FAQ

Frequently Asked Questions

What is the maximum file size?

560KB per seal.

Workarounds for larger files:

  • Compress before upload (ZIP can reduce size 50-90%)
  • Split into multiple seals (500KB chunks)
  • Upload to cloud storage and seal the download link
  • Self-host with R2 storage for files up to 5GB

How does Time-Seal prevent early access?

Split-Key Architecture:

  • Browser generates Key A and Key B
  • Key A stays in URL hash (never sent to server)
  • Key B sent to server (encrypted with master key before storage)
  • Both keys required for decryption
  • Server refuses to release Key B until unlock time

Server-Side Time Enforcement: Cloudflare NTP-synchronized timestamps. Your local clock is completely irrelevant.

How do I create a seal?

Timed Release:

  • Enter message or upload file (max 560KB)
  • Select "TIMED" mode
  • Choose unlock date/time (up to 30 days)
  • Complete Cloudflare Turnstile security check
  • Choose how to save: COPY | DOWNLOAD (MD) | SAVE (encrypted vault)

Dead Man's Switch:

  • Follow steps 1-2 above
  • Select "DEADMAN" mode
  • Set pulse interval (how often you check in)
  • Save TWO links: vault link (public) and pulse link (private)
  • Visit pulse link before interval expires to keep sealed

Ephemeral (Self-Destructing):

  • Follow steps 1-2 above
  • Select "EPHEMERAL" mode
  • Set max views (1-100, default: 1 for read-once)
  • Complete security check and create seal
  • Seal unlocks immediately but auto-deletes after N views
  • Perfect for one-time passwords and confidential messages

How do I save my seals for later?

Three options after creating a seal:

  • COPY - Copy vault link to clipboard (paste into password manager)
  • DOWNLOAD (MD) - Download markdown file with both vault and pulse links
  • SAVE - Encrypt and save to browser vault (AES-GCM-256)

Encrypted Local Storage:

  • Seals encrypted with AES-GCM-256 in your browser
  • Unique encryption key per browser (stored locally)
  • No server-side storage of your vault links
  • Access saved seals at /dashboard

Best practices: Use all three methods for important seals. Store markdown files in encrypted cloud storage. Never share vault links over unencrypted channels.

How do I unlock a seal?

  • Open vault link (contains Key A in URL hash)
  • If locked: See countdown timer
  • If unlocked: Content automatically decrypts in browser
  • Download or copy decrypted content

Decryption happens entirely in your browser. Server never sees decrypted content.

How does Dead Man's Switch work?

Setup:

  • Set pulse interval (e.g., 7 days)
  • Seal unlocks if you don't check in within that time
  • Get private pulse link to reset timer

Checking In:

  • Visit private pulse link (from any device)
  • Click "Pulse" button
  • Timer resets for another interval
  • Repeat before each interval expires

If You Miss a Pulse:

  • Seal automatically unlocks at deadline
  • Recipient can access with vault link
  • Cannot be reversed once unlocked

Burning a Seal: Use pulse link to permanently delete seal. Content destroyed immediately and cannot be recovered.

Can I decrypt my seal early?

No. The time-lock is cryptographically enforced. Not even the creator can decrypt before unlock time. This is by design for security.

What happens if I lose the vault link?

Lost forever. Key A is in the URL hash. Without it, server cannot decrypt (doesn't have Key A) and you cannot decrypt (don't have the link). No recovery mechanism exists by design.

Best practices:

  • Save vault links in password manager
  • Email to yourself (encrypted email recommended)
  • Print QR code for physical backup
  • Never share vault links over unencrypted channels

What happens if I miss a pulse?

The seal will automatically unlock for recipients after the pulse interval expires. This is the intended behavior for Dead Man's Switch mode.

Can I cancel or delete a seal?

Timed Release: ❌ No. Cannot be deleted once created.

Dead Man's Switch: ✅ Yes. Use pulse link to "burn" the seal (permanently destroy content).

Ephemeral: ⚠️ Auto-deletes after max views reached. Cannot be manually deleted.

Where is my data stored?

Encrypted blobs stored in Cloudflare D1 database (SQLite at the edge). All data encrypted with triple-layer encryption:

  • Client-side AES-GCM-256 encryption
  • Server-side Key B encryption with master key
  • Database encryption at rest
  • Zero plaintext storage

Is this really secure?

Yes. Security features include:

  • AES-GCM 256-bit encryption
  • Split-key architecture (no single point of failure)
  • Server-side time-lock enforcement
  • Triple-layer encrypted storage
  • Rate limiting with SHA-256 fingerprinting
  • Cloudflare Turnstile bot protection
  • Replay attack prevention with nonce validation
  • Open source code for audit

Do you have access to my content?

No. Encryption happens client-side in your browser. We only store:

  • Encrypted blob (AES-GCM-256 ciphertext)
  • Encrypted Key B (encrypted with master key)
  • IV (public, needed for decryption)
  • Metadata (unlock time, timestamps)

Both Key A (from URL) and Key B (from server) are required for decryption. We never have both keys at the same time.

What file formats are supported?

All file types. The system encrypts raw bytes, so any file format works (documents, images, videos, archives, etc.).

Is there a cost to use TimeSeal?

License: Business Source License (BSL)

  • ✅ Free for non-commercial use
  • ❌ Commercial use requires license
  • ✅ Source code available for inspection
  • ✅ Converts to Apache 2.0 after 4 years

How long do seals last?

Maximum Duration: 30 days until unlock

Retention: Seals auto-delete 30 days after unlock

Total Lifetime: Maximum 60 days (30 + 30)

Is the URL hash secure?

Yes. The URL hash (#KeyA) is never sent to the server. HTTPS protects it in transit. However, it's visible in browser history and bookmarks.

Best practices: Use incognito mode for sensitive seals, clear browser history after use, treat vault links like passwords.

Can someone guess my seal ID?

Extremely unlikely. Seal IDs are 32 hex characters (16 bytes) = 2^128 possible combinations. Would take billions of years to guess.

Even if guessed, they cannot decrypt without Key A from your vault link.

What if Cloudflare goes down?

Your seal remains safe in the database. Countdown pauses during outage and resumes when service restored. No data loss.

Does TimeSeal track my activity?

We use privacy-first analytics with zero external dependencies. No cookies, no IP addresses, no personal data.

We only track: page views, seal creation count, unlock events, and country (from Cloudflare headers). All data is aggregate and GDPR compliant.