Love Future You2026-09-14

Privacy.

What we hold, how private keys are handled, and what is removed after delivery.

Your letter

Your letter is encrypted in your browser before it is sent to us. The key is generated on your device and is included in the part of your private link after the #. Ordinary link navigation does not send that fragment to the server. The application does send the key for the specific requests described below. Our letter database stores the encrypted content without a private-key column.

Your letter is encrypted in your browser. Our letter database stores encrypted content, not the private key. However, the browser sends the key to our server for the key email and certain checks, including refund and Tapestry requests. Those checks can decrypt the letter temporarily in server memory. The email provider also processes the private link. This is not a promise that we could never access a letter. For a letter written for someone else there is one narrow, stated exception: see Letters for someone else.

Those requests use the key in memory to check access or compose the email. The application does not intentionally write the key or decrypted letter into database rows or operational logs. That is narrower than saying the key never leaves your browser or that the operator could never see it. Protect the device and inbox you use; anyone who obtains a private access link may be able to use it when the letter becomes available.

Keep your private link or key email somewhere safe. We do not retain a recovery copy of the key in the letter database. If you lose every copy, we cannot recreate it. Reminder and opening-day emails do not replace the key email.

Letters for someone else. For this letter type only, the assembled opening link (the key inside it) is written down encrypted from the moment your browser seals the letter until that first email is accepted by our email provider, typically minutes, and is deleted the moment it is. Between those two moments the operator could technically read the letter. For a letter to yourself, nothing of the kind is stored.

Private drafts on your device

While you write a letter before paying for it, this tab saves your draft and the details you entered in your browser, encrypted with AES-256-GCM. The browser stores the encrypted copy and a non-extractable encryption key in IndexedDB; session storage holds an opaque identifier for this tab. This draft copy is not sent to our server until you submit it. It is intended to survive a refresh or checkout return in the same tab, not to provide cross-device recovery.

A draft of a letter written before paying that has not been updated for seven days is deleted, together with its draft encryption key, when this browser next opens draft storage. You can also clear an unsubmitted draft in the writer. Clearing site data removes local copies. Starting another letter does not automatically erase the previous private recovery copy; its normal expiration still applies. Keep your private opening links separately.

Letters you paid for first. Nothing you write in a letter you paid for first reaches us until you seal it. Until then your words are saved only in that browser, encrypted, for up to 100 days, and they do not follow you to another device. Anyone holding that link can write, seal or refund that one unsealed letter, so keep it private. It cannot open any letter and cannot change where emails go. We keep it only as a one-way hash and an encrypted copy, so that our reminders can include it, and we delete both when the letter is sealed, refunded or cleared.

Those words are kept in a separate IndexedDB store in this browser, encrypted the same way, under an identifier belonging to that letter rather than to a tab, so every tab in this browser finds the same draft and session storage is not used for it. A copy that has not been updated for 100 days is deleted, together with its encryption key, when this browser next opens that store. It is also removed after this browser seals or refunds that letter. If the letter is sealed or refunded from somewhere else, this browser keeps the words until you clear them or they expire, so you can copy them first.

Use a trusted device. Encryption here prevents accidental plaintext storage; it does not protect against someone controlling this browser profile or malicious code running on this website. A shared device is not a separate secure session for each writer. If checkout returns an uncertain result, we preserve the encrypted draft and keys rather than automatically submit or charge again. A downloaded private recovery file contains keys and must not be shared publicly or sent to support.

What we actually store

What is kept separate

Optional Lighthouse sign-in

If you choose to enter the Lighthouse, Clerk processes your email address, account and session records, and connection information such as your IP address and browser details on our behalf. Sign-in uses cookies to maintain your session. We do not ask for a name or phone number for this sign-in. Hosted authentication is not a promise that no personal data is processed or that only the provider is responsible for it.

Our server checks your verified email and active session with Clerk, then uses the existing email lookup hash to check eligible paid letters. This does not add an account table to the letter database or send your letter contents or private opening key to Clerk. Future Chain shows existing letter dates; it does not extend letter retention. Contact our privacy address below about Lighthouse account information or deletion. Removing a Lighthouse account does not automatically cancel or delete a paid letter.

How long

Daily cleanup clears the encrypted letter, its stored delivery address and the address's lookup hash after 30 days from recorded delivery, not from when you first read it. Failed deliveries need follow-up. Payment, security and other operational records are separate; this does not erase every record or every backup. Save your letter after opening if you want to keep it.

The first letter stays as an encrypted, unsealed draft. Once expiry is processed, the invited person's stored delivery address and recoverable invitation link are cleared. The draft content and its delivery address are eligible for daily cleanup 60 days from the draft's original creation, unless it still has a captured payment or belongs to a still-pending pair. Other records are not all erased at that point.

The same 60-day daily cleanup applies to abandoned unpaid drafts, with exceptions while a captured payment or pending pair protects the record. Content cleanup sets the letter and delivery-address fields and the address's lookup hash to null. Identifiers, payment records and some pair and operational metadata can remain. It does not remove copies in your inbox or instantly erase provider backups. Contact us about the retention of a particular record; existing deletion commitments for letters already purchased still apply.

A pay-first checkout that is never paid is cleared by the same 60-day cleanup as other unpaid drafts. After a refund, that letter's email address and link are deleted.

Who else touches it

We do not sell your personal data.

Your rights

Write to privacy@lovefutureyou.com to ask what we hold, obtain a copy, correct information or request deletion. We handle these requests through support, verify that the request concerns your data, and explain any records we must retain and why. This is not an automated account-deletion tool. An export of stored letter content is encrypted and needs your private key to read. Requesting deletion does not require opening the letter early. Existing deletion commitments are not withdrawn by this explanation of the current cleanup process.

If you are in Australia, the Privacy Act 1988 applies and you may complain to the Office of the Australian Information Commissioner. If you are in the UK or the EEA, the UK GDPR or GDPR applies and you may complain to your local supervisory authority. We rely on your consent, given when you seal a letter, and on the necessity of processing your email address to perform the service you bought.

This service is operated by Love Future You (ABN 15 196 987 632), Queensland, Australia. Payments are processed by Polar Software Inc., which is the merchant of record and the seller shown on your statement.

Privacy · Love Future You