Privacy Policy

Effective August 9, 2026

Effective August 9, 2026. This policy explains what data Still Arrives collects, what we do with it, and the rights you have over it. The design goal was: nothing surprising.

1. What we collect

We collect only what we need to make the service work. Everything below is either something you give us on purpose, or something the service produces as a side effect of operating.

1.1 Things you actively give us

  • Your letters. Text, photos, and the context you attach (mood, weather, song title, "what's happening right now"). This is the core of the product.
  • Delivery addresses. The primary and optional backup email addresses where the letter should arrive.
  • Contact and account information. If you register an account, we store your email address and any settings you configure.

1.2 Things the service records as it operates

  • Delivery attempts. Every time we try to send a capsule — success or failure — we record the timestamp, the channel used, and the outcome. This is what powers the reliability metrics we publish, and what makes the retry logic work.
  • Audit log. Actions we consider consequential — creation, sealing, delivery, opening, deletion — are logged with a timestamp. This is our accountability trail; it's also how we can answer "when did this letter get delivered?" without guesswork.
  • Basic technical metadata. IP address hash, user agent, request timing. We use these for security, for detecting abuse, and for basic operational monitoring.

1.3 Things we do not collect

  • We do not use third-party ad tracking, session recording, or behavioral analytics.
  • We do not use cookies beyond the ones the service functionally requires (session, A/B variant assignment, delivery link tokens).
  • We do not sell any of your data, ever.

2. Why we collect it

  • To deliver the service you asked for. The letter has to be stored, and it has to arrive.
  • To keep the service reliable. The retry logic, the pre-flight health checks, and the anniversary emails all depend on us knowing when capsules exist and where they should go.
  • To be accountable. The audit log is what lets us tell you (and, if it ever comes to it, a regulator) exactly what happened to any given capsule.
  • To comply with law. In some jurisdictions we are required to retain payment and transaction records for a defined period.

We do not use your data to train models, to profile you, or to advertise.

3. How your data is protected

  • In transit: all traffic to and from the service is TLS-encrypted.
  • At rest: letter contents and media are stored with AES-256 encryption. Encryption keys are held by us (see the note below).
  • Media files are stored in a private object storage bucket and served only through short-lived signed URLs. There are no permanent public URLs to your uploads.
  • Administrative access to production data is limited to a small set of authorized operators, requires two-factor authentication, and is logged. Our internal tooling does not expose the private contents of user capsules by default.

A note on encryption honesty. Because we hold the keys, we are technically able to read your letters. In practice we do not do so except for the narrow set of reasons in section 4 (security, support, legal). We are choosing not to claim "we cannot read your letters" — that would only be true under a zero-knowledge architecture, which we do not currently use. If we ever adopt one, we will say so plainly and update this section.

4. Who can access your data

  • You. You can view, export, and delete your data at any time.
  • Our operators — only when necessary for one of these reasons, and only with an audit-logged access event:
    • Investigating a security incident
    • Responding to a support request you initiated
    • Complying with a valid legal order
  • Our sub-processors — the third-party services that operate the technical infrastructure. See section 8.
  • No one else. We do not disclose your data to advertisers, data brokers, or any commercial third party.

5. How long we keep it

  • Sealed capsules are kept until you delete them or the account is closed. A ten-year letter stays for ten years by design.
  • Delivered capsules stay in your account after opening, forever, until you delete them. We do not archive or destroy delivered letters after any period.
  • Deleted capsules go through a 7-day cooldown, then are permanently removed from primary storage. Backup copies expire within an additional 30 days.
  • Delivery attempt and audit records are retained for the life of the associated capsule plus 12 months, then archived in aggregate form.
  • Payment records are retained for the period required by applicable tax and accounting law (typically 7 years).
  • Technical logs (IP hash, request metadata) are retained for 90 days for security analysis, then discarded.

6. Your rights

You always have the right to:

  • Access — view a complete copy of your data.
  • Export — download it in JSON plus original media files. This works from your account with one click; no request required.
  • Correct — update any information we hold about you.
  • Delete — remove any capsule or your entire account. Subject to section 5 for records we are legally required to retain.
  • Object — to any specific processing you don't agree with. Contact us.
  • Portability — the export format is open. No lock-in.

If you are in the EU, UK, or a jurisdiction with similar laws (California CCPA, Brazil LGPD, etc.), these rights are also guaranteed to you by that law. You may exercise them by contacting privacy@stillarrives.com. We aim to respond within 30 days.

You also have the right to complain to your local data protection authority if you believe we are handling your data unlawfully.

7. Children

The service is not designed for anyone under 16. We do not knowingly collect data from children under this age. If you believe a child has created an account or been given contact through our service, please contact privacy@stillarrives.com and we will remove the data promptly.

8. Sub-processors

We use the following third-party services to run the product. Each of them processes only what they need for their function, and each is bound by a data processing agreement.

Service What they do Where
Supabase Application database and authentication US / EU multi-region
Cloudflare R2 Media file storage (photos, audio) Global object storage
Vercel Application hosting and content delivery Global edge network
Resend Transactional email delivery US
Waffo Payment processing (merchant of record) Multi-region

We will notify you at least 30 days in advance of any change to this list that would result in new categories of data being sent to new sub-processors.

9. International data transfers

If you are in the EU or UK and your data is processed by a sub-processor in a country without an adequacy decision, we rely on Standard Contractual Clauses or equivalent safeguards to protect the transfer. You can request a copy by contacting privacy@stillarrives.com.

10. Data breach response

If we experience a security incident that compromises personal data, we will:

  • Notify affected users within 72 hours of confirmation.
  • Notify the relevant supervisory authorities where legally required.
  • Publish a public post-mortem within 30 days, describing what happened, what data was affected, and what we changed to prevent recurrence.

We will not attempt to conceal or minimize the scope of a breach.

11. Changes to this policy

Material changes are notified to all users by email at least 30 days in advance. The effective date at the top of this document always reflects the current version.

12. Contact

Data Protection Officer: TBD. Until we appoint one, contact privacy@stillarrives.com and it will reach the operator directly.