It is not zero-knowledge
Many digital vaults announce that not even their publisher can read their users' data. We do not say that, because it would not be true.
For your trusted contact to open your vault when the day comes, our server has to be able to send them a readable backup password. So our server has to be able to decrypt it. That is imposed by the transmission mechanism itself; no technical trick gets around it. The same mechanism is used when you ask to reset your password.
Put bluntly: someone holding both a copy of our database and our server encryption key could reconstruct the contents of a vault.
What we do so that this does not happen:
- that key is never written to a log, and is never stored in the same place as the database backups;
- backup passwords are held in a server-side vault encrypted with AES-256-GCM, with key rotation;
- our administration tool displays no vault content: no preview, no excerpt, no "reveal" button. No such function exists, not even disabled;
- every administrator action on an account is written to an immutable log, before it is executed, and kept for five years.
One clarification, so that nothing stays vague: switching off automatic unlocking prevents any transmission, but changes nothing of the above. The backup password exists from the moment you sign up, since it also serves to reset your password.
We do not say "nobody but you can read your data"
The exact wording is this: in normal operation, nobody reads your data. Not our administrators, not our back-office, which does not know how to display it. But "nobody does" is not "nobody can". We will not conflate the two, and we invite you to be wary of any service that does.
There is no two-factor authentication
No six-digit code, no authenticator app.
What does exist, and protects the setting with the heaviest consequences: any change to the trusted contact, the delay or automatic unlocking is held pending and must be confirmed from your mailbox, through a link valid for ten minutes. Until you have clicked, the previous setting stays in place. That is real protection, but it is not two-factor authentication, and we will not call it that.
The advance notice rests on a single e-mail
Two days before the deadline, we send you a message to warn you. That is the only warning: there is no in-app notification, no text message, and no second reminder.
If it lands in your spam folder, if your account's address is no longer being read, or if you are simply away during those two days, nothing else will alert you — and the transmission will happen on the date set.
So the only thing to watch remains the date shown on your dashboard. Choose a delay that leaves you room, and push it back without waiting for the last day.
Your vault's contents live on our servers, not on your machine
On your computer, SafeTale keeps only your preferences: theme, language, a few display settings. No vault content. That is what lets your trusted contact reach it from another PC, and what protects your data if your machine is lost, stolen or destroyed.
It is also what makes your vault dependent on our service, and there is no export function yet. Advice we would apply to ourselves: do not make SafeTale the only copy of what is vital.
It is not a will
A text written in SafeTale's journal has no testamentary value. Under French law, a holographic will must be written in full, dated and signed in your own hand (article 970 of the Civil Code).
SafeTale serves to pass on access, codes, explanations, words. Not to organise an estate. For that, see a notary. The two are complementary; they do not replace one another.
We do not sell an availability guarantee
SafeTale is free. We take backups, we monitor, and we receive an alert when a transmission fails. But behind this service there is no service-level agreement, no availability commitment and no on-call rota. We do not sell you a guarantee, because we do not sell you anything.
The code has not been audited by a third party, and it is not public
No outside firm has audited SafeTale, and it carries no certification.
What we can show instead: 190 contract tests on the server; cross-implementation cryptographic vectors that lock the Windows and server implementations together, so that a divergence in one makes the other's tests fail; and a deny-by-default stance on any undeclared network origin. That is verifiable in fact. It is not an audit, and we will not present it as one.
SafeTale runs on Windows only, and accepts one trusted contact
No mobile app, no browser access. The "Phone" section serves to store your phone's codes, not to open SafeTale from it. Practical consequence: pushing your delay back requires a Windows PC.
You can name one person only, and there is no backup recipient. If, when the day comes, their address no longer exists, the e-mail goes nowhere and nobody else is notified in their place. We are alerted to the failure and can send it again, but we cannot guess another recipient.
Finally, that backup password is sent by e-mail: its confidentiality therefore also depends on your trusted contact's mailbox. We chose this trade-off for a precise reason: on the day that message arrives, the person receiving it has neither the time nor the presence of mind to set up something complicated.