© 2026 TimeWill
HelpPrivacy PolicyTerms of ServiceSecurity
Operated by Haikou Meilan Qipin Network TechnologyContact: qipin0307@gmail.com
Home/Guides/TimeWill's Encryption: Two Layers Protecting Your Letters and Passwords Separately

TimeWill's Encryption: Two Layers Protecting Your Letters and Passwords Separately

TimeWill · Updated 2026-06-25

TL;DR

TimeWill uses two encryption layers. End-to-end encrypted letters are encrypted locally in your browser before upload, so the platform never sees the plaintext—ideal for your most private content. The password vault uses server-side hosted encryption, so the system can decrypt it when trigger conditions are met and automatically release it to your contacts after a missed heartbeat check-in. The two serve different purposes—choose based on content sensitivity.

When you entrust last letters, passwords, and private keys to an online service, the first question to ask is: can the platform itself read them? TimeWill applies different encryption strategies to different content types. The sections below explain the distinction between the two layers so you can choose based on how sensitive your content is. Further reading: How to Pass Cryptocurrency and Digital Assets to Your Family.

Layer One: End-to-End Encrypted Letters (Unreadable by the Platform)

With end-to-end encrypted letters, your content is encrypted locally in your browser with a key before it is ever uploaded. The server stores only ciphertext, and the decryption key is never held by the platform—so the platform cannot read the plaintext of these letters. The trade-off: if both you and your recipient lose the key or passphrase, the content cannot be recovered. This is the layer for your most private content that no one should read while you are alive.

Layer Two: The Password Vault (Server-Side Hosted Encryption, Auto-Release Enabled)

Entries in the password vault are encrypted with AES-256 and stored on the server. Unlike end-to-end letters, the vault uses server-side hosted encryption—because its core function is to automatically deliver content to your designated contacts after you have been unreachable for an extended period, the heartbeat check-in has triggered, and your emergency contacts have confirmed. For "automatic delivery" to work, the system must be able to decrypt when the trigger conditions are met. This is a deliberate trade-off between functionality and "the platform cannot read it at all." We mitigate the risk through access controls, key management, and operation auditing, but we do not claim the platform is technically unable to read vault contents.

How to Choose: Route by Content Sensitivity

A practical rule of thumb: for content that should "never be read by the platform or anyone while you are alive," use end-to-end encrypted letters; for account passwords and transfer instructions that should "reach your family automatically and reliably after you lose contact," use the vault. Within the vault, you can set a handling rule for each entry—release to a contact, keep as a record only, or destroy after triggering.

What Level of Security Is AES-256?

AES-256 is a symmetric encryption standard widely adopted today by banks, government agencies, and the security industry. With the key properly safeguarded, it substantially raises the cost of unauthorized reading. It is important to note: encryption protects "stored data"—it does not eliminate risks in other links such as device theft, passphrase leakage, or account takeover, and it does not replace your own responsibility for account security.

Encryption Is Not a Panacea: The Limits You Should Know

We do not use phrases like "absolutely secure," "never leaks," or "unbreakable"—no responsible security product should make such promises. Encryption dramatically raises the threshold for unauthorized reading, but security is a systems engineering problem: your devices, passphrases, and account habits matter just as much. For end-to-end encrypted content, be sure to safely store the key or passphrase and make sure your recipient knows how to obtain it—otherwise the content may be permanently unrecoverable.

FAQ

Q: Can the platform see my data?

It depends on the content type. End-to-end encrypted letters are encrypted in your browser before upload, so the platform stores only ciphertext and cannot read the plaintext. The password vault, to enable automatic delivery to your contacts after a missed heartbeat check-in, uses server-side hosted encryption—meaning the system can decrypt it when the trigger conditions are met. This is a prerequisite for the auto-release feature. For your most private content that no one should read while you are alive, use end-to-end encrypted letters.

Q: Is AES-256 secure?

AES-256 is a symmetric encryption standard widely adopted by banks, governments, and the security industry. Provided the key is properly safeguarded, it substantially raises the cost of unauthorized access. However, encryption does not eliminate risks such as device theft, key leakage, or account takeover, and it does not replace your own responsibility for account security.

Q: Can I assign different recipients to different content?

Yes. Letters can have separate recipients and release conditions—your spouse, your child, or set to never release. Vault entries can each have their own handling: release to a contact, keep as a record only, or destroy after triggering.

Related Guides

Digital WillCrypto AssetsTime Capsule

Create Your Encrypted Last Letter

End-to-end encrypted letters plus a hosted encrypted vault—protected separately by content sensitivity.

Start Free
Start Free