Words for the future.
A small commitment. A little patience. Proof that your words stayed the same.
Write. Seal. Reveal.
Sign in with GitHub, write Markdown or LaTeX, and choose a reveal time up to 365 days away. Publishing freezes the exact source and time. Share the link immediately. Until the deadline, visitors see only the hash and timestamps. At the deadline, anyone with the link can read the message and verify its hash.
What the hash proves
We hash your exact UTF-8 source, the UTC reveal time, and a random 256-bit nonce using SHA-256. The nonce stays private until reveal to prevent guessing short messages. Format v1 joins timeha.sh:v1, an ISO timestamp with milliseconds, the 64-character lowercase nonce, and your exact source with one newline between each. No trimming or Unicode normalization occurs. The revealed page includes all inputs and a browser verification button.
The hash proves the inputs match. It does not encrypt the message, prove who wrote it, or independently certify the publication timestamp. Markdown rendering is a presentation of the source; external images and raw HTML are disabled.
Privacy & trust
We store your source and nonce in a private Supabase database. Database access rules and the database clock control reveal; changing a browser clock cannot unlock a message. You trust the service operators and hosting providers to protect the stored source before reveal. Do not use this service for passwords, credentials, or material that must remain confidential after the deadline.
GitHub supplies account information for sign-in. Your account identifier links your posts to your dashboard; public pages show your GitHub username and avatar, linked to your GitHub profile, even before reveal. Your email and internal account identifier stay private. Authentication uses cookies. Vercel provides hosting and aggregate site analytics; Supabase provides authentication and storage. Application error messages exclude message source and nonces.
Sharing & retention
Messages are unlisted: they are not placed in a public directory or sitemap, and their pages request no search indexing. Anyone who receives the link can share it. These are not access controls, and revealed content may be copied permanently.
Published messages cannot be edited or deleted by their authors in this first version. We intend to retain them while the service operates, without guaranteeing indefinite availability. Keep your own copy. We may remove abusive or unlawful content; a removed commitment becomes unavailable and can never be replaced at its old hash. Removal clears active message storage, while provider backups can retain data until their normal expiry.
Limits & abuse
Messages may contain up to 32 KiB of UTF-8 source. Publishing is limited to 10 messages per hour and 100 per day per account. Do not publish unlawful material, private information about others without permission, threats, or harassment. To report a link or request help with account data, contact the maintainer on GitHub and include the commitment URL. Never send sealed source in a public report.