Important beta notice
New letters posted through the current creator use end-to-end encryption for the written message and private media, but no online service can promise absolute confidentiality or uninterrupted availability. Do not use the beta for passwords, bank credentials, identity documents, medical records, privileged legal material or confidential business secrets.
1. Who this policy applies to
This policy applies to senders, recipients and visitors using the Intezaar website and public-beta letter service.
Intezaar is currently an early-stage project. The formal operating entity, registered address and dedicated privacy contact will be published before commercial launch. Until then, the service is offered only as a limited public beta.
2. Information you provide
Depending on how you use Intezaar, you may provide:
- sender and recipient names;
- recipient email addresses for optional registered delivery or delivery notices;
- a sender email address when you explicitly ask for a one-time notification that a particular letter has been opened;
- occasion, opening date and time, and optional origin or destination city;
- the written letter, heading and closing;
- photographs, voice notes, videos, captions and photo-layout choices; and
- information included in a safety, support or legal request.
Only provide another person's email address or personal information when you have a legitimate reason to contact them and doing so respects their wishes and rights.
3. Information created automatically
The service may create or receive technical and operational information such as:
- random private access and management tokens, which are stored as one-way hashes;
- letter status, creation time, opening time, expiry time and delivery events;
- the first recorded time a recipient breaks the seal after arrival, when that event is available;
- whether a sender enabled a one-time opened-letter notification and whether that notification was sent;
- security-check results from Cloudflare Turnstile;
- basic request, error, device, browser, network and hosting logs;
- email-delivery status and provider message identifiers; and
- storage paths, file sizes, file types and encrypted-media upload status.
4. Browser-local information
Intezaar uses local storage and session storage to preserve a draft, optional email fields, the latest secure recipient link, posting state and parts of the recipient experience. This information remains on the device until it is removed by the browser, the user or site updates.
For a new end-to-end encrypted letter, the sender's browser generates the private decryption key. The complete recipient link contains that key in the URL fragment after the # character. The fragment is used by the recipient's browser for local decryption and is not sent to Intezaar's server as part of the page request.
Selected media initially exists as a browser-local file and preview. It is encrypted in the browser and uploaded only when the sender completes secure posting.
5. How private letters are protected
For new letters posted through the current creator, the heading, written message, closing, attachment names, captions and photo-layout choices are encrypted in the sender's browser using authenticated encryption before the encrypted payload is sent to Intezaar. Private media files are encrypted in the sender's browser before upload to the private storage bucket.
Intezaar stores the encrypted message payload but does not store the decryption key for these new letters. The key remains in the complete private recipient link. After the opening time, the encrypted payload is delivered to the recipient's browser and is decrypted there.
Before the selected opening time, the recipient's browser does not receive the encrypted message payload, private-media download URLs or the encrypted media files. The server continues to enforce the opening time before releasing them.
Some delivery information must remain available to Intezaar in readable form so the service can operate. This can include sender and recipient names, email addresses when provided, occasion, format, opening time, expiry time, route labels, file type and size, delivery status and security events. End-to-end encryption therefore applies to the letter message and private media, not every item of delivery metadata.
Letters created before the end-to-end encryption upgrade may continue to use the earlier server-side encrypted format until they expire. Those legacy letters can be decrypted by the Intezaar server after their opening time so that existing deliveries continue to work.
6. Private links, email and recipient verification
Anyone who obtains the complete private recipient link, including its decryption-key fragment, may be able to decrypt a new letter after the selected opening time. Keep the complete link private and share it only with the intended recipient.
For end-to-end encrypted letters, an automated Intezaar recipient email notice does not contain the decryption key. The sender must still share the complete private link with the recipient. This separation prevents Intezaar's email system from receiving or storing the key.
A sender can separately choose to provide their own email address after posting in order to receive one notification when that letter is first recorded as opened. This sender notification contains no letter text, private media, complete recipient link or decryption key. The sender email is stored as delivery metadata for that letter and is sent to Resend only when needed to provide the requested email service.
If Registered Intezaar Mail is enabled, the recipient must also complete the email one-time-code check before the encrypted payload and private-media download URLs are released. Registered Intezaar Mail is an Intezaar verification feature, not a postal service or proof of legal delivery.
7. Why information is used
Intezaar uses information to:
- create, secure, schedule and deliver a private letter;
- send an invitation or arrival-notice email when requested;
- send a one-time opened-letter notification when the sender explicitly opts in;
- record privacy-limited product events such as a seal being opened or a recipient choosing to start a new letter, without recording the private letter contents;
- preserve the selected recipient experience;
- prevent bots, abuse, fraud and unauthorised access;
- diagnose errors and improve reliability;
- measure general product usage and creation steps where permitted;
- enforce the User Agreement and Community Guidelines; and
- respond to valid safety, legal or regulatory requirements.
Intezaar does not sell private letter content or personal information and does not use the contents of letters for behavioural advertising.
8. Service providers and measurement
Intezaar currently relies on specialist providers to operate the beta:
- Vercel for website hosting, server functions, deployment, operational logs and first-party web analytics;
- Supabase for the database and private encrypted-media storage;
- Resend for optional invitation, arrival-notice and sender opened-letter email delivery;
- Cloudflare Turnstile for automated-abuse and bot protection; and
- Meta for optional advertising measurement only after the visitor chooses to allow it.
The Meta measurement prompt is delayed so it does not need to interrupt a visitor's first view of the product. If declined, the Meta Pixel is not loaded. Our configured Meta events are intended to measure page visits and creation steps, not the contents typed into a private letter.
Advertising measurement and web-analytics components are not rendered on private /receive/ delivery pages, where an end-to-end decryption key may be present in the browser URL fragment.
Private recipient pages can still send narrowly scoped first-party service events to Intezaar, such as “seal opened” or “write a letter back clicked”, so the delivery service can provide requested notifications and measure the recipient-to-creator loop. These events do not include the private message, media or URL decryption fragment.
These providers process limited information according to their own infrastructure, security and privacy terms. Data may be processed in countries outside the sender's or recipient's location.
9. When information may be disclosed
Information available to Intezaar may be disclosed when reasonably necessary to:
- operate the service through the providers listed above;
- investigate credible abuse, threats, exploitation, fraud or security incidents;
- protect users, Intezaar or the public from serious harm;
- comply with a valid legal request or applicable law; or
- support a future restructuring, transfer or formal launch, subject to appropriate notice and safeguards.
For current end-to-end encrypted letters, Intezaar does not hold the key required to decrypt the message content or private media. Private letters are not routinely read or manually reviewed.
10. Retention and deletion
A posted letter is assigned an expiry time 90 days after its selected opening time. A protected daily cleanup process deletes encrypted media from storage and marks the letter expired.
The current beta cleanup does not immediately erase every encrypted database field or operational event. Encrypted records, sender or recipient email-delivery data, security logs and backups may remain for a reasonable period for reliability, abuse prevention, debugging or legal compliance.
Browser-local drafts and session data remain under the user's browser controls. Clearing site data removes them from that device.
11. Service continuity and export
Intezaar is an early-stage beta and does not promise permanent archival storage. The recipient can currently save or print an opened letter as a keepsake, but there is no guaranteed bulk export or shutdown-export system.
If Intezaar plans a material service closure or migration, we intend to give advance notice where reasonably possible so users can preserve important content. This is an operational intention, not a guarantee of uninterrupted access, notice in every circumstance or recoverability after a technical failure.
12. Your choices
- Recipient email addresses are optional.
- A sender email address for a one-time opened-letter notification is optional and is collected only after an explicit opt-in.
- Media attachments are optional.
- You may copy and share the complete private link manually.
- You may allow or decline optional Meta advertising measurement.
- You can clear local browser data to remove saved drafts and local session information.
- Do not share a private link you no longer want used.
A complete account dashboard, withdrawal tool, privacy-request portal and self-service deletion control are not yet available.
13. Children
The public beta is intended for adults aged 18 or over. Intezaar is not designed for children, and users must not send sexual, exploitative or otherwise inappropriate content involving anyone under 18.
14. Security limits
Intezaar uses end-to-end encryption for new message content and private media, private token links, short-lived media URLs, server-side time checks, restricted storage and Cloudflare bot protection. However, a recipient can forward a complete private link, a device can be compromised, software can contain defects and third-party infrastructure can fail.
End-to-end encryption does not prevent an intended recipient from copying, photographing, saving or forwarding content after they decrypt it. Keep the recipient link private and retain your own copy of anything important.
15. Changes to this policy
This policy will change as the beta adds accounts, reporting, longer scheduling, payment or new storage controls. The last-updated date will identify the latest published version.
16. Privacy requests and formal contact
A verified privacy and safety contact address will be published before wider public or paid launch. During the limited beta, do not upload information that requires a formal confidentiality arrangement, guaranteed deletion deadline or regulated record-retention service.