Last updated July 17, 2026
Privacy Policy
This page explains the current behavior of Secret Letter in plain language. It is intended to help you decide what information is appropriate to place in a letter.
What the service stores
When you create a letter, the service stores the letter body, optional sender and recipient names, reveal date, sent date, appearance settings, and a timezone offset used for the reveal experience. The message must be stored so it can be displayed from its unique link.
Secret links and access
A letter URL should be treated like a secret. Anyone who obtains the link may be able to access the page and, after the reveal date, read the message. Secret Letter does not currently promise password protection, one-time access, or end-to-end encryption.
Unnamed letters
Sender and recipient names are optional. Leaving a name blank prevents it from appearing in the letter, but does not make the service an untraceable or technically anonymous communication channel.
Abuse protection
The service may process network information such as an IP address to apply rate limits, prevent automated abuse, and protect availability. This information is not placed inside the public letter.
Product analytics
Secret Letter may record first-party product events such as letter creation attempts, successful letter creation, letter page views, missing-letter requests, and rate-limit hits. These logs may include hashed IP address, hashed user agent, hashed letter ID or unresolved path, country, network/ASN, browser family, device type, language, referrer host, request method and status, letter text length, whether the letter appears to contain a URL, honeypot or validation signals, and small non-sensitive reason codes. Analytics logs do not store letter content, raw private letter URLs, raw letter IDs, raw IP addresses, full user agents, private tokens, or first-party analytics cookie IDs.
Third-party analytics
The site may use Cloudflare Web Analytics to understand aggregate usage and page performance. Secret Letter does not currently load Google advertising technology or display ads.
Retention and deletion
Raw first-party product analytics event logs are scheduled for deletion after they are more than 30 days old. Rate-limit records are scheduled for deletion after they are more than 24 hours old. Cleanup runs daily, so eligible records are normally removed on the next run; a failed run or an unusually large backlog can delay removal until maintenance catches up. These schedules do not delete letters. Secret Letter does not currently offer automatic self-service deletion or promise automatic deletion of letter records after a fixed period. Letter records may remain stored until removed by the operator. To request deletion, send the exact letter URL from an address where you can receive the response; requests may require reasonable verification.
Sensitive information
Do not use Secret Letter for passwords, payment details, medical records, legal notices, emergency messages, threats, or information that would cause harm if the link were forwarded or accessed by someone else.
Contact
For privacy questions or a deletion request, email hello@secretletter.co. Include only the information needed to identify the request.