The most serious failure WillSignal could cause is delivering your words before you intended anyone to receive them.
Everything below exists to prevent that.
It is worth reading in full before trusting a countdown with something that matters.
Late, never early.
Whenever a design choice could go in either direction, WillSignal chooses the one that delays delivery.
Not the option that is faster, tidier, or easier to explain.
A failure on our side can postpone delivery. Nothing here is built to start one.
Every safeguard below follows from that rule. They are not separate features added afterward; they are consequences of the same design decision.
A new account’s signal begins off. Nothing counts down, and nothing can be delivered, until you deliberately start it.
Someone who creates an account, looks around, and leaves before starting the signal cannot cause anything to be delivered.
A draft is never delivered. It is not delivered when your signal goes out, afterward, or simply because receivers have already been selected.
A draft becomes eligible for delivery only when you explicitly activate it.
A message with no receiver has nowhere to go. Receivers are chosen separately for each message. If a message that is ready has nobody attached to it, there is nobody to receive it when the signal goes out.
You choose the cycle. The available duration ranges from one day to thirty days, with three days as the default.
A longer cycle means fewer check-ins and more time before anything can happen. A shorter cycle means the opposite.
The choice is yours, and you can change it.
WillSignal warns you before the end, more than once. As the signal fades, WillSignal sends reminder emails to the address on your account, spaced according to the cycle you selected.
Each reminder tells you how much time remains and asks you to check in. It never identifies a message or a receiver.
Even if someone else can see the reminder email, it reveals no message or receiver details.
Every check-in restarts the full countdown. A check-in does not add a partial extension. It begins the entire selected cycle again from the moment you check in.
You can pause the signal. A pause can last for a set period or continue indefinitely.
While paused, the signal does not drain and cannot go out.
For a hospital stay, a long flight, time away from the internet, or any period when regular check-ins would not be realistic, pausing is the direct way to prevent the countdown from continuing.
This is where many countdown systems become unsafe, so the behavior is worth explaining clearly.
An outage credits time back. If the service is interrupted, running countdowns are moved forward to account for the unavailable period.
You are not charged for time during which you had no working way to check in. A countdown close to zero receives a meaningful safety margin rather than only a technically sufficient extension.
If WillSignal cannot confirm that check-ins are working, delivery is held. WillSignal regularly verifies that the check-in path is functioning.
The service is set so that when that verification stops succeeding, delivery stops until the check-in path is healthy again.
WillSignal would rather hold every message than release one because a service failure made an active user appear silent.
A closing account cannot deliver anything. Deleting your account freezes the signal throughout the entire 30-day recovery window.
If you change your mind and recover the account, the signal returns turned off. It never resumes halfway through a countdown or seconds from delivery.
Only you can start it again.
No collection of safeguards is complete, so the final safeguard assumes that the others have failed.
You can pull back any delivered message. Pulling it back removes the message from the receiver’s inbox.
There is no time limit, and pull-back remains available regardless of your account’s current signal state.
What pull-back cannot do is make someone unsee something.
If the receiver already opened your message, retrieving it cannot remove the words from their memory or from a copy or screenshot they kept.
That is a real limit. It is also why preventing premature delivery matters more than correcting it afterward.
You restart the signal when you are ready. Restarting after a mistaken delivery carries a lock: one month, growing to three and then six if it keeps happening.
The lock is measured from the moment the signal went out, rather than from the moment you restart it.
This is deliberate, but it is not intended as punishment.
A signal that repeatedly goes out and returns stops meaning anything, both to its owner and to the people waiting on it. The restart lock keeps the signal going out as serious as it sounds.
There is one exception.
If the signal went out while no bound receiver was attached to any message that was ready, nothing was eligible for delivery in the first place, and no restart lock is applied.
Drafts do not change that. A draft with receivers already chosen still counts as nothing delivered, because a draft is not eligible for delivery at all.
While the lock remains active, only the signal is locked. You can continue writing, editing, and pulling back messages.
Two features are absent on purpose.
Both may sound reassuring at first, but either would make the system less safe.
There is no “Are you sure?” prompt at zero. When the countdown ends, the signal goes out and delivery happens as part of that moment.
A confirmation prompt would require you to be present and able to respond. Being unable to respond is the premise of the system.
A prompt that nobody can answer is not a safeguard.
WillSignal does not infer death from a missed check-in. WillSignal does not claim that a signal going out proves death or incapacity.
A missed check-in shows only that the owner stopped checking in. It does not explain why.
Trying to guess would produce mistakes in both directions, and the dangerous mistake is the one that causes delivery while the owner is still alive.
For the full mechanism, see How it works. Additional edge cases are covered in the FAQ.