Privacy.
What we hold, how private keys are handled, and what is removed after delivery.
Your letter
Your letter is encrypted in your browser before it is sent to us. The key is generated on your device and is included in the part of your private link after the #. Ordinary link navigation does not send that fragment to the server. The application does send the key for the specific requests described below. Our letter database stores the encrypted content without a private-key column.
Your letter is encrypted in your browser. Our letter database stores encrypted content, not the private key. However, the browser sends the key to our server for the key email and certain checks, including refund and Tapestry requests. Those checks can decrypt the letter temporarily in server memory. The email provider also processes the private link. This is not a promise that we could never access a letter. For a letter written for someone else there is one narrow, stated exception: see Letters for someone else.
Those requests use the key in memory to check access or compose the email. The application does not intentionally write the key or decrypted letter into database rows or operational logs. That is narrower than saying the key never leaves your browser or that the operator could never see it. Protect the device and inbox you use; anyone who obtains a private access link may be able to use it when the letter becomes available.
Keep your private link or key email somewhere safe. We do not retain a recovery copy of the key in the letter database. If you lose every copy, we cannot recreate it. Reminder and opening-day emails do not replace the key email.
Letters for someone else. For this letter type only, the assembled opening link (the key inside it) is written down encrypted from the moment your browser seals the letter until that first email is accepted by our email provider, typically minutes, and is deleted the moment it is. Between those two moments the operator could technically read the letter. For a letter to yourself, nothing of the kind is stored.
Private drafts on your device
While you write a letter before paying for it, this tab saves your draft and the details you entered in your browser, encrypted with AES-256-GCM. The browser stores the encrypted copy and a non-extractable encryption key in IndexedDB; session storage holds an opaque identifier for this tab. This draft copy is not sent to our server until you submit it. It is intended to survive a refresh or checkout return in the same tab, not to provide cross-device recovery.
A draft of a letter written before paying that has not been updated for seven days is deleted, together with its draft encryption key, when this browser next opens draft storage. You can also clear an unsubmitted draft in the writer. Clearing site data removes local copies. Starting another letter does not automatically erase the previous private recovery copy; its normal expiration still applies. Keep your private opening links separately.
Letters you paid for first. Nothing you write in a letter you paid for first reaches us until you seal it. Until then your words are saved only in that browser, encrypted, for up to 100 days, and they do not follow you to another device. Anyone holding that link can write, seal or refund that one unsealed letter, so keep it private. It cannot open any letter and cannot change where emails go. We keep it only as a one-way hash and an encrypted copy, so that our reminders can include it, and we delete both when the letter is sealed, refunded or cleared.
Those words are kept in a separate IndexedDB store in this browser, encrypted the same way, under an identifier belonging to that letter rather than to a tab, so every tab in this browser finds the same draft and session storage is not used for it. A copy that has not been updated for 100 days is deleted, together with its encryption key, when this browser next opens that store. It is also removed after this browser seals or refunds that letter. If the letter is sealed or refunded from somewhere else, this browser keeps the words until you clear them or they expire, so you can copy them first.
Use a trusted device. Encryption here prevents accidental plaintext storage; it does not protect against someone controlling this browser profile or malicious code running on this website. A shared device is not a separate secure session for each writer. If checkout returns an uncertain result, we preserve the encrypted draft and keys rather than automatically submit or charge again. A downloaded private recovery file contains keys and must not be shared publicly or sent to support.
What we actually store
- The encrypted letter, without its private key in the letter database.
- Your email address, encrypted at rest, alongside a one-way hash of it so we can find your records to delete them without decrypting anything.
- For a letter written for someone else: the recipient’s name and email address, encrypted at rest with the same kind of one-way hash, and the name you gave as the sender. We rely on your assurance that the recipient gave you their address; the first email they receive says who we are, why we have their address, and how to decline, which also tells us never to write to that address about a letter again.
- Your timezone, site and email languages, the country your connection came from when you sealed (a two-letter code, never an address), billing country when returned by the payment provider, and the recorded terms and translation versions.
- Where you arrived from, as one short word like x or google, kept only when a campaign link or a referring site announces it. We also record pass-it-forward link identifiers and resulting seals. These are operational attribution records, not letter contents.
- The opening date, the plan you chose, and whether the letter has been sent yet.
- For a pair: the first names you each typed, so the invitation reads like a person sent it; encrypted invitation contact information and tokens, token hashes, participation status and any exchange choice.
- A log of what our own system did: that a key email was sent, that a letter was delivered, without the contents of anything.
- Payment references, status, amounts, currency, tax and refund information needed to operate checkout and keep transaction records.
- For a letter you paid for first and have not yet sealed: a one-way hash and an encrypted copy of its private waiting link, when its payment was captured, which reminder it has reached, and when we sent the notice about its automatic refund.
- For a sealed pair of letters: one anonymous bond between the two countries the letters were sealed in, counted on EarthHope inside the paid Lighthouse. Each letter is held there under a one-way pseudonym, never your name, email address, letter or key, and only country-level totals are shown. Either of you can withdraw your light on EarthHope.
- If you choose the Human Tapestry: its coarse location and letter mark. Public snapshots do not include your letter, email address, name or private key. A shared same-device pair choice can add both marks; agree together before selecting it. Contact privacy@lovefutureyou.com about removal. There is not currently a self-service withdrawal control.
What is kept separate
- Private keys are not retained in the letter database, with the one stated exception for letters written for someone else, which is bounded to minutes. Key emails and copies you save are separate from it. Database encryption does not protect against every compromise of a device, inbox, email provider or application server.
- Card details. Those go to our payment processor and never reach us.
- Private letter access does not require a Lighthouse account. Optional Lighthouse sign-in is hosted by Clerk and uses email verification codes, not your private letter key or a password.
- Your IP address is used for abuse prevention. Alongside in-memory limits, the database holds keyed hashes of network prefixes or other rate-limit identifiers; daily cleanup removes those buckets after eight days. The raw IP is not a field in the letter database. At checkout it is passed to the payment processor for location handling. Hosting and payment providers also process connection data under their own policies.
- We do not use advertising trackers on the writing pages. We do keep the operational and attribution records described above; that is not a claim of no analytics at all. Checkout providers operate their own pages and cookies.
Optional Lighthouse sign-in
If you choose to enter the Lighthouse, Clerk processes your email address, account and session records, and connection information such as your IP address and browser details on our behalf. Sign-in uses cookies to maintain your session. We do not ask for a name or phone number for this sign-in. Hosted authentication is not a promise that no personal data is processed or that only the provider is responsible for it.
Our server checks your verified email and active session with Clerk, then uses the existing email lookup hash to check eligible paid letters. This does not add an account table to the letter database or send your letter contents or private opening key to Clerk. Future Chain shows existing letter dates; it does not extend letter retention. Contact our privacy address below about Lighthouse account information or deletion. Removing a Lighthouse account does not automatically cancel or delete a paid letter.
How long
Daily cleanup clears the encrypted letter, its stored delivery address and the address's lookup hash after 30 days from recorded delivery, not from when you first read it. Failed deliveries need follow-up. Payment, security and other operational records are separate; this does not erase every record or every backup. Save your letter after opening if you want to keep it.
The first letter stays as an encrypted, unsealed draft. Once expiry is processed, the invited person's stored delivery address and recoverable invitation link are cleared. The draft content and its delivery address are eligible for daily cleanup 60 days from the draft's original creation, unless it still has a captured payment or belongs to a still-pending pair. Other records are not all erased at that point.
The same 60-day daily cleanup applies to abandoned unpaid drafts, with exceptions while a captured payment or pending pair protects the record. Content cleanup sets the letter and delivery-address fields and the address's lookup hash to null. Identifiers, payment records and some pair and operational metadata can remain. It does not remove copies in your inbox or instantly erase provider backups. Contact us about the retention of a particular record; existing deletion commitments for letters already purchased still apply.
A pay-first checkout that is never paid is cleared by the same 60-day cleanup as other unpaid drafts. After a refund, that letter's email address and link are deleted.
Who else touches it
- Our payment processor handles the transaction and holds your billing details under its own privacy policy. We receive transaction references, amounts, currency, status, tax and billing-country information.
- Our email provider delivers your key email, your letter’s opening link and, for a letter you paid for first, its private waiting link and reminders. That email contains your key, so it is as sensitive as the letter itself. Treat that email the way you would treat a spare house key. The provider and your inbox may retain the message under their own policies; letter-content cleanup does not recall it.
- Our hosting and database providers process application requests and store encrypted content and operational data. Requests that carry private keys also pass through application hosting. Backups and infrastructure logs have their own retention; they are not covered by a promise that every copy disappears after 30 days.
We do not sell your personal data.
Your rights
Write to privacy@lovefutureyou.com to ask what we hold, obtain a copy, correct information or request deletion. We handle these requests through support, verify that the request concerns your data, and explain any records we must retain and why. This is not an automated account-deletion tool. An export of stored letter content is encrypted and needs your private key to read. Requesting deletion does not require opening the letter early. Existing deletion commitments are not withdrawn by this explanation of the current cleanup process.
If you are in Australia, the Privacy Act 1988 applies and you may complain to the Office of the Australian Information Commissioner. If you are in the UK or the EEA, the UK GDPR or GDPR applies and you may complain to your local supervisory authority. We rely on your consent, given when you seal a letter, and on the necessity of processing your email address to perform the service you bought.
This service is operated by Love Future You (ABN 15 196 987 632), Queensland, Australia. Payments are processed by Polar Software Inc., which is the merchant of record and the seller shown on your statement.
