The short version
New letter content and private media use end-to-end encryption. Delivery metadata does not. Anyone who obtains the complete private recipient link may be able to decrypt the letter after its opening time, so the complete link must be treated as a secret.
1. When the sender posts
The sender's browser generates a random decryption key. The heading, message, closing and private-media details are encrypted locally before the encrypted payload is sent to Intezaar.
Private photos, voice notes and videos are also encrypted in the browser before upload.
2. What Intezaar stores
Intezaar stores encrypted ciphertext and the delivery information needed to operate the service. It does not store the decryption key for new end-to-end encrypted letters.
The key is carried in the complete recipient URL after the # character. That part of a URL is a browser fragment and is not sent to the Intezaar server as part of the normal page request.
3. Why the letter still cannot open early
End-to-end encryption and timed release are separate protections. Before the chosen opening time, Intezaar does not release the encrypted message payload or private-media download URLs to the recipient browser.
At the chosen time, the server can release the ciphertext. The recipient's browser then uses the key from the complete private link to decrypt it locally.
4. What remains visible to Intezaar
Some information must remain readable for delivery to work. Depending on the letter, this can include sender and recipient names, optional email addresses, occasion, format, route labels, opening and expiry times, file type and size, letter status, security events and email-delivery status.
So the accurate claim is: the letter content and private media are end-to-end encrypted. It would be inaccurate to say that every piece of delivery metadata is hidden from Intezaar.
5. The complete private link is the key
If the #k=... part is lost, Intezaar does not have a stored copy of that key to reconstruct it. If the complete link is forwarded to someone else, that person may be able to decrypt the letter once it becomes available.
For that reason, treat the complete recipient link like a private key and send it only to the intended recipient.
6. Registered Intezaar Mail
Registered Intezaar Mail can add an email one-time-code check before the encrypted payload is released. The email notice itself does not contain the end-to-end decryption key, so the sender still needs to share the complete private link separately.
This is an Intezaar verification feature, not postal registered mail and not proof of legal service.
7. Analytics on recipient pages
Advertising measurement and web-analytics components are disabled on private /receive/ pages because the recipient's browser may hold the decryption key in the URL fragment.
8. Older letters
Letters created before the end-to-end encryption upgrade may continue to use the earlier server-side encrypted format until they expire. That compatibility path exists so previously posted letters are not broken.
9. Limits of end-to-end encryption
Encryption cannot protect a compromised device, stop an intended recipient from copying the letter after opening, prevent someone from forwarding the complete private link, or guarantee that software will never contain a security defect.
For more detail about storage, retention and service providers, read the Privacy Policy.
10. Public-beta reliability
Intezaar is not permanent archival storage. Current letters are assigned an expiry 90 days after their opening time, and availability is not guaranteed indefinitely. Keep your own copy of anything irreplaceable.