What happens if we disappear.
Version 0.1 · September 2026 · reviewed with every release
Every dedicated “after you are gone” service we could find is gone itself — SafeBeyond, Afternote, Cake, HereAfter, DeathSwitch. Each took its users’ words down with it. We think the only honest response is to design Posthum so that our own disappearance costs you nothing, and to say so in writing before asking anyone to trust us.
1. Your journal never needed us
Posthum is local-first. Your entries are encrypted in your browser with a key derived from your passphrase and stored on your device. The free app makes no network requests at all — the vault is served with a Content-Security-Policy that forbids them, which you can read in the response headers. If our servers went dark tonight, an installed copy of Posthum would open tomorrow exactly as it did today.
2. Export is one click, free, forever
Settings → Download encrypted backup gives you a .posthum file: your vault header and your encrypted entries, nothing more. Plain Markdown and JSON exports are there too. No tier, no trial, no upsell will ever sit between you and your own words.
3. The format is public
A .posthum file is documented JSON: PBKDF2-SHA256 derives a key from your passphrase; that key unwraps a random AES-256 vault key; each entry is AES-256-GCM with a fresh IV and additional data binding it to its row. The specification lives in the repository README, next to the unit test that is its executable proof.
4. The decryptor is one file, with no dependencies
posthum.app/decrypt opens any backup in your browser with your passphrase or your 12-word recovery key, on a page that is served with connect-src 'none' — it cannot talk to any server, including ours. The same tool exists as a single HTML file you can keep on a USB stick beside your backup. It is public domain, uses only the WebCrypto built into every browser, and will keep working long after this domain lapses. It is tested against real archives on every commit.
5. If Posthum shuts down
- Notice. At least 90 days by email to every account and on this page, before anything stops.
- Read-and-export mode. The app stays reachable for that whole period so anyone can download a backup.
- Sealed letters. Any letter we were holding for future delivery (a paid feature, not yet built) is returned to its author, encrypted, before we stop — never dropped, never delivered early without your say.
- The code stays. The repository, the format and the decryptor remain public. Anyone may host their own copy.
- Data is deleted. Whatever ciphertext we held for sync is destroyed at the end of the notice period, and we say so here.
6. What we will not sell you
No “100-year plan”, no “forever”. Text storage costs almost nothing; custody — a company still answering email in 2071 — is a promise nobody can price honestly. If we ever offer prepayment, it will be for a stated number of years with a stated end date.
7. What we will never do
- Train any model on your entries, or let anyone else.
- Sell, share, or read them. We cannot read them; that is the design, not a policy.
- Release anything to anyone on an inactivity timer. A legacy release, when it exists, will require people you chose, a waiting period, and your veto.
- Build a chatbot that speaks as you after you are gone.
- Show ads, streaks, or guilt.
Questions or corrections: hello@minute.tech. This page is versioned in the repository; its history is public.