How we protect your data

Owl's Hour is built on a single principle: we should be technically incapable of reading your messages, not merely contractually prohibited. Here is how that works.

No. Messages are encrypted in your browser before reaching our servers. We store only ciphertext — the scrambled output of encryption. We hold no key that could decrypt it. Even in the event of a server breach, your contents would be unreadable to anyone without your recipients' private keys.

Technically, yes — and we think you deserve to know that. The seal on when your message is released is a contractual and operational commitment, not a cryptographic one. Confidentiality — whether anyone can read the contents — is guaranteed by mathematics. When it is released is guaranteed by our systems and architecture. These are different kinds of promise, and we keep them separate.

Your message content is encrypted with XChaCha20-Poly1305, a modern authenticated cipher. Keys are exchanged using ML-KEM-768, a post-quantum algorithm standardised by NIST — designed to remain secure even against future quantum computers.

No. Your password is used only to authenticate you. Encryption relies on a separate cryptographic key stored in your browser and backed up separately. Your password never touches the encryption layer.

When you first set up your account, you create an encrypted backup protected by a backup password of your choice. If your device is lost or your browser data is cleared, you recover your keys using your email address and that backup password — and all your stored messages remain accessible.

Messages encrypted under your old keys become permanently inaccessible. This is intentional: if we cannot recover your keys, neither can anyone else — including us under legal compulsion. You can create a new account and start fresh, but old messages are unrecoverable by design.

Yes. The key used to unlock your message travels only in the URL fragment — the part after the # symbol. URL fragments are never sent to our servers. Only the person who receives the email can access that key.

The message and all its attachments are permanently deleted from our servers. There is no recovery path — for you, for us, or for anyone else.

Encrypted ciphertext, public keys, and encrypted key backups. We never store plaintext messages, decryption keys, or your backup password. A subpoena of our servers would yield only data that cannot be decrypted without keys we do not hold.

Yes. The service must not be used to transmit threatening, extortionate, harassing, or illegal content of any kind. Because Owl's Hour is technically unable to read encrypted secrets, users bear sole and full responsibility for the content they encrypt and schedule for delivery. Misuse may result in immediate account termination and, where required by law, cooperation with competent authorities.

Owl's Hour continuously monitors the security status of the cryptographic algorithms protecting stored secrets. If a cipher is found to be compromised or no longer considered secure, we reserve the right to proactively delete affected secrets before they can be adversarially decrypted. We will notify the sender by email before deletion wherever operationally possible. This is a protective measure — not a service failure — and users accept this possibility by using the service.