Keeping the key
Every capsule is locked with a key. Before sealing, you decide who keeps that key — and one of the choices cannot be undone.
Version 2026-09-29 · In force since September 29, 2026
1. What the key is
The capsule’s content is encrypted. The key is what makes it readable again on the opening date. It appears on screen only once, at the moment of sealing, and is also sent to your email.
Keep it with the care you would give a letter that can only be opened many years from now. Without it — if you chose to be the only one holding the key — the capsule stays closed forever.
2. Option 1 — We keep a copy (recoverable)
We keep a protected copy of the key on our side. If you lose yours, we can send it again to your email — or, if we cannot reach you, to the backup contact you named — so that the capsule can be opened.
This also means that, on our side, there is a technical path to open the capsule. That path is only used to provide the service to you, never to read your content for any other reason. Choose this option if recovery matters more to you than being the only one who keeps the key.
3. Option 2 — Only you keep it (irreversible)
We keep no copy of the key. It is 100% your responsibility.
If the key is lost, the capsule’s content can never be read again. Nobody can recover it:
- not you, without the key;
- not us, who run the service;
- not our support team, whatever the request or proof;
- not with the master key or any administrative access we have.
This is not a policy that can be reconsidered in a special case: without the key, there is no technical path to the content.
4. What we can check — and what we cannot
We keep a verifier of the key. Its only use is to confirm whether a typed key is the right one. It cannot be used to read the capsule’s content.
This works because the verifier is derived independently of the decryption key. Checking and reading are separate capabilities.
5. When we can read — and when we cannot
The key-keeping choice is a trade-off: recoverability or privacy from us. To be transparent, here is when the content can be decrypted on our side:
- Before sealing: the content is already stored encrypted, but with a key in our keeping, so that participants can write and read during the writing stage.
- Sealed capsule, with “we keep a copy”: the copy of the key is protected by the service’s master key. We can decrypt the capsule — that is what makes it recoverable if you lose your key.
- Sealed capsule, with “only you keep it”: we cannot read the content. Without the key, it stays encrypted until it is deleted.
- After the opening, with either option: when the capsule is opened with the correct key, the content comes back into our keeping, so that participants can read it without typing the key again.
At none of these moments do we use technical access to read your content for any reason other than providing the service or complying with the law.
6. How your choice is recorded
We record the option you chose, the date, the time and the version of these terms in force. That record is never changed. If you switch from “we keep a copy” to “only you keep it”, we erase our copy and record the change; the reverse path does not exist, because an erased copy cannot be recreated by us.
7. Responsibility
If you choose “only you keep it” and the key is lost, we are not liable for the loss of access to the content: the choice is yours, made after the notice on this page, and the system has no alternative recovery path — neither support, nor the master key, nor any internal order changes that technical fact.
With the “we keep a copy” option, we commit to keeping the copy with the same security care as the rest of the service and to using it only to recover access at a legitimate request from you or from the capsule’s participants.
8. Change history
- September 29, 2026First published version: the two ways of keeping the key, the verifier, the exceptions and each party’s responsibility.