Back to Legal

Privacy Policy

Your privacy is fundamental to everything we do.

Last updated: December 2024

The short version

Encrypted

Letters and recipients are encrypted end-to-end

No tracking

No IP logging, no analytics, no third-party trackers

Minimal data

Only email and timestamps — nothing else

Your control

Delete your account and data anytime

1. Introduction

TimedMail ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.

We believe privacy is a fundamental right. Our service is designed from the ground up to minimize data collection while providing a secure way to store and deliver your letters.

TimedMail is operated from Reykjavik, Iceland, and your data is processed under Icelandic and European Economic Area (EEA) data protection law.

2. Why Iceland?

We deliberately chose Iceland as our jurisdiction because it offers some of the strongest privacy protections in the world:

  • Iceland's Act No. 90/2018 fully implements the EU General Data Protection Regulation (GDPR)
  • As an EEA member, Iceland provides the same data protection standards as the European Union
  • Iceland is outside US jurisdiction — not subject to NSA surveillance programs or the US DMCA
  • The Icelandic Data Protection Authority (Persónuvernd) actively enforces privacy rights
  • Iceland ranks #1 on the Global Peace Index and has strong rule of law

Your data never leaves the protection of Icelandic and EEA law. We do not operate any servers in jurisdictions with weaker privacy protections.

100% Renewable Energy

Our servers run entirely on Iceland's renewable energy grid — 100% geothermal and hydroelectric power. Your privacy choices also help protect the planet.

3. Information We Collect

Account Information

  • Email address (required for account creation and check-in reminders)
  • Password (stored as a secure hash, never in plain text)
  • Payment information (processed by our payment provider, not stored by us)

Letter Data

  • Recipient email addresses (encrypted, we cannot read these)
  • Encrypted letter content (we cannot read this)
  • Check-in interval settings
  • Last check-in timestamp

What We Don't Collect

  • IP addresses (we do not log these)
  • Browser fingerprints or device identifiers
  • Usage analytics or tracking data

4. How We Use Your Information

We use your information solely to:

  • Provide and maintain the TimedMail service
  • Send check-in reminders to your email
  • Deliver your letters to recipients when triggered
  • Process payments
  • Prevent fraud and abuse
  • Respond to support requests

We do not use your information for advertising, profiling, or any purpose other than operating the service.

5. Encryption and Security

Your letter content is encrypted using AES-256-GCM encryption combined with timelock cryptography before being stored on our servers. This means:

  • We cannot read the content of your letters — this is mathematically guaranteed
  • Decryption keys are timelocked via a public beacon (drand) and only become available at a future date
  • Each time you check in, your letters are re-encrypted with a new future timelock
  • Only the intended recipient can decrypt and read your letter after the timelock expires

We use the drand (Distributed Randomness Beacon) network, operated by Cloudflare, Protocol Labs, and other independent organizations. This decentralized system ensures that no single party — including TimedMail — can access your content before the scheduled time.

Additional security measures include HTTPS encryption, secure password hashing, and regular security audits.

6. Data Sharing

We do not sell, rent, or share your personal information with third parties, except:

Payment processors:To process your payments securely
Email delivery:To send check-in reminders and deliver letters
Legal requirements:If required by law or to protect our rights

We do not use any third-party analytics, advertising, or tracking services.

7. Data Retention

We retain your data for as long as your account is active. After a letter is delivered, the encrypted content is automatically deleted from our servers within 30 days.

If you delete your account, all your data including letters, recipient information, and account details are permanently deleted within 30 days.

8. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and all associated data
  • Export your data in a portable format
  • Object to processing of your data

To exercise any of these rights, please contact us at [email protected].

9. Cookies

We use only essential cookies required for the service to function:

  • Session cookies to keep you logged in
  • Security cookies to prevent CSRF attacks

We do not use tracking cookies, advertising cookies, or any third-party cookies.

10. International Data Transfers

TimedMail is headquartered in Iceland, a member of the European Economic Area (EEA). Your data is primarily processed and stored in Iceland.

For users outside Iceland, this means your data is transferred to and stored under Icelandic and EEA data protection law, which provides one of the highest standards of data protection globally.

Any data transfers outside the EEA (such as email delivery services) are conducted in compliance with GDPR requirements, using appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfers only to countries with an EU adequacy decision
  • Binding Corporate Rules where applicable

We do not transfer data to, or operate servers in, jurisdictions that lack adequate privacy protections or are subject to mass surveillance programs.

11. Children's Privacy

TimedMail is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by email and update the "Last updated" date at the top of this page.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Address

TimedMail
Hafnarhusinu, Tryggvagata 17
101 Reykjavik, Iceland

Data Protection Authority

Persónuvernd (Icelandic Data Protection Authority)
www.personuvernd.is

Your privacy matters to us

We built TimedMail with privacy at its core. If you have any questions or concerns, we're here to help.