Letter encryption
Letters can be password-encrypted or end-to-end encrypted. Password-encrypted content is encrypted in the browser before saving; the server stores only ciphertext and a hint.
Security & trust rules
TimeWill's goal is not to collect more data, but to deliver the right information to the right people when it matters. We reduce risk through encryption, heartbeat checks, contact confirmation, backend audits, and minimal display.
Letters can be password-encrypted or end-to-end encrypted. Password-encrypted content is encrypted in the browser before saving; the server stores only ciphertext and a hint.
Vault content is encrypted with AES-256-GCM. The backend shows only counts, categories, and status by default, never plaintext.
Premium users can generate RSA keys and encrypt content written to themselves with a public key; the private key is kept by the user.
A heartbeat is not proof of death, but a signal of missed check-ins. The system uses T1-T4 staged reminders, confirmations, and handover to reduce false triggers.
Contacts can confirm their identity via email. Users can also confirm offline and skip email confirmation; the system records the status.
Drafts, undelivered capsules, contacts, and vault entries can be managed in the dashboard. Delivered content is handled per user settings.
For the boundaries of legal effect, disclaimers, and digital estate guidance, please read the legal notice.