Skip to content
Afterward

Trust

We hold the pages.
We can’t open the envelope.

Your binder is a working document. We keep its pages on our servers so you can read them anywhere, and so the people you name can read them when it matters. The few details too sensitive for any page, you seal on your device — and we cannot read sealed details. Not us, not anyone at the company that built this.

Below: where that line sits, in plain language — what we hold, what we cannot read, and the trade-offs we made on purpose.

A small brass key resting quietly on a folded handwritten note, in cool natural light

The pledge

  1. 01

    The details you seal are closed on your device, before they ever reach us.

  2. 02

    We cannot read sealed details. The means to open them never reaches us.

  3. 03

    You can export your binder, and no plan takes that away.

The ledger

What we hold, and what we can’t read.

A short, honest accounting. The left column is what sits on our servers, and why. The right column is what we could not read if we tried.

We hold

  • 01

    The pages of your binder.

    Stored so we can show them to you anywhere, and to the people you name when it matters.

  • 02

    Your sealed envelopes, still sealed.

    We can store them, move them, deliver them. We cannot open them.

  • 03

    Your account email, sign-in state, and billing references.

    Stripe holds the card itself.

  • 04

    The names and contact details of the people you choose.

    So we can deliver the read-link if and when it’s needed.

  • 05

    A record of shares, edits, and check-ins.

    When something changed and who it went to — the record itself carries no contents.

We cannot read

  • 01

    The three details you seal.

    Your phone passcode, your primary email password, your password manager’s master password — closed on your device before they ever reach us.

  • 02

    Your backup code.

    Made on your device, saved by you, somewhere we’ve never been.

  • 03

    The keys that open a sealed envelope.

    Your device holds yours. The people you name hold theirs. We don’t.

Everything in the left column stays yours to edit, export, or erase. The ledger is what we hold, not what we own.

Two ways a sealed envelope opens

Your phone, or the code you tucked away.

The pages of your binder open with an ordinary sign-in. The sealed envelope asks for more: one of two doors, and we never made the second one optional, because the first one fits in your pocket and pockets get lost.

Door one

The phone in your hand.

When you reach for a sealed detail, your device proves it’s yours the same way it unlocks your banking app: your face, your fingerprint, the passcode it already trusts. From that, the envelope opens.

The proof never leaves the device. We see only that the door was opened, not the key that opened it.

Used whenever you reach for a sealed detail. Quiet, one-tap, never types a password.

Door two

A backup code, written down.

On the day you sign up, Afterward generates a backup code and asks you to save it somewhere private: a safe, a wallet pocket, an envelope tucked inside a book.

That code is the second way in. It opens the same sealed envelope if your phone is ever lost, broken, or replaced. We do not know what it is.

Used rarely, perhaps never. There the day you need it.

Both doors open the same envelope. Not two copies of what you sealed, two ways to reach for it.

If something goes wrong

What happens when the phone is lost, and the harder question we won’t pretend away.

If you lose your phone

The pages of your binder come back the moment you sign in again — they were never locked to the phone.

The sealed envelope asks for the second door: you enter your backup code, the whole code is verified, and the new device is quietly enrolled as another way in.

If you lose the backup code too

We can’t open a sealed envelope for you. Not because we won’t: the envelope was closed on your device, and the means to open it never reached us. Your pages are still here, but what you sealed would need to be sealed again, fresh, on a device you trust.

This is a trade-off we made deliberately. Every product that promises a way back in for the forgetful holds the means to read your most sensitive details on a quiet day. We don’t want to.

The honest list

What we protect against, and what we don’t.

Every product in this category quietly hopes you don’t ask. The list below is the one we’d want you to read before you trust us with anything.

  • We protect

    Your sealed details, in a breach of our servers.

    An attacker would find your sealed envelopes exactly as we hold them: closed. Opening one takes keys that never reach us.

  • We don’t

    Your binder pages, in a breach of our servers.

    Pages are guarded the way careful services guard data — locked doors, narrow access, a record of who entered — but they are not sealed the way sealed details are. We won’t pretend that difference away; it is why the three most dangerous details get the envelope.

  • We protect

    Someone at Afterward opening a sealed envelope.

    No employee, founder, or engineer can read a sealed detail. The capability does not exist to be misused.

  • We don’t

    Someone at Afterward reading a binder page.

    Access to production systems is restricted to the few who run them, and it leaves a trail. That is discipline and audit, not mathematics — the honest difference between a page and a sealed envelope.

  • We protect

    Losing your phone.

    Your pages come back the moment you sign in again. The sealed envelope opens from a new device with the backup code you saved.

  • We don’t

    Your device being read while it is unlocked.

    If someone is using your phone while you’re signed in, we can’t tell the difference between you and them. Your phone passcode is your last line.

  • We don’t

    Sharing your backup code with the wrong person.

    The code opens what you sealed. Anyone holding it holds that door. We tell you this plainly the day you make it.

  • We don’t

    A determined attacker watching your screen.

    No technology fixes shoulder-surfing. What the binder shows you is still yours to handle with care.

A paper calendar on a desk with a single quiet day marked, beside a sealed envelope

The courtesy interval

We don’t release the binder until we’re sure you can’t reach for it yourself.

If you stop opening Afterward for sixty days, we send a quiet note asking if anything has changed. A check-in, not an alarm.

If we still don’t hear from you after that, the people you named can ask to read what you left them, and you have seven days to say no. Answering the note — or simply opening Afterward — resets the clock.

Most of the time, no one ever needs this. It runs in the background like a thoughtful friend, so the binder can do what it’s there for.

A small archival packet of papers tied with linen string beside a thumb drive on a desk, ready to be carried out

If you decide to leave

Take your binder with you, the day you go.

Your binder belongs to you, not to us. At any time, on any plan, you can download the printed copy or a portable archive: every page, in plain files your family could read without our help, without our software, without us.

The sealed envelopes are the one thing an export leaves out, on purpose. Sealed details never travel in a file; they have their own reveal-and-print flow, made for paper you keep somewhere safe, one detail at a time.

The day you decide we aren’t for you is the day you walk out with your binder. Close the account, and we delete what we held on the schedule the privacy policy sets out.

The audit ledger

The work that earns the words on this page.

We did not put logos here. The category does that, and they all blur. Below is the actual schedule.

  • SOC 2 Type II

    In progress

    Audit window opened February 2026 with a regional firm specializing in consumer privacy products. Report expected mid-July.

    Target · 2026-07-15

  • Independent security review

    Selecting

    A specialist firm will review the sealed-envelope architecture and the backup-code path before v1 launch. Selection is in progress; the public summary will be linked from this page once the engagement begins.

    Engagement · pre-launch

  • Penetration testing

    Recurring

    External pen test before every named release, plus an annual full-scope test. Findings go to the engineering team and to a public changelog after remediation.

    Cadence · per release + annual

  • Security whitepaper

    In draft

    A public, plain-language description of the sealed-envelope architecture, recovery model, and threat boundaries. This is the document a security-minded reader can hold us to — the claims on this page, written down precisely.

    Publishing · with v1

For the technically curious

The same story, with the architecture in view.

Open this if you want the architecture summary, not the metaphor. It is the same story, written for a security-minded reader.

Where the line sits
Your binder’s pages — the section fields, the contact details, the where-things-are — are stored on our servers as structured records, so we can render them to you and to the people you name. Exactly three details are different in kind: your phone passcode, your primary email password, and your password manager’s master password. Those are sealed on your device, and the rest of this ledger is about them.
The sealed-details key
A long random key is created on your device. It seals the three details, and only those. The key itself never leaves your device for our servers — not at setup, not ever.
First way in
Your device proves itself the same way it unlocks your banking app. The proof is converted into a wrapping that holds the sealed-details key. We see only that the proof checked out, not the proof itself, and the wrapping never leaves your device unsealed. Adding a second device wraps the same key again, so we never have to re-seal what you already closed.
Second way in
A backup code, generated on your device, is run through a slow, memory-hard derivation to produce a second wrapping for the same key. This path is mandatory: the binder does not open for the first time until the code exists and you have acknowledged putting it somewhere private.
Sealed envelopes
For each of the three sealed details, an envelope is sealed against the named recipient’s public key on your device. The sealed envelope is opaque to us. Only the recipient’s device, holding the matching private key, can open it.
Server boundary
Our servers store binder pages as records, sealed details as opaque ciphertext, wrapped keys, and account metadata. Route handlers never have access to an owner’s private keys, and the sealed tables hold ciphertext and nonces only — a boundary enforced in code review on every change that touches it.
Recovery from a single device
Lose the phone, sign in with the backup code, enroll the new device, and the sealed-details key is re-wrapped for it. Lose both the phone and the code, and the sealed details are unrecoverable by design — your pages remain with your account, but what you sealed must be sealed again. This is the same trade-off Bitwarden, 1Password, and Apple Advanced Data Protection make for their vaults, and we make it deliberately.

The full security whitepaper, with the cryptographic primitives named in the precise vocabulary, publishes alongside v1. If you have questions before then, write to  security@afterward.care.

Begin in five quiet minutes.

Free to start. No card. Export your binder anytime, including the day you decide we’re not for you.