Privacy Policy
Last updated: 7 August 2026
The short version
Your answers are stored only on your device, encrypted. We run no database of answers, we require no account, and we never log the content of what you write. To create your questions and your letter, your answers are sent — over an encrypted connection — to our relay and on to Anthropic’s AI, processed in memory, and returned. We cannot look your answers up afterwards, because they are never stored on anything we operate.
Your finished letter is backed up, but sealed: your device encrypts it with a key derived from your recovery key — the mirror-… phrase shown with your letter — and we only ever receive the encrypted result. The recovery key itself never reaches us. We therefore cannot read the letters we store, and neither can anyone who obtains them. Only you can, and only with your recovery key.
What is processed, where
- On your device: all answers and your letter, in your browser’s local storage, encrypted at rest with a key that never leaves your browser. Deleting the site’s data (or using “Start over”) erases them.
- Our relay (Vercel): receives your answers only to forward them to Anthropic, keeps them in memory for the duration of the request, stores no answers, and logs only technical error reasons — never content. Standard infrastructure metadata (IP address, timestamps) is processed by Vercel to serve the request.
- Our vault (Upstash Redis, London): holds two kinds of thing, and nothing else. First, your sealed letter, stored under an address derived from your recovery key, kept for up to a year after you last open it and deleted automatically after that; you can erase it yourself at any time. Second, anonymous counters that stop the AI being abused at our expense — these hold irreversible salted hashes of IP addresses and payment-session identifiers, never the values themselves, and they expire on their own.
- Anthropic (AI processing): your answers are processed by the Claude API to generate your questions and letter, under Anthropic’s commercial data terms. Anthropic does not train on this data; API inputs are retained by Anthropic for a limited period (currently up to 30 days) for abuse prevention, then deleted.
- Stripe (payment): if you buy the letter, Stripe processes your payment details, name and billing country. Stripe never receives your answers; we never see your card.
What we deliberately don’t do
- No accounts, no profiles, no answer database.
- No analytics or tracking cookies.
- No sale or sharing of data with advertisers — there is nothing to sell.
An honest limitation
The letter we store is sealed against us, but the moment of writing it cannot be: an AI must read your words to write your letter. So while nothing readable is kept anywhere afterwards, your answers do pass through our relay and Anthropic’s AI while the letter is being written. We minimize that exposure — no answers are persisted, transport is encrypted, the name field is optional, and nothing we hold identifies you. Answer as openly or as anonymously as you like.
Your recovery key
The recovery key is the only way into your sealed letter. We do not hold it, cannot reset it, and cannot recognise you without it — that is precisely what makes the seal meaningful. Keep it somewhere safe: if it is lost, the stored letter can never be opened again by anyone.
Legal bases (UK GDPR and EU GDPR)
Processing your answers to generate questions and the letter: Art. 6(1)(b) (performance of the service you request). Payment processing: Art. 6(1)(b) and legal obligations (Art. 6(1)(c)). Answers may include information you consider sensitive; they are processed solely to deliver the service you explicitly request, at your initiative.
Your rights
Access, rectification, erasure, restriction, portability, objection — though for answers, the honest answer is: they are already only in your hands. For payment data, contact us or Stripe. Complaints: the UK Information Commissioner’s Office (ICO), or your local data-protection authority in the EU. Contact: connect@rktechs.io.