Terms of Service (Current Service Draft)
Version: current-service-draft-v0.1 Last updated: 2026-07-07
This page reflects the current For Later service. It still requires legal review before launch. This draft is not legal advice and does not replace advice from lawyers, accountants, medical professionals, or other qualified professionals.
1. Definitions
1.1 For Later / the Service means the private message creation, review, storage, conditional opening, recipient notice, and identity verification service provided by the platform.
1.2 User / Sender means a person who registers, signs in, creates messages, buys points, submits content, sets recipients, creates time capsules, or uses other service features.
1.3 Recipient means the person designated by a user, or the person who may receive notice after conditions are met and may view a message after completing the platform's required identity verification.
1.4 Private message / message means text content and related metadata created, submitted, stored, scheduled, reviewed, held for opening, or delivered through For Later.
1.5 Message Points are in-service credits used for messages, AI assistance, review, add-ons, special withdrawal, time capsule quota, and other platform features. Message Points are not cash, an electronic payment account, transferable money, deposits, securities, cryptocurrency, or withdrawable assets.
1.6 Mutual Unlock Message means a message mode in which both sides must actively create and submit messages to each other, and both messages must satisfy review, payment, verification, and safety requirements before they may enter a viewable flow.
1.7 Scheduled Unlock means a message mode in which content becomes viewable only after the selected date, or after a paid selected hour on that date. This is not a scheduled-send or guaranteed punctual notification service.
1.8 Time Capsule means a feature where a user creates a capsule, collects participant names and messages through a QR code or supported platform flow, stores approved entries, and opens them later according to the selected date and permission settings.
1.9 Opening date, opening hour, and open_at refer to when content starts becoming viewable. Paid opening-hour selection may be converted internally into a UTC open_at timestamp.
1.10 Notice means email, in-app notice, push, SMS, or other supported communication reminding a user or recipient about an available action or message. Notices do not include full private message content.
1.11 Identity verification means proving a reasonable connection to an identifier or account through email, phone, login, OTP, or another supported method.
1.12 AI review / automated review means classification, rejection, restriction, or flagging by AI models, rules engines, risk systems, or other automated tools based on content, names, metadata, behavior, or risk signals.
2. Nature of the Service
2.1 The service provides private message creation, storage, review, conditional opening, notice, and verified viewing.
2.2 The service is not a legal will service, estate planning service, asset transfer service, medical directive service, guardianship service, posthumous arrangement service, legal notice service, financial document custodian, password manager, or formal legal delivery service.
2.3 Users must not rely on the service for property, inheritance, medical, guardianship, death arrangements, debt, contracts, company matters, or other legally effective matters. Users should consult qualified professionals and use legally valid documents when needed.
2.4 The platform determines whether a message may enter a viewable or notice flow based on the product flow, payment status, review result, opening condition, notice setting, recipient verification, and safety checks selected or confirmed when the message was created.
3. Currently Supported Message Modes
3.1 The currently supported primary modes are Mutual Unlock Message, Scheduled Unlock, and Time Capsule.
3.2 The platform may also provide drafts, draft reminders, AI rewrite, AI drafting, account-capacity upgrades, paid opening-hour selection, special withdrawal, phone verification, and other supporting features. These supporting features are not necessarily independent message modes.
3.3 Future features such as Legacy Message, Future Self Message, Trusted Contacts, No-Response Release, Kind Words Pool, paper delivery, exports, or other features are governed by the terms and confirmations shown when those features launch. Unreleased features are not current service commitments.
4. Mutual Unlock Message
4.1 Mutual Unlock is designed so a message may be seen only when both sides actively choose to leave a message for each other.
4.2 If user A creates a mutual unlock message for user B or a specific identifier, B is not immediately told that A left a message.
4.3 Entering another person's email, phone, or identifier must not reveal whether that person has left a message. The feature must not become a lookup tool for discovering whether someone has messaged.
4.4 A reciprocal match may be evaluated only after B also creates, pays or holds points for, and submits a message that satisfies review and safety requirements.
4.5 Even after mutual conditions are met, the platform may require email, phone, login, or other identity verification before full content can be viewed.
4.6 Mutual unlock is not guaranteed. Failure or delay may result from the other person not creating a message, identifier mismatch, review failure, payment failure, verification failure, risk controls, disabled accounts, recipient blocking, or other platform policy reasons.
4.7 Ordinary email, SMS, or push notices must not contain full private message content.
5. Scheduled Unlock
5.1 Scheduled Unlock is not scheduled sending. It means a message becomes viewable only after the selected date or paid selected hour.
5.2 The basic feature supports an opening date. From that date, content may be viewed according to permissions and verification results.
5.3 If offered, paid opening-hour selection supports hours 0 through 23 and does not support minute selection.
5.4 The platform does not provide minute-level opening settings and avoids creating an expectation of exact-minute notification delivery.
5.5 Viewability is controlled by open_at. APIs may use now >= open_at to determine whether a recipient can view content. Notices are handled separately by notification_after and background notification systems.
5.6 If the user enables recipient notice, the platform only commits to trying to notify after the message becomes viewable. It does not promise punctual or immediate delivery.
5.7 Notices do not include full message content. The recipient must still complete platform verification before reading.
5.8 After formal submission, a scheduled unlock message may enter point charging, review, storage, and waiting-for-opening flows. Stopping later delivery is governed by special withdrawal, cancellation, point-release, refund, or other applicable rules.
6. Time Capsule
6.1 Time Capsule may be offered as event capsules and relationship capsules. Different uses may have different participation methods, viewing permissions, review modes, point rules, and paid add-ons.
6.2 Event capsules are for weddings, graduations, gatherings, company events, or other live multi-person message collection. The platform may let the creator generate a QR code or fill link and share it during a supported collection window.
6.3 Event capsule participants usually do not need to install the app to submit. The platform may require browser, device, IP, session, email, phone, or other checks for risk control and abuse prevention.
6.4 An event capsule fill form usually includes participant name, message content, submit button, and any required confirmations, verification, or risk-control fields.
6.5 Event capsule participant names and message content usually require AI, automated, or necessary manual review. Rejected content is not accepted or displayed.
6.6 Event capsules may have an expected contributor count or package quota. The platform may hold corresponding Message Points when the capsule is created. Actual capture should depend on approved and accepted entries and the rules shown at that time.
6.7 Event capsule rejected entries generally should not be charged as successful accepted entries. The platform may still charge for abuse handling, appeals, manual processing, or other incurred costs according to rules shown at the time.
6.8 Event capsule entries over quota may be kept as candidate or OVER_QUOTA_PENDING entries. Further review, acceptance, or charging depends on whether the creator adds quota and the platform rules then in effect.
6.9 Ordering and quota handling should primarily use submitted_at, received_at, or another platform-defined receipt time, not simply AI review completion time.
6.10 Relationship capsules are for partners, family, close friends, or similar participants leaving future content for a relationship. Participants usually need to sign in, use the supported app or web interface, and complete required identity verification before viewing content after the opening date.
6.11 Relationship capsules generally do not undergo ordinary AI content review at submission. Users are responsible for the content they submit. If content is reported, creates safety risk, is legally required, violates platform policy, or otherwise requires action, the platform may restrict content, preserve records, provide support handling, or cooperate through lawful process.
6.12 Time capsules do not guarantee every participant will submit, every entry passes review, every notice arrives, or every recipient views content.
6.13 Capsule content is not a legal promise, contract, will, financial arrangement, medical directive, or formal document.
7. Drafts, Pre-Submission State, and Special Withdrawal
7.1 Drafts are not formally submitted content. A draft does not mean a message has been sent, scheduled, reviewed, sealed, or put into a delivery flow.
7.2 Draft reminders help users return to review drafts. They are not scheduled unlocks or delivery commitments.
7.3 If the platform offers a short post-submit reversal period, charges, review, and formal records are governed by the rules shown at submission.
7.4 Special withdrawal is a paid or restricted feature for stopping later delivery after formal submission. Availability depends on message status, review status, notices, viewing status, payment status, safety checks, and platform policy.
7.5 If a message has already been viewed, exported, screenshotted, saved by the recipient, or processed irreversibly, special withdrawal may not undo those effects.
7.6 Special-withdrawal charges, refunds, point releases, and limits are governed by the screen shown at the time of operation and platform rules.
8. Message Points and Charging Rules
8.1 Message Points may be used for message creation, review, AI assistance, time capsule quota, opening-hour selection, special withdrawal, account-capacity upgrades, phone verification, and other features.
8.2 Message Points are not cash, electronic payment balances, transferable money, deposits, securities, cryptocurrency, or withdrawable assets.
8.3 The platform may distinguish paid points and bonus points. Bonus points may come from Open Beta, promotions, compensation, or other campaigns, and may have expiration, scope, refund, or deduction-order rules.
8.4 Charging may include hold, capture, and release. Hold reserves points, capture formally deducts points after conditions are met or service is provided, and release removes a hold when points are unused or rules allow release.
8.5 Actual charges, rejection fees, appeal fees, AI fees, special-withdrawal fees, opening-hour fees, time capsule fees, and other costs follow the screen, payment page, announcement, or effective policy shown at the time of operation.
8.6 The platform may adjust point pricing, charging rules, and bonus ratios due to costs, exchange rates, payment fees, App Store or Google Play rules, AI costs, SMS costs, taxes, Open Beta campaigns, or operating strategy.
9. Paid Add-On Features
9.1 Paid add-ons may include opening-hour selection, AI rewrite/drafting/multiple variants/tone adjustment, account-capacity upgrades, special withdrawal, time capsule quota add-ons, and other announced features.
9.2 Account-capacity upgrades are one-time account add-ons that apply while the service exists, the account is valid, and the user has not violated the terms. They are not subscriptions unless clearly labeled.
9.3 Capacity upgrades do not mean the platform promises permanent operation, permanent feature availability, permanent data storage, or capacity unaffected by future policy.
9.4 Opening-hour selection is a per-message or per-capsule add-on, not an account-capacity upgrade. It must be unlocked for each message or capsule according to the rules.
10. AI Review, Automated Review, and Necessary Manual Review
10.1 Messages, time capsule participant names, entries, metadata, and related records may be reviewed at submission, storage, editing, scheduling, opening, notice, report, appeal, risk-control, or other necessary stages.
10.2 Review helps prevent harassment, threats, hate, scams, extortion, illegal content, minor-safety risks, privacy violations, high-value sensitive storage, high-risk legal or financial instructions, emotional coercion, retaliatory content, and other unsuitable use.
10.3 AI and automated review may be wrong. Users may revise and resubmit, or appeal according to platform procedures.
10.4 The platform decides whether to conduct manual review based on message risk, appeal reason, account records, payment records, prior review records, recipient reports, and platform policy.
10.5 Manual review does not mean all platform staff may freely view plaintext content. It should be limited to authorized personnel, necessary scope, controlled workflows, and auditable records.
11. Unsuitable Content, Rejection, and Delivery Limits
11.1 If content is or appears unsuitable, prohibited, high-risk, illegal, abusive, or policy-violating, the platform may reject it, require edits, restrict modes, delay opening or delivery for review, cancel delivery, hide, freeze, destroy, delete, restrict accounts or verification attempts, suspend features, or take other necessary action.
11.2 The platform may charge fees or points for rejection, resubmission, appeal, manual review, or incurred costs according to the rules shown at submission.
12. No High-Value or Highly Sensitive Information
12.1 Users must not store, submit, seal, schedule, open, or request delivery of high-value or highly sensitive information through the service.
12.2 Prohibited or restricted content includes passwords, OTPs, login credentials, banking credentials, full card numbers or CVV, payment secrets, cryptocurrency keys or seed phrases, official ID images, text intended as a formal will, inheritance or asset distribution instructions, medical treatment or proxy instructions, requests to transfer money or assets, trade secrets, unauthorized personal data, threats, extortion, retaliation, humiliation, doxxing, emotional coercion, and other content that may harm recipients.
12.3 The platform may reject, require edits, suspend, freeze, destroy, or refuse delivery of content violating this section based on AI review, manual review, reports, legal requirements, or platform policy.
13. Recipient Notice and Identity Verification
13.1 When a message or time capsule content satisfies opening conditions, the platform may notify the recipient according to user settings, feature design, or platform policy.
13.2 Full message content must not be sent through ordinary email, SMS, or push notification.
13.3 Recipients must complete platform-required identity verification before viewing full content.
13.4 Verification may include email verification, SMS verification, account login, or other supported methods.
13.5 Notice, verification, opening, or viewing may fail or be delayed because email or phone data is invalid, the recipient cannot verify, the recipient refuses to view, review restrictions apply, third-party services fail, force majeure occurs, or law or policy limits apply.
14. Email and Phone Verification
14.1 Email is the platform's primary login, notice, and general verification channel.
14.2 Phone verification is mainly used for identity binding, higher-trust verification, recipient identification, important-message viewing, risk operations, special withdrawal, abnormal accounts, or user-enabled SMS notice.
14.3 The platform may use third-party SMS or verification providers to send OTP or verification messages.
14.4 SMS may be affected by carriers, country codes, devices, roaming, blocking, third-party services, cost, or legal limits. SMS delivery is not guaranteed.
14.5 The platform may limit verification attempts by account, phone, IP, device, or country/region to prevent abuse, toll fraud, cost abuse, or account attacks.
14.6 Error messages should not reveal whether a specific email or phone belongs to a specific user, to reduce enumeration and privacy risks.
15. Recipient Rights and Controls
15.1 After verification, recipients may be offered controls to view, hide or delete display records in their account, report messages, block a sender or identifier, stop future notices, or request privacy handling of personal data.
15.2 Hiding or deleting a message may affect only the recipient's account display and may not immediately delete backups, audit records, payment records, review records, or legally required retained data.
16. Account, Contact Data, and Notice Responsibility
16.1 Users are responsible for keeping account data, email, phone, login methods, notification channels, and recipient identifiers accurate and usable; avoiding prohibited content; and reviewing platform notices, payment records, review results, and delivery status.
16.2 Delivery, notice, or verification failures caused by outdated, incorrect, inaccessible, blocked, or third-party-limited user data are borne by the user unless law or platform intentional misconduct or gross negligence requires otherwise.
17. Privacy, Data Processing, Encryption, and Third-Party Services
17.1 The platform may process user account data, recipient identifiers, message content and encrypted content, metadata, review results, payment and point records, time capsule records, recipient notice and verification records, IP, device, risk, abuse-prevention, and security records.
17.2 Necessary data may be provided to third-party providers for content review, security, abuse detection, message opening, email or SMS notice, payment, cloud storage, support, dispute handling, legal compliance, or operations.
17.3 The platform should make reasonable efforts to limit access to message content and use encryption, hashed identifiers, keyed identifiers, permissions, audit logs, or other safeguards where appropriate.
17.4 Unless clearly announced with matching technical design, the service should not be described as end-to-end encrypted. The platform may need controlled content processing for AI review, rejection, reports, abuse prevention, security investigation, legal compliance, or user appeals.
17.5 Data collection, processing, retention, deletion, third-party sharing, and user rights are further governed by the Privacy Policy.
18. Can Engineers or Support See Private Messages?
18.1 For Later encrypts message content and sensitive data such as email addresses and phone numbers. Engineers and support staff cannot directly view plaintext content from the database or ordinary admin tools.
18.2 Ordinary support workflows do not ask users to provide full private message content and should not allow arbitrary browsing of private messages.
18.3 For platform safety, content review, reports, abuse prevention, security investigation, payment disputes, legal compliance, or user-initiated appeals, the platform may use controlled automated processing or necessary authorized manual review.
18.4 The platform should make reasonable efforts to limit access scope and keep permission controls, operation records, or audit records for necessary access.
19. Security and Abuse Prevention
19.1 The platform may use automated and manual systems to detect abuse, fraud, harassment, threats, extortion, illegal content, high-value secret storage, policy violations, payment abuse, SMS cost abuse, account compromise, and other security risks.
19.2 The platform may limit accounts, payment methods, recipients, IPs, devices, regions, verification attempts, message types, time capsule submission, QR code access, or other functions to prevent abuse or reduce risk.
20. Availability and No Guarantees
20.1 The platform will make reasonable efforts to operate the service, but does not guarantee uninterrupted service, error-free operation, permanent storage, successful notice, successful verification, or successful delivery.
20.2 Service may be affected by system failures, third-party failures, email/SMS/push failures, AI or review service failures, payment or app store issues, legal or policy changes, account compromise, security events, force majeure, service changes, or service shutdown.
20.3 For Scheduled Unlock, the platform commits to content being viewable after open_at according to permissions, not punctual notification delivery.
20.4 For Time Capsule, the platform does not guarantee that every participant can submit, every entry passes review, every notice arrives, or all content is stored forever.
21. Use Restrictions
21.1 Users must not use the service to harass, threaten, humiliate, extort, manipulate, harm others, send retaliatory messages, disclose secrets or personal data, evade law, store high-value secrets, publish legal/medical/financial/inheritance instructions, commit fraud or illegal transactions, impersonate others, infringe rights, or use platform functions in automated, bulk, malicious, or abnormal ways.
22. Refunds, Point Returns, and Payment Disputes
22.1 The platform may hold, reserve, or deduct points or fees when a user submits a message, creates a time capsule, buys add-ons, or enables a specific flow.
22.2 If content passes review and completes acceptance, storage, opening setup, or another service flow, held points may be formally captured.
22.3 If content is rejected for unsuitable content, prohibited content, format error, policy violation, high-risk signals, or other reasons, the platform may deduct review, processing, AI, manual, or other incurred service costs according to rules shown at submission. Any remaining point return depends on message type, payment method, and announced rules.
22.4 Manual appeals may carry an appeal review fee. If successful, the platform may return all or part of appeal, review, or point fees according to announced rules. If unsuccessful, appeal fees generally are not returned unless policy or mandatory law requires otherwise.
22.5 Case-by-case refunds, point returns, or compensation do not mean the platform admits breach, illegality, fault, or liability.
22.6 If a user requests a refund, chargeback, or payment dispute through an app store, payment processor, card issuer, or other third party, the platform may adjust points, freeze unused quota, mark negative balances, limit account functions, or take other necessary action to prevent duplicate refunds or abuse.
23. Dispute Handling and Support
23.1 Users or recipients with questions about review, points, rejection, appeals, delivery, notice, verification, refunds, data handling, or account limits should first use the platform's support or appeal process.
23.2 The platform may review message creation time, terms version, payment and point rules, confirmations, message mode and opening settings, AI/automated/manual review results, recipient notices and verification, viewing status, point/payment/refund/dispute records, support communications, risk records, security records, and system records.
23.3 During a dispute, the platform may suspend, delay, or freeze related messages, delivery flows, refunds, points, or account features to preserve data, prevent further harm, or complete necessary investigation.
24. Cross-Border Use, Governing Law, and Jurisdiction
24.1 The service is currently primarily intended for users in Taiwan. Users elsewhere are responsible for confirming whether their use complies with local law.
24.2 Unless mandatory law requires otherwise, these terms are governed by the laws of the Republic of China (Taiwan).
24.3 Disputes arising from or related to the service are subject to courts with jurisdiction in Taiwan as the court of first instance, without excluding mandatory consumer protection, personal data protection, ecommerce, payment, app store, Google Play, or local-law protections that cannot be waived by contract.
24.4 If local law differs and cannot be waived, the platform may restrict, adjust, or stop providing all or part of the service in that region based on law, policy, operational feasibility, or risk control.
25. Required Confirmations Before Submission
25.1 The platform should clearly notify and obtain confirmation before users submit messages, create time capsules, enable paid add-ons, use special withdrawal, buy points, or perform high-risk operations.
25.2 Suggested confirmations include:
- I understand this service is not a legal will and has no legal effect for property distribution, medical instructions, or legal notices.
- I understand this service should not store passwords, financial information, cryptocurrency keys, formal wills, identity documents, medical instructions, or other high-value sensitive information.
- I understand my submitted messages, names, or time capsule content may be reviewed by AI, automated systems, or necessary manual review and may be rejected, edited, restricted, or canceled.
- I understand rejected messages, resubmissions, or manual appeals may incur review, processing, appeal, or other incurred costs.
- I understand notices do not include full message content and recipients must complete platform verification before reading.
- I understand Scheduled Unlock controls when a message is viewable and does not guarantee punctual notice delivery.
- I understand Message Points are not cash, electronic payment balances, or withdrawable assets and are used and refunded according to platform rules.
26. Short Summary
For Later is a reviewed private message platform for mutual unlock messages, scheduled unlock messages, and time capsules. It is not a will, estate distribution service, medical instruction service, financial information custodian, or formal legal notice service.
Users must not store passwords, financial accounts, cryptocurrency keys, identity documents, formal wills, property distribution instructions, medical instructions, or other high-value sensitive information. Messages, event capsule participant names and content, and relationship capsule content in report or necessary handling situations may be reviewed by AI, automated systems, or necessary manual review, and may be rejected, edited, suspended, deleted, or not delivered for safety, legal, abuse-prevention, or content-policy reasons.
Scheduled Unlock is not scheduled sending. It controls when a message becomes viewable after a selected date or paid selected hour. Notices, if enabled, are sent after the message opens when feasible and are not guaranteed to be punctual. Notices do not include full content, and recipients must verify before reading.
Time Capsule is separated into event and relationship uses. Event capsules are for live multi-person collection, usually through a QR-code web form, and entries are collected and charged only after AI review. Relationship capsules are for future content in close relationships, usually require sign-in and identity verification, and generally do not undergo ordinary AI pre-review; the platform provides reporting, blocking, necessary record preservation, support appeals, and lawful cooperation mechanisms.
For Later encrypts message content, email addresses, phone numbers, and other sensitive data. Engineers and support staff cannot directly read plaintext from the database or ordinary admin tools. Controlled automated processing or authorized review may still occur for review, reports, abuse prevention, security, payment disputes, legal compliance, or user appeals.
27. Items Not Yet Open or Not Current Main Features
27.1 The following items should not be treated as current main service commitments: Legacy Message, Future Self Message as an independent main feature, Trusted Contacts, No-Response Release, check-in-triggered delivery, paper delivery, service-shutdown backup delivery, Kind Words Pool, Cool-down Message as an independent mode, and Relationship Time Capsule as an independent main feature.
27.2 If the platform later opens these features, it should provide supplemental terms, risk notices, point rules, confirmations, and product flows, and obtain necessary user confirmation before activation.
28. Data Deletion Requests
28.1 Users may request deletion of their account and associated data at any time, including data collected through third-party login (such as Google or Facebook Login).
28.2 Until self-service account deactivation and deletion are available, users may submit a deletion request through the in-app Support form after signing in. The platform will process the request and confirm completion within a reasonable time.
28.3 The platform plans to add self-service account deactivation (temporarily disabling an account) and account deletion (permanently removing an account and its data, subject to legally required retention) as in-app features. This section will be updated with the corresponding self-service flow once available.
28.4 Deleting an account does not necessarily delete backups, audit records, payment records, review records, or data the platform must retain by law.