Security
What we protect, and what we will not pretend.
You are trusting us with words you may only get to say once. The least we owe you is a precise account of how they are stored — including the parts that are not reassuring.
What we guarantee
Encrypted in transit
Every connection to MyWishLetter is served over HTTPS with a certificate issued by AWS Certificate Manager. Session cookies are marked Secure and HttpOnly, so they are never sent over plain HTTP and are not readable from JavaScript.
Your files are encrypted before they leave your device
Every attachment — photograph, voice note, video or document — is encrypted in your browser with its own AES-256 key before it is uploaded. Our servers only ever receive the encrypted result. The plaintext of a file you upload never exists on our infrastructure at any point.
Administrators cannot open your files
Each file's key is sealed by a key in AWS Key Management Service whose policy grants decryption to the application alone. Our administrators — including the account owner — are able to manage that key but are explicitly not permitted to use it to decrypt. An administrator opening our storage console sees encrypted blobs they have no permission to unseal, and every decryption the application performs is recorded in an AWS audit log naming the caller.
Encrypted at rest
Letters live in Amazon DynamoDB, which encrypts every table at rest by default. Nothing is written to disk unencrypted, and no letter or attachment is stored in a publicly reachable location — the attachment bucket blocks all public access and refuses any request that is not over TLS.
Never publicly addressable
There is no URL that lists letters, and no letter can be reached by guessing an identifier. Reading a letter requires either your own authenticated session or a signed, expiring link issued to the named recipient.
Sign-in without a password
We use email sign-in links, so there is no password for us to store or for you to reuse. A sign-in link is valid for fifteen minutes, works once, and is cryptographically bound so it cannot be modified or extended.
Notifications never quote content
A delivery email tells the recipient that a letter is waiting. It does not include the letter's text. Neither does any push notification, log line, or error report.
Least-privilege infrastructure
The servers running MyWishLetter can read and write only MyWishLetter's own database tables and only its own payment credential. They have no access to any other system in our account, and payment secrets are held in AWS Secrets Manager where every read is logged.
Deletion means deletion
Deleting a letter removes the stored content, not just its listing. Deleting your account removes your letters, recipients and delivery history. This is free and needs no explanation from you.
An audit trail on privileged actions
Administrative actions are recorded to a separate audit log with the actor, the action and the time. Administrators do not read letter content in the course of support work.
What we do not claim
Plenty of products in this category imply more than they deliver. Here is what MyWishLetter does not do.
The letter text is not end-to-end encrypted
Your attachments are encrypted in your browser, but the letter's own words are not — to email a letter on the date you chose, our servers must be able to read that text at that moment, possibly years from now and without you present. So we can technically read letter bodies, and so could anyone who compromised our infrastructure. We restrict, log and design against that, but we will not call the product end-to-end encrypted or zero-knowledge, because for the letter text it is neither.
Nor is it zero-knowledge for files, strictly speaking
We hold the sealed key to each of your files, even though we are not permitted to unseal it. That is a deliberate trade: a scheme where only you held the key would mean a letter scheduled for 2038 could never be delivered if you forgot a password or were no longer here — which would defeat the purpose of the product. The account owner can, in principle, change the key's policy to grant themselves decryption; doing so leaves a permanent record in the audit log. Removing even that ability requires organisation-level controls we have not yet put in place, and we would rather write that down than imply a guarantee we cannot make.
We are not a legal will
A letter delivered on a condition you set has no legal force. It does not transfer property, appoint a guardian or replace a will. Please talk to a lawyer for anything that must hold up legally, and use MyWishLetter for the words a will has no room for.
Email is only as private as the inbox
Once a letter is delivered, it lives in your recipient's email account under their control and their provider's policies. We cannot recall a delivered letter, and we cannot protect it there.
We have not been independently audited
MyWishLetter has had no third-party penetration test or SOC 2 audit. When that changes we will say so here, with a date. Until then, treat these statements as our own description of our own system.
Reporting a vulnerability
If you have found a security problem, please email support@mywishletter.com with enough detail to reproduce it. We will acknowledge you within three working days. We will not pursue legal action against anyone who reports a flaw in good faith, does not access other people’s letters, and gives us reasonable time to fix it before publishing.
For what we collect and how long we keep it, see the privacy policy.