Privacy
Draft. This page will be reviewed by a lawyer before launch.
What we keep
- Open letters: the text, with email addresses, phone numbers, links and similar numbers removed. Names are not removed automatically, so please leave them out.
- Sealed letters: only the encrypted text. It is encrypted in your browser with a key that is never saved or sent, so we cannot read it.
- The date and time a letter was sent, and the country your connection came from. Publicly, we show only the day.
- A fingerprint (hash) of your withdraw code, so you can delete the letter later. Not the code itself.
What we don't keep
- No accounts, names or email addresses.
- No cookies and no tracking or advertising scripts. (If you choose a language, it is remembered in your browser.)
- Your IP address is held only briefly in memory, to stop floods of letters, and is not stored.
Letters that worry us
If a letter sounds like its writer may be in danger, we show a helpline while they write. This check happens on your own device. Such a letter is always sealed, never published.
Deleting your letter
Open letters wait a day before they appear. You can withdraw any letter at any time with the code on your receipt. We cannot find a letter for you without that code, because we don't know who wrote it.
Copies
Published letters are open to anyone and may be copied by others, including by machines and AI systems. A letter you withdraw is removed from everything we publish from then on, but we cannot recall copies other people have already made.
Where the data lives
Our database and servers are in the European Union.
Age
Open letters are for people aged 16 and over. Anyone may send a sealed letter.