How your letters are protected
What FuturePostman encrypts, how a recipient proves who they are, when a link stops working, what staff can see and where the protection ends.
7 minutes to read
A letter can wait for years, so it matters how it is kept. This article describes what the service does today, and says plainly what it does not do.
In short
- The recipients, the subject and the text of an email letter are encrypted before they are stored.
- The text of a paper letter, a greeting or sign-off you typed, and the name and address of its recipient are encrypted in the same way.
- Attached files and recordings are encrypted while they are written to disk.
- A recipient needs a private link, the right email address and an access code to open an email letter.
- The text of an email letter never travels by email. It is shown only on the FuturePostman page, after the recipient has unlocked it. The notice email holds the link, the access code and the names and sizes of attached files, not the files themselves.
The limits of that protection:
- The encryption is not end to end. The server holds the key and decrypts a letter whenever it has to deliver or show it.
- A paper letter goes to the print centre in readable form, because it has to be printed.
- A letter you publish in the gallery is public.
What is encrypted while a letter waits
| What | How it is stored |
|---|---|
| Email letter: recipients (To, Cc and Bcc), subject and text | Encrypted with AES-256 before it is saved. No readable copy is stored beside it. |
| Paper letter: text, a greeting or sign-off you typed, name and postal address of the recipient | Encrypted with AES-256 before it is saved. No readable copy is stored beside it. A greeting or sign-off that an older letter still holds readable is encrypted the next time the letter is saved. |
| Attached files, voice and video recordings | Encrypted with AES-256 on the way to the disk. No readable copy is written first. |
| The access code of a recipient | Not stored. It is made when the letter is sent and goes out in the notice email only. A spare code that a letter gets when you write it is erased once the letter is delivered. |
| File names, sizes and types. Dates, statuses and options of a letter | Readable. |
| Delivery records: for each delivered email letter, the address it went to and the time | Readable. They are deleted together with the letter, and with the account. |
| Your profile and your contacts | Readable. Every address you send an email letter to is saved as a contact. |
| A letter you share in the public gallery: name to show, tags and opening lines | Readable. The opening lines are stored readable only while the letter is approved. They are removed when the letter is not approved, taken out of the gallery or sent back to review. |
One key protects all letters and files. It is part of the configuration of the server and is not kept in the database, so the encrypted fields in a copy of the database cannot be read without it. There is no separate key per account, and you do not hold a key yourself.
What the encryption does not do
- It is not end-to-end encryption. FuturePostman can decrypt your letters, because it has to: to deliver them on their day, to show them to you in the app and to show them to the recipient.
- It protects stored data against someone who gets hold of the database or the disk. It does not hide a letter from the service itself.
- A letter you send to the public gallery is public once it is approved. See share a letter in the public gallery.
- When you use the AI writer, the instruction you type is sent to an outside AI provider. See the AI writer.
How a recipient opens a letter
You have received a message from the past
Email address
Access code
- On the delivery day every recipient gets a notice email with a private link and an access code. Each recipient has a link and a code of their own.
- To unlock the letter, the recipient types the email address the letter was sent to and the access code. Both have to match that link.
- The code is made at the moment of sending and goes out in the notice email only. FuturePostman does not store it, so neither you nor staff can look it up later.
- If a recipient has lost the notice email, send it again: in Manage Letters, open the details of the delivered letter and choose Send the notice again. The recipient gets a new link and a new code. The earlier ones keep working.
What the recipient sees step by step is described in what the recipient sees.
Attempt limits
- Only wrong tries are counted. After 3 wrong tries within 15 minutes the page says Too many attempts. To keep the letter safe it is locked for 15 minutes. Please try again after that.
- The tries are counted for one letter and one email address, from one network address. The right address and code are never counted, so another recipient of the same letter is not locked out by someone else's mistakes.
- A second, wider limit counts all wrong tries on one letter from one network address: 30 within 15 minutes, whichever email address is typed. It keeps someone from guessing with one address after another.
- An unlocked letter does not stay unlocked for ever. After 30 minutes without loading anything, reloading the page or downloading a file asks for the email address and the code again.
The numbers of these and all other limits are in all limits in one place.
When the link stops working
- The link works for the time you set under Link stays open for in the composer. The time counts from the delivery, not from the day you wrote the letter.
- After that the recipient sees This letter can no longer be opened. The letter itself stays in your account until you delete it.
- You can give a delivered letter more time: with Extend link in the details of the letter under Manage Letters, or with Extend Expiration on the Files page. Both extend the link and every file of the letter together, to at most 1 year from today.
- Files are deleted for good 30 days after their link has expired.
- You can also limit how often each recipient may download a file. See file sharing settings.
- When you delete a delivered letter, its recipients can no longer read it. Their link then says The sender removed this letter.
What staff can see
A staff account has one of two roles, admin or super admin. This is what the admin pages give each of them.
| What | Admin | Super admin |
|---|---|---|
| Accounts: name, email address, plan, usage and credit balance | Yes | Yes |
| The list of email letters: account of the sender, recipients, subject, status, dates, names and sizes of attached files | Yes | Yes |
| The text of an email letter | No | Yes, one letter at a time |
| A letter waiting for review for the public gallery: subject, text, name to show and tags | Yes | Yes |
| The list of paper letters: account of the sender, country, status, dates, credits and tracking number | Yes | Yes |
| A paper letter: text, name and postal address of the recipient | No | Yes |
| The content of attached files and recordings | No page for it | No page for it |
Paper letters
- In the FuturePostman database the text and the recipient address stay encrypted, as the table above describes.
- A paper letter has to be printed. On the posting day its text, the name and postal address of the recipient, your name and, if you chose to print it, your own address are sent to the print centre as a readable PDF. From then on the print centre holds a readable copy of the letter.
- From there it travels as ordinary mail. Anyone who opens the envelope can read it.
What you can do yourself
- Check the email address of each recipient. The link and the code go to exactly that address.
- Keep Link stays open for as short as the occasion allows.
- Leave passwords, card numbers and similar secrets out of a letter.
- Delete a letter or a file you no longer want stored. See your data and how to delete it.
- What your recipient sees and how they open the letterThe notice email, the unlock page, reading the letter and getting its files, step by step. You can pass this page on to a recipient who is stuck.
- Control how recipients open your filesDecide whether the files of a letter can be viewed online, downloaded or both, how often and for how long. Then follow, extend or delete them on the Files page.
- Your data and how to delete itWhat FuturePostman stores about you, how to delete a letter, a file or your whole account, and what stays behind afterwards.
- Privacy PolicyWhat is collected and why.