Privacy Policy

Last updated: April 14, 2026

Your privacy is at the heart of everything we build.

Preserve U ("we", "our", or "us") is a digital time capsule service that lets you create encrypted messages, media, and documents to be delivered to recipients at a scheduled future date. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding that data.

By using Preserve U, you agree to this Privacy Policy. If you do not agree, please discontinue use of the service.

1. Information We Collect

a. Account Information

When you create an account, we collect your name, email address, and a hashed password. We never store your password in plain text.

b. Capsule Content

Text capsules are encrypted client-side using AES-256-GCM with a password you set. We store only the encrypted ciphertext — we cannot read your messages.

Media capsules (images, videos, audio, documents) are encrypted with AES-256-GCM before upload and stored as encrypted binary files. We cannot access their content.

c. Delivery & Scheduling Data

We store recipient name, recipient email, scheduled delivery date/time, and capsule metadata (type, size, creation date).

d. Usage & Analytics

We may collect anonymised usage data (page views, feature interactions) via industry-standard analytics tools to improve the service. This data cannot be used to identify you personally.

e. Payment Information

Payments are processed entirely by our authorised payment processor. We do not store card numbers, CVVs, or bank account details. We receive only transaction confirmation and order IDs.

2. How We Use Your Information

  • To create and manage your account
  • To deliver time capsules to recipients at the scheduled time via email
  • To process payments for capsule creation
  • To send transactional emails (account confirmation, payment receipts)
  • To maintain and improve the security and performance of our service
  • To comply with legal obligations

We do not sell your personal information to third parties. We do not use your information for advertising purposes.

3. Data Retention

  • Active capsules: Stored until the scheduled delivery date, then marked as delivered. Media files are retained for 30 days post-delivery.
  • Account data: Retained while your account is active. You may request deletion at any time.
  • Self-destruct capsules: Permanently deleted from our servers after the trigger condition is met.
  • Dead Man's Switch capsules: Deleted if you perform a check-in before the switch triggers.

4. End-to-End Encryption

All text content is encrypted in your browser using AES-256-GCM before transmission. The encryption key is derived from your chosen password using PBKDF2. We store only the encrypted ciphertext, salt, and IV — never the password or decryption key. We cannot decrypt your messages under any circumstances.

Media files are also encrypted client-side before upload. If you lose your password, the content is unrecoverable by design.

5. Third-Party Service Providers

To deliver a secure and reliable service, we work with carefully vetted third-party providers across the following categories:

  • Email delivery — for sending capsule notifications and transactional emails
  • Payment processing — for securely handling in-app transactions (we never receive raw card data)
  • Cloud hosting & infrastructure — for running our servers and APIs
  • Database storage — for storing encrypted capsule metadata
  • Encrypted file storage — for storing encrypted media and document capsules

All providers are contractually bound to process your data only as directed by us and to maintain appropriate security standards. We do not disclose provider names publicly.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your capsule metadata (note: encrypted content cannot be decrypted by us)
  • Withdraw consent for non-essential data processing

To exercise any of these rights, contact us at privacy@preserveu.com.

7. Cookies

We use only essential cookies required for authentication (secure session tokens). We do not use advertising or tracking cookies without your consent.

8. Security

We implement industry-standard security measures including TLS/HTTPS, client-side encryption, bcrypt password hashing, and regular security reviews. However, no system is 100% secure. In the event of a data breach, we will notify affected users as required by applicable law.

9. Children's Privacy

Preserve U is not directed to children under 13. We do not knowingly collect personal data from children under 13. If we become aware of such data being collected, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a prominent notice on our website. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related inquiries:

Preserve U

Email: privacy@preserveu.com

Website: preserveu.com