Skip to content

Trust & security

Two promises. Kept for decades.

Nothing you write is shared with anyone you didn't choose. And nothing is released while you're still here.

Private while you're here

  • Encrypted at rest

    Every message body is encrypted with AES-256-GCM before it's written to our database. Connections to Sealkept are encrypted in transit with TLS.

  • Handled under GDPR

    Your data is encrypted at rest and handled under GDPR, Europe's data protection law, whether you live in Ohio or Oslo.

  • Only the right person

    Each recipient gets their own private, unguessable link, and sees only the messages addressed to them.

  • A private seal, if you want one

    Optional, per letter. It's encrypted in your browser and opens with a question only your recipient can answer, or a key card you give them, plus a half we release on delivery. We can't read it.

Never released by mistake

  • Layers of "are you okay?"

    Reminders, then an optional verifier, then a soft alert, then a grace period. A missed check-in is never treated as proof of anything.

  • One check-in stops everything

    Check in at any stage and the whole process resets instantly.

  • Anyone can say you're fine

    Verifiers and recipients can each tell us you're okay, which pauses the switch for 7 days while we wait to hear from you.

  • Pause anytime

    Travel, surgery, a long hospital stay. Pause for 30 days with one tap, and pause again if you need longer.

How it works

Honest about access

What we can and cannot see.

By default Sealkept is not end-to-end encrypted, and we'd rather tell you why than pretend. To deliver your words to someone who has no account, at a moment when you can't be there, our servers must be able to unlock them. Here is exactly what that means, and how an optional private seal changes it.

What our systems hold

  • Your account details: name, email address and plan
  • Your recipients' names, email addresses and optional birthdays
  • Your check-in schedule and the status of your switch
  • Message details such as type, recipient, release rule and dates

What stays locked

  • Message bodies are stored encrypted, never as plain text
  • They're decrypted only to show them to you while you edit, and to your recipient on delivery
  • Our policy is that no one at Sealkept reads message content
  • We never sell your data, show you ads or use your messages to train AI

What we cannot see

  • Your password, which is stored only as a one-way hash
  • Letters with a private seal: they're encrypted in your browser, and the key on the card never reaches us
  • Anything you haven't written into Sealkept

Our continuity promise

Even if we close, your words still arrive.

Services in this space have shut down before, and a message for a child's eighteenth birthday has to outlast a lot. So we've written down what happens if Sealkept ever closes.

  1. 01

    You'd hear from us first

    Every member gets notice by email, well before anything changes.

  2. 02

    You'd get everything back

    A complete export of your messages and recipients, yours to keep.

  3. 03

    Waiting messages still go out

    Messages still sealed would be delivered by the rules you set, on schedule.

How the Lifetime continuity fund works

Part of every Lifetime payment is set aside in a separate continuity fund, kept apart from the money we use to run the company. It can only be spent on storing and delivering Lifetime members' messages. That way the cost of keeping your words safe is paid for in advance, rather than depending on future sales.

See Lifetime pricing

Your data, your rights

You stay in control.

Read the privacy policy
  • See it

    Ask for a copy of all the personal data we hold about you.

  • Change it

    Edit your messages, recipients and rules at any time, or ask us to correct anything.

  • Delete it

    Delete your account and your messages, recipients and settings are erased with it.

  • Ask us

    Write to [email protected] with any privacy question or request.

FAQ

Safety questions

A basic one that sends on a single missed click can misfire. Sealkept never sends on one missed check-in: it reminds you several times, can ask a trusted verifier to confirm, sends recipients a soft alert, and waits a grace period you choose before anything is delivered.

Not by default. Message bodies are encrypted at rest with AES-256-GCM, but our servers hold the keys so we can deliver your messages when you can't. For any letter you can turn on a private seal instead: it's encrypted in your browser with a key printed on a card you give your recipient. We keep only the other half of what's needed and release it on delivery, so we can't read the letter. The trade-off: if the card is lost, no one can open it, including us.

On servers we run with Oracle Cloud in Mumbai, India, encrypted at rest and handled under GDPR for every member wherever they live.

You'd get notice and a full export of your messages, and messages still waiting would be delivered by your rules. Lifetime storage is paid for by a separate continuity fund.

A few minutes tonight. Peace of mind for good.

Start with one message to one person. You can add the rest whenever you're ready.

Write your first message

Set up in a few minutes · $5 a month, cancel anytime