Privacy

What we can see

We can read your letters

This is the most important thing on the page, so it goes first.

Your letter is encrypted before it is written to our database, with a key unique to that letter, which is itself encrypted under a master key held separately. If someone steals our database, what they get is unreadable.

But we hold the master key, because we have to. The service exists to send your letter at a moment when you are, by assumption, not available to unlock it. There is no arrangement in which the letter can be opened then and cannot be opened by us now. If a competitor tells you your letter is private even from them while offering the same delivery promise, one of those two claims is false.

What we offer instead of a technical guarantee is a practical one: we do not read letters, access is restricted to the administrator accounts that need it, and every start, cancellation, and delivery of the system is written to an audit log naming who did it and when. Please write with that in mind, and do not store passwords, account numbers, or anything whose exposure would harm you.

What we store

  • Your email address, so you can sign in and we can reach you.
  • Your letters, encrypted as described above.
  • The names and contact details of the people you name as recipients.
  • Payment records from Stripe. We never see or store your card details.

The people you name

Your recipients have not agreed to any of this and in most cases do not know we exist. We hold their details only to deliver your letter. We will not market to them, sell their details, or contact them for any other reason, and after your letter is delivered we send them nothing further.

Deleting

You can delete a letter at any time, which removes it and its recipients from our store. We cannot recover it afterwards. Deleting your account removes everything except the payment records we are required to retain.