Back to Legal

Law Enforcement

Information for government and law enforcement agencies regarding data requests and our technical architecture.

Last updated: desember 2024

Important: Technical Limitations

Due to our end-to-end encryption architecture, TimedMail cannot access the content of user letters. We do not possess the encryption keys necessary to decrypt user content, even in response to valid legal requests.

Our Encryption Architecture

End-to-End Encrypted

All letter content is encrypted client-side before transmission to our servers.

Zero-Knowledge

Encryption keys are derived from user credentials and never stored on our servers.

No Backdoors

We have no technical capability to decrypt user content, by design.

Technical Details

TimedMail uses AES-256-GCM encryption combined with timelock cryptography via a decentralized public beacon (drand). The encryption process works as follows:

  1. User content is encrypted in the browser before being sent to our servers
  2. Encryption keys are timelocked — they will only become available from the public beacon at a future date
  3. Each time the user checks in, the content is re-encrypted with a new future timelock
  4. We only store the encrypted ciphertext — we do not possess decryption keys
  5. Upon timer expiry, the beacon publishes the key and delivery is triggered automatically

This architecture means that even TimedMail cannot decrypt user content before the timelock expires. This is not a policy — it is a mathematical guarantee.

Timelock Beacon (drand)

We use the drand (Distributed Randomness Beacon) network, operated by Cloudflare, Protocol Labs, and other independent organizations worldwide. This decentralized network publishes cryptographic keys at precise future times. No single party — including TimedMail — can access the key before the scheduled time.

Quantum-Resistant

Our encryption is designed to remain secure even against future quantum computers. AES-256 retains 128-bit effective security against quantum attacks (Grover's algorithm), providing long-term protection for user data.

Data We Can & Cannot Provide

Data We May Provide

With valid legal process, we may be able to provide:

  • ✓
    Account registration email
  • ✓
    Account creation date
  • ✓
    Last check-in timestamp
  • ✓
    Payment transaction records

This is the complete extent of unencrypted data we store.

Data We Cannot Provide

Due to encryption or no collection, we are unable to provide:

  • ✕
    Decrypted letter content
  • ✕
    Recipient email addresses (encrypted)
  • ✕
    User passwords
  • ✕
    Encryption keys
  • ✕
    IP addresses (not logged)
  • ✕
    Plaintext of any messages

This is not a policy choice but a technical limitation. We do not possess the capability to decrypt user content, and we do not log IP addresses.

Submitting a Request

Requirements

All requests must include:

  • Valid legal process (subpoena, court order, or warrant as applicable)
  • Specific account identifiers (email address)
  • Description of the specific data requested
  • Official law enforcement email address for response

Contact

Law enforcement requests should be sent to:

Please note that we do not accept requests via phone or social media.

Response Time

We aim to respond to valid requests within 10 business days. Emergency requests may be expedited when there is imminent risk to life or serious physical harm.

Our Commitment to Transparency

TimedMail is committed to protecting user privacy while complying with applicable laws. We will:

  • Carefully review all requests for legal validity
  • Narrow overly broad requests where possible
  • Notify users of requests unless legally prohibited
  • Never provide data beyond what is legally required
  • Publish transparency reports on requests received

Questions?

For questions about this policy or our technical architecture, contact us at [email protected]