Security & Privacy
A plain-language guide to how your sealed messages stay private — from the moment you write them to the moment they're finally opened, however many years that takes.
The short version: when you send a Vault Dispatch, it's scrambled into unreadable gibberish before it ever leaves your device. Only the person you're sending it to — using a digital key only they hold — can turn it back into readable words. Not Remea, not our servers, not anyone in between.
It means your message is locked on your own device before it's ever sent anywhere, and it only gets unlocked on the recipient's device when they open it. At every point in between — while it's traveling, while it's sitting on our servers waiting to be delivered — it exists only as scrambled, meaningless data. There's no point in that journey where anyone could read it, even if they wanted to.
No. This isn't a policy promise we're asking you to trust — it's a mathematical one. We never have access to the key that could unlock your message, so even if someone wanted to read it, including us, there's genuinely no way to. The lock and the key are handled entirely on your devices, not ours.
Every Remea user has two keys that work as a pair: a public key, which can be freely shared and is used to lock things for you specifically, and a private key, which never leaves your control and is the only thing that can unlock what was locked with your public key. When someone sends you a dispatch, it gets sealed using your public key — and from that point on, only your private key can open it. Not even the person who sent it can unlock it again once it's sealed.
Your private key is normally kept only on the device where it was first set up. To make sure a new device doesn't mean losing access, Remea also keeps a securely locked backup copy — one version unlocked by your account password, and a separate version unlocked by a one-time recovery code you're given when you set things up. On a new device, entering either one restores full access, with nothing lost.
Because it's your safety net if you ever forget your password. If you lose your password and your recovery code and the original device — there's no way back in, for anyone, including us. That's the honest trade-off of a system built so that nobody but you can ever read your messages: the same design that keeps everyone else out also means there's no "reset" button that quietly lets someone else back in. Save that code somewhere durable — a password manager, a printed copy somewhere safe — the day you're shown it.
When you designate a Legacy Contact, a copy of your private key is sealed specifically for them, using their own public key — the same locking method used everywhere else in this system. That sealed copy sits completely inactive and unreadable to them while you're alive. It only becomes accessible after your account has been formally, deliberately verified and activated as a memorial through Remea's legacy process — never automatically, and never based on a guess.
No. The sealed copy of your key is invisible to them entirely until your account is actually activated as a memorial — that's enforced by the system itself, not just a setting they're asked to respect. Choosing someone as a Legacy Contact is about making sure your dispatches can eventually be opened by someone you trust — it doesn't open anything early.
Then only you can ever unlock your dispatches — using your password, your recovery code, or a device where your key is already saved. There's real, permanent value in setting up a Legacy Contact if the point of what you're sending is for it to eventually reach someone else. Without one, that decision is left entirely in your hands, for as long as you're the only one holding the key.
They're sealed the exact same way as any other dispatch — the time-lock only controls when the recipient is allowed to try opening it within Remea, not how strong the underlying lock is. The message itself stays just as unreadable to everyone else, for as long as it takes to reach that date.