Pastpond — Terms of Service
Last updated: 2026-09-08. Provisional v0.15.
This is the binding agreement between you and NATIFY LIMITED when you use the service at pastpond.com. NATIFY LIMITED is a company incorporated in the Abu Dhabi Global Market (ADGM), registration number 17201, and operates Pastpond. "We" and "us" mean NATIFY LIMITED.
1. What Pastpond is
Pastpond is a software service that lets you store personal memories — photos, documents, written messages — encrypted, replicated across cloud infrastructure, and released to people you designate under conditions you set.
Encryption and release are the two halves of that sentence and they trade against each other. Until a release condition is met, your capsule is encrypted with a key we do not have and we cannot read it. When one is met, we open that capsule for the people you named, and from that point we can read it too. Note that a fixed date and a beneficiary's age can both be met while you are alive and checking in — a release is governed by the condition, not by whether you are still here. There is also one route that does not begin with a condition you chose: if you configure no plan at all, Section 6's default applies. Section 4 sets out what we can and cannot see in each state, and Section 6 sets out both routes.
2. Your account
You must be at least 18 years old to create an account. One account per person. You are responsible for keeping your sign-in email, any passkeys you add, and your encryption passphrase safe.
3. The passphrase. Critical.
Your data is encrypted on your device using a key derived from your passphrase. We do not store your passphrase. We cannot recover it. If you lose it, your access to your capsule is gone permanently. No part of that is recoverable by us.
One thing survives a lost passphrase, and only one: a release. If a release condition has been met for someone you named, that release does not depend on your passphrase and it still reaches them (Section 6). Losing the passphrase costs you your own access; it does not cost the people you named the memories you left them.
This is not a way back in for you. A release cannot be triggered by your having forgotten a passphrase, it opens the capsule for the people you named rather than for you, and there is no support route that will use it to restore your own access. If you lose your passphrase, your access is gone.
We strongly recommend you write down your passphrase and store it physically with a person you trust or in a locked container.
4. What we can and cannot see
We can see your email address, account metadata, the size and type of items you upload, and the beneficiary email addresses and release conditions you set.
While your capsule is sealed — that is, until a release condition has been met, or Section 6's default has applied to a capsule for which you configured none — we cannot see the contents of your uploaded files or your AI-generated descriptions (encrypted on your device before storage). We never see your passphrase or any key derived from it, in any state.
After a release we can see the contents of the released capsule. Once a condition you set is met, that capsule is opened for the people you named and is readable by us as well. This is how the release works: there is no code or key that the person has to have been given while you were here, so the capsule is opened with a key we hold. The rule that it is opened only once the condition is met is enforced by our systems, not by encryption. We say so plainly rather than implying that mathematics prevents us from opening it early; it does not.
A capsule whose conditions have not been met stays sealed to us, with the one exception Section 6 sets out: the anonymized-donation default, which applies precisely because you set no condition. A release opens one capsule, not your account.
How AI processing works: when your capsule organizes a photo, your device decrypts it and sends it, via our server (held in memory only, never written to disk), to our AI provider OpenAI, which returns a description. The same path places photos on your timeline, and — only when you ask for it — writes your story from descriptions already produced this way plus the milestones you confirmed yourself. Your files are never sent for story writing. OpenAI retains API data for up to 30 days for abuse monitoring and does not use it to train models. Everything returned is encrypted on your device before it is stored, so while the capsule is sealed we hold only ciphertext; a release opens the descriptions along with the memories they describe.
5. Storage duration plans
You may purchase an active capsule as a Single or Family plan, billed monthly or annually. All plans are auto-renewing subscriptions and renew automatically until you cancel.
Lifetime plans are not sold to the public.
If your subscription ends or is not renewed, your capsule goes cold — it is not deleted. Archive storage is free and has no end date: what you already stored stays stored, and you can still sign in and read it. What stops is everything that needs an active plan — uploading new files, adding notes, AI organising, and story writing — until you subscribe again. We do not delete a capsule for non-payment. Deleting your account and its contents is your decision alone, from Settings.
6. Beneficiaries and succession
You may designate one or more beneficiaries and configure release conditions. The default succession behavior is a 12-month escrow window after a passing is verified or a missed-check-in trigger fires, after which the configured releases execute. That window exists so a trigger that fired in error can be undone: when it opens we email you, and one click stops it. Stopping it is yours to do — there is no process by which anyone else can claim or contest a release, and we do not adjudicate between the people you named and anyone who is not on your list. If no plan is configured, the default is anonymized donation to a public repository, not erasure. You may change this default at any time.
What "the configured releases execute" means, stated in full. When a release to the people you named executes, three things happen at once, and the second is the one this section exists to disclose:
- We email each person you named a link, and send a one-time code to the address you gave for them when they open it. Nothing had to be handed to them while you were here, and nothing they were given can be lost — but a link on its own, forwarded to somebody else, does not open anything.
- The capsule becomes readable by us. It is opened with a key we hold, so from the moment the release executes we are able to read what it contains. Before that moment we cannot.
- The release stands. We can stop a link working, but a link that has already been opened cannot be taken back — what has been read has been read.
The line between 1 and 2 is a rule our systems follow, not a property of the encryption. Nothing arithmetic stops a release being opened early; our own code is what stops it. We state this because the alternative — a design in which only a code held by your recipient could open the capsule — is the design this replaces, and it failed for a reason worth naming: a code that has to survive for years in a drawer and be found again by someone else is the most likely way for a capsule to be lost forever.
The anonymized-donation default, stated in full and before it operates. The default named above is not a release to a beneficiary and it emails nobody a link. In the way that matters most it is the same kind of event, so it gets the same three points:
- Nobody is sent anything. There is no recipient to name, because you named none.
- The capsule becomes readable by us. It is opened with a key we hold, exactly as a release is.
- The contents are published, and publication cannot be undone. They are contributed, stripped of your account identity, to a public repository. Anything published can be copied, cached and indexed by people we have no relationship with — so deleting it afterwards means we remove our copy, not that the material stops existing anywhere.
Two things we will not overstate. "Anonymized" means we remove what identifies the account — your name, your email address, the people you named. It cannot mean we remove what identifies you from inside your own memories: a photograph of your face is still a photograph of your face, and we will not pretend otherwise. And no donation route is in operation today. This section is being changed before one is, which is what Section 12 requires of us; until that change has taken effect and a route exists, an un-configured capsule is neither read nor published. If you do not want this default, configure a release plan, or delete your account and its contents from Settings. You may change the default at any time.
7. Service availability
We make our best effort to maintain durability and availability of your capsule across redundant infrastructure providers and jurisdictions. We do not promise uninterrupted access. We do not promise that any single provider, jurisdiction, or technology underlying the service will exist for the full duration of your subscription.
8. Acceptable use
You may not upload material that is illegal under applicable law, depicts the sexual abuse of minors, is intended to threaten or harass a specific person, or contains malware.
You may not connect a public profile that is not your own, or import another person's posts, unless you have a lawful basis for doing so. Connecting a profile requires no proof that it belongs to you, so this obligation sits with you rather than with a check we perform.
We do not screen capsule contents. For a sealed capsule we could not, whatever we decided (encryption — see Section 4); for a capsule released to the people you named we could, and we choose not to, because that release is a private inheritance and not a published one. A capsule that goes to the donation default is the one case where the output is published rather than inherited, and we will screen it before it is — publishing unscreened material is not a position we can take. If we receive a verified report of illegal content under applicable law, we will act per applicable law. We will also act on a verified report from a person whose posts were imported by an account — including suspending or terminating that account.
Which remedies are available to us depends on the capsule's state. For a sealed capsule, acting against the account is the only remedy the encryption leaves us; we cannot locate or delete an individual item on request. For a released capsule we can, and on a verified report we will remove the individual item as well.
9. Succession and disclosure
If we receive a verified report of your passing from a designated beneficiary or appropriate authority, we begin the succession process you configured. We do not voluntarily disclose your capsule's existence or contents to anyone other than your designated beneficiaries, with two exceptions and no others: under lawful legal compulsion, and the anonymized-donation default in Section 6, which applies only to a capsule for which you configured no plan and which publishes rather than discloses privately.
That last exception means something different before and after a release, and you should know which. While your capsule is sealed, a lawful demand for its contents is one we cannot satisfy — we hold ciphertext and no key, so there is nothing to produce. Once a capsule has been released we hold the key, and a lawful demand for its contents is one we can be compelled to satisfy. We will resist demands we consider unlawful or overbroad and will notify you, or the people you named, wherever we are permitted to. But we will not tell you that a released capsule is beyond legal reach, because it is not.
10. Termination
You may close your account at any time. On account closure with no succession plan, your data is deleted within 30 days from active storage and within 90 days from backups, together with any key material held for it.
One narrow record survives, and we name it here rather than leave it to be found. For every message we have sent you we keep a send-once record: a one-way digest of the destination address — never the address itself — a short reason code, and the dates. It is what stops a message being sent twice, so deleting it would re-arm it rather than free anything. The Retention section of the Privacy Policy sets out exactly what it holds and what a digest does and does not protect.
This is not the same event as Section 6's default, and the difference is the whole point. Closing your account is you instructing us to delete, and we delete — the donation default does not apply to it and never overrides it. Section 6's default applies only to a capsule you left in place and configured no plan for, where the alternative to donation is not deletion but an escrow nobody can ever open. If you want deletion rather than either, close your account.
A capsule that has already been released is not deleted by your closing your account. A release is meant to outlast you, so it survives closure — the people you named keep what you left them, and the keys that open it are kept for as long as it exists. If you want a released capsule deleted, ask us and we will delete it.
11. Liability
To the maximum extent permitted by law, our total liability to you for any claim arising from the service is limited to the amount you paid us in the 12 months prior to the claim.
12. Changes to these terms
Material changes will be communicated to you by email at least 30 days in advance. Continued use after the effective date constitutes acceptance.
13. Governing law
These terms are governed by the laws of England and Wales. Any dispute arising from them, or from your use of the service, is subject to the exclusive jurisdiction of the ADGM Courts.
If you use the service as a consumer, nothing in this section deprives you of the protection of the mandatory laws of your country of residence, or of the right to bring proceedings there.
Contact
NATIFY LIMITED, Sky Tower, Shams Abu Dhabi, Al Reem Island, Abu Dhabi, UAE. Registered in the Abu Dhabi Global Market (ADGM), registration 17201.