Show HN: Seal – Letters and passwords that open for your family after you die (github.com)

2 points by jpage2 ↗ HN
I'm a CS undergrad who has developed an interest in hardware keys ever since I used them for a school project a few years ago. I made a little chat app that only allows users to chat if they registered a key, nothing else.

The backstory of how I came to work on Seal (this project): was that I was generating ideas with Claude to come up with an idea that only hardware keys could make into software. I was thinking about physical house keys and what you could do with those, but in software. I was already making iOS apps with Claude, and I came up with this idea and it sounded good. I had already worked on a few projects involving hardware keys and I already loved them.

Today I submitted my latest app, Seal, for review in the app store. Seal is an iOS app for iPhone and iPad that lets you write an Envelope (an encrypted bundle of passwords, photos, voice memos, etc...) for all of your loved ones when you're gone.

You can register hardware keys and assign identities for each person. Then you can create Envelopes and assign them to the key that you want to distribute. They plug in the key to their phone and are ready to receive an Envelope from you.

If you don't log into the app for months, one of your designated key holders can start the process of opening the Sealed Envelope. You, as the writer of the letters, get weeks of warnings to check in at least once before the letters open.

After 90 days of countdown, 21 days of warnings, and 14 days of grace, the envelope opens for each person they met IRL and exchange keys with.

No one else can read the envelope or see the photos (even the key holders, Apple, or me) unless that envelope was designated for that person.

What's different from a password manager like 1Password: emergency access there hands one person your whole vault through the company's server, so it needs that company to still exist and be honest on the day it matters. Seal gives each person their own envelope nobody else can open, and there's no company in the middle.

There's also no server at all besides a free Cloudflare static site. The encrypted bundles of passwords and photos are in Cloud Kit. Sign-in/identity is a passkey Face ID/Touch ID or a Hardware Key. It's all Crypto Kit, so there's no dependencies required.

Currently, it's just me and Claude working on this. It hasn't been independently audited by anyone, and it's iPhone only for now. Please do not put a live seed phrase in it yet. If anyone has advice for me as the lead developer for this project, I'm all ears! You can help contribute on the github source code repository page if you'd like. My mom likes this app especially because she's into crypto and she needed a way to pass down or give away the seed phrases for her wallets to all 3 kids without any question about who gets what and when. In the end, there's no confusion or hurt feelings after the fact with just crypto. Thank you for reading and let me know if you have any questions or concerns for me or the project!

Source: https://github.com/jasonepage/Seal

Site with limits and objections pages: https://sealmessenger.com

Free on TestFlight while the App Store version is in review: https://testflight.apple.com/join/cYp9JRCG

14 comments

[ 1.0 ms ] story [ 62.0 ms ] thread
> the keys never leave the phones, and the record of who did what can be checked with a script that has no Seal in it.

What happens if someone loses their phone or buys a new phone? What happens if they forget to tell you that they need a new key?

Thank you for these questions!!

In an example, my mom holds a piece of my key. She upgrades her iPhone. She signs into iCloud, Face ID works, she opens Seal and it knows exactly who she is. Everything looks normal. But her piece of my key is dead, because that piece was locked to the old phone. She has no reason to suspect anything is wrong, which is why I need to fix this in the app ASAP I think. She needs to Seal her Envelopes again with the new phone's key.

She can also have a backup hardware key to restore the credential but she has to re-seal again as well in this scenario if she is logged out of her Apple account or broke her main hardware key.

> What is not done

Rewrite this Readme without Claude?

Also

> There's also no server at all besides a free Cloudflare static site. The encrypted bundles of passwords and photos are in Cloud Kit. Sign-in/identity is a passkey Face ID/Touch ID or a Hardware Key. It's all Crypto Kit, so there's no dependencies required.

To me, this clearly implies that there’s a server involved… Apple’s server. Am I wrong?

Ngl this is humbling I need to hit the textbooks or something because you're definitely right lol there has to be a server... It's just not Seal's server or decryptable by Apple, us, or anyone without the designated keys. It's Apple's Cloud Kit container so they can delete or deny access to any of it... which is a real fault. Also, the database is readable so counts, timing, account IDs and your rule(s) are visible. Also, Apple could decide to terminate my developer account with the container associated with it which would be devastating.
> If you don't log into the app for months

> After 90 days of countdown, 21 days of warnings, and 14 days of grace, the envelope opens

vs

> it needs that company to still exist and be honest on the day it matters

> there's no company in the middle

which is it?

there's no middleman, but also I need to log in to your app regularly to avoid being declared dead?

> I need to log in to your app regularly to avoid being declared dead?

Technically, until we get to a point where we still have embedded "life signal" chips, there's no way to automatically detect that someone has died. Other than those who've actually seen a body, the best we have is "not seen - at Y - for a while".

Yes ty for making that point! And it's worth mentioning that the letters open not close whenever someone goes inactive rather than are closed forever.
You're right, sorry I should have painted the picture in a better way because I just basically shifted the middleman dependency compared to 1password or something.

With a company ran vault, they can mess up by failing to exist, not being honest, and they have to make the correct decision when someone dies.

With Seal, no single person makes the decision when the person is gone/inactive. There's no company to decrypt anything, which is what I was trying to paint the picture of with "no company in the middle", but yeah you have to also make sure the software exists so they can check in.

The envelopes also will open when the user can no longer check in because the countdown will end and the family can use the keys to decrypt without a backend needed.

Very coool side project! how are you currently sourcing or curating the ads featured on the wall? is it an automated scraping pipeline or manual submission?
This project? or birthed.app? sorry for the late reply or if you we're talking about something else lol I curated them from wikipedia and gemini iirc
> there's no company in the middle

Yet this seems dependent on Apple's ecosystem. That's a company in the middle.

Why it's not also available in the web running client-side?
Sorry, it's just one person working on this so it can be hard to do multiple platforms at a time. We want to do Android and Web eventually.

I think the main thing restricting it though is that there's nothing in the browser where the person's piece of the key is locked to their phone's chip and cannot copied? Sorry I could be wrong