Privacy
What we can see
We can read your letters
This is the most important thing on the page, so it goes first.
Your letter is encrypted before it is written to our database, with a key unique to that letter, which is itself encrypted under a master key held separately. If someone steals our database, what they get is unreadable.
But we hold the master key, because we have to. The service exists to send your letter at a moment when you are, by assumption, not available to unlock it. There is no arrangement in which the letter can be opened then and cannot be opened by us now.
What we offer instead of a technical guarantee is a practical one: we do not read letters, access is restricted to the administrator accounts that need it, and every start, cancellation, and delivery of the system is written to an audit log naming who did it and when. Please write with that in mind, and do not store passwords, account numbers, or anything whose exposure would harm you.
What we store
- Your email address, so you can sign in and we can reach you.
- Your letters, encrypted as described above.
- The name and contact details of the person you name as the recipient.
- Payment records from Stripe. We never see or store your card details.
The person you name
Your recipient has not agreed to any of this and in most cases does not know we exist. We hold their details only to deliver your letter. We will not market to them, sell their details, or contact them for any other reason, and after your letter is delivered we send them nothing further.
Deleting
You can delete a letter at any time, which removes it and its recipient from our store. We cannot recover it afterwards. Deleting your account removes everything except the payment records we are required to retain.