What we know about you.

Draft · September 2026 · not yet reviewed by a lawyer

Draft

This page is written to be read, not scrolled past. It is short because there is not much to say: the product is designed so that the most interesting data — your journal — never reaches us.

Your journal

Entries, photos, tags, moods, sealed-letter addressees and legacy contacts are encrypted on your device with a key derived from your passphrase. They are stored in your browser’s IndexedDB. Private notes stay on your device. If you confirm sharing with a group, the note and its photo are encrypted with the group key before upload. If you confirm publishing to the world, that note and photo become readable by anyone with the link. We have no copy of your vault key. Nothing in this section can change without a change to the code, which is public.

Photos and dictation

Photos are resized and re-encoded on your device, removing embedded location metadata and the original filename. They are stored encrypted with the note and follow its sharing choice. Local dictation requires a browser that supports on-device speech recognition. A language pack may need a one-time download; microphone audio is processed on your device and is not stored or uploaded by Posthum. We do not fall back to cloud transcription.

Subscriptions

If you subscribe to sync, payment is handled by Stripe on Stripe’s pages. We receive a customer id, the plan and its status, and the email you gave Stripe, so we can tell your devices the subscription is live. We never see your card. Cancel any time; your journal stays yours either way.

Reflection (bring your own key)

Optionally you can paste your own Anthropic API key into Settings. It is stored encrypted inside your vault. When you press “Reflect on this” and confirm, the exact text shown in the dialog is sent from your browser directly to api.anthropic.com under your key and Anthropic’s privacy policy. It never passes through us. The reply is not stored unless you insert it into an entry.

This website

The marketing pages use no analytics, no cookies, no third-party scripts and no tracking pixels. Our host keeps ordinary request logs (IP address, user agent, URL, time) for a short period for security and debugging.

Children

Posthum is for people 13 and older.

How to check

Read the response headers on /app: connect-src 'self' https://api.anthropic.com. Read the code at github.com/minute-tech/posthum. Open a backup without us at /decrypt.

Changes and contact

Changes to this page are made in the public repository, so its history is visible. Questions: hello@minute.tech.