Privacy
Effective September 26, 2026
To My Person is operated by To My Person (“we”). People write things here they've never said out loud, so we collect as little as we can and keep private things private. This page explains exactly what happens to your data.
The short version
- No account is needed. No ads, no analytics, no tracking cookies. We don't sell or share your data.
- Letters you keep or seal are encrypted before they're stored.
- A letter you “let go” never leaves your device.
- Wall letters are public but anonymous — no name or email is ever shown.
- You can download or delete everything at any time from Settings.
What we collect
Letters
What you write: who it's to, the letter itself, and any sign-off, song, color, category, or opening date you choose. How each letter is stored depends on what you do with it:
- Kept — encrypted at rest; only you can see it, from your drawer.
- Sealed — encrypted at rest; readable by anyone holding its link once its opening date arrives (and by you at any time). The link preview shows only the recipient's name and the date, never the letter.
- Let go — the text is never sent to us. We store only that a letter to that name was let go, so it can appear in your drawer.
- On the wall — stored as written so it can be shown publicly, without any link to you.
Your drawer and account
- A session cookie that ties your drawer to your browser. It's strictly necessary for the site to work, which is why there's no cookie banner.
- If you choose to add them: your email address and a password, which is stored only as a salted scrypt hash.
- Whether you want “opened” and “wrote back” emails.
Other things
- A one-way hash of your IP address, stored with letters and used only to limit spam and block abuse. We don't store your IP address itself.
- Email addresses given for reminders (“email me when it opens”) and future-me delivery. Each is used only for that one purpose.
- Anonymous counts of reactions and views on wall letters.
- Your light/dark preference, stored in your own browser.
- Standard technical logs kept by our hosting provider (such as request times and errors) for security and troubleshooting.
Who can see your letters
Our moderation tools only show wall letters. For a sealed letter, they can show its recipient name and dates (so we can act on abuse reports) but not its text. Staff don't read private letters. As with any online service, the people who run the servers control the systems and encryption keys, and we may be required to disclose information if the law compels it — we'll only do so when legally required.
Emails we send
Only emails you asked for: future-me letters, “it's open” reminders, notes when a letter you sealed is opened or answered, notes when a wall letter resonates, and password resets. Every optional note has a one-click unsubscribe. No newsletters, no marketing.
Service providers
- Railway — hosts the site and database (United States).
- Resend — delivers our emails.
They process data only to provide these services to us.
How long we keep things
- Letters and your drawer: until you delete them (or your whole drawer).
- Guest drawers with nothing in them: deleted after 30 days.
- Sessions expire after about a year; reset links after one hour.
- Sent reminders: deleted after 30 days.
- Wall letters removed by moderation may be kept briefly as a record of the decision.
Your choices and rights
Wherever you live, you can:
- See and download everything in your drawer — Settings → Download my data.
- Edit or delete any letter from your drawer, or delete your whole drawer and account from Settings.
- Turn off optional emails in Settings or from any email's unsubscribe link.
- Ask us anything about your data, or exercise rights you have under laws like the GDPR or CCPA, by contacting the “Report” link on any letter. You may also complain to your local data protection authority.
We don't sell or “share” personal information as those terms are defined under California law.
Children
To My Person isn't for children under 13 (or the minimum age in your country). We don't knowingly collect data from them; if you believe a child has used the site, contact us and we'll delete it.
Security
Everything travels over HTTPS. Private letters are encrypted with AES-256-GCM, passwords are hashed, and reset links are single-use. No system is perfectly secure, but we work to keep yours safe.
Changes
If we change this policy, we'll update the date above. If a change affects how private letters are handled, we'll say so on the site first.
Contact
Questions or requests: the “Report” link on any letter.