Privacy Policy
Last updated: April 14, 2026
Your privacy is at the heart of everything we build.
Preserve U ("we", "our", or "us") is a digital time capsule service that lets you create encrypted messages, media, and documents to be delivered to recipients at a scheduled future date. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding that data.
By using Preserve U, you agree to this Privacy Policy. If you do not agree, please discontinue use of the service.
1. Information We Collect
a. Account Information
When you create an account, we collect your name, email address, and a hashed password. We never store your password in plain text.
b. Capsule Content
Text capsules are encrypted client-side using AES-256-GCM with a password you set. We store only the encrypted ciphertext — we cannot read your messages.
Media capsules (images, videos, audio, documents) are encrypted with AES-256-GCM before upload and stored as encrypted binary files. We cannot access their content.
c. Delivery & Scheduling Data
We store recipient name, recipient email, scheduled delivery date/time, and capsule metadata (type, size, creation date).
d. Usage & Analytics
We may collect anonymised usage data (page views, feature interactions) via industry-standard analytics tools to improve the service. This data cannot be used to identify you personally.
e. Payment Information
Payments are processed entirely by our authorised payment processor. We do not store card numbers, CVVs, or bank account details. We receive only transaction confirmation and order IDs.
2. How We Use Your Information
- To create and manage your account
- To deliver time capsules to recipients at the scheduled time via email
- To process payments for capsule creation
- To send transactional emails (account confirmation, payment receipts)
- To maintain and improve the security and performance of our service
- To comply with legal obligations
We do not sell your personal information to third parties. We do not use your information for advertising purposes.
3. Data Retention
- Active capsules: Stored until the scheduled delivery date, then marked as delivered. Media files are retained for 30 days post-delivery.
- Account data: Retained while your account is active. You may request deletion at any time.
- Self-destruct capsules: Permanently deleted from our servers after the trigger condition is met.
- Dead Man's Switch capsules: Deleted if you perform a check-in before the switch triggers.
4. End-to-End Encryption
All text content is encrypted in your browser using AES-256-GCM before transmission. The encryption key is derived from your chosen password using PBKDF2. We store only the encrypted ciphertext, salt, and IV — never the password or decryption key. We cannot decrypt your messages under any circumstances.
Media files are also encrypted client-side before upload. If you lose your password, the content is unrecoverable by design.
5. Third-Party Service Providers
To deliver a secure and reliable service, we work with carefully vetted third-party providers across the following categories:
- Email delivery — for sending capsule notifications and transactional emails
- Payment processing — for securely handling in-app transactions (we never receive raw card data)
- Cloud hosting & infrastructure — for running our servers and APIs
- Database storage — for storing encrypted capsule metadata
- Encrypted file storage — for storing encrypted media and document capsules
All providers are contractually bound to process your data only as directed by us and to maintain appropriate security standards. We do not disclose provider names publicly.
6. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your capsule metadata (note: encrypted content cannot be decrypted by us)
- Withdraw consent for non-essential data processing
To exercise any of these rights, contact us at privacy@preserveu.com.
7. Cookies
We use only essential cookies required for authentication (secure session tokens). We do not use advertising or tracking cookies without your consent.
8. Security
We implement industry-standard security measures including TLS/HTTPS, client-side encryption, bcrypt password hashing, and regular security reviews. However, no system is 100% secure. In the event of a data breach, we will notify affected users as required by applicable law.
9. Children's Privacy
Preserve U is not directed to children under 13. We do not knowingly collect personal data from children under 13. If we become aware of such data being collected, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a prominent notice on our website. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related inquiries: