Privacy Policy
Effective date: June 8, 2026 · Last updated: June 8, 2026
1. Introduction
This Privacy Policy explains how While I Can ("we", "us", or "the Service") collects, uses, and protects your information when you use our website and services. By using the Service, you agree to the practices described here. We care deeply about the trust you place in us when you store something as personal as a letter to someone you love.
2. Information We Collect
We collect only what we need to operate the Service:
- Account information such as your name, email address, and an optional phone number used for retrieval notifications.
- Your password, which is stored only as a secure one-way hash. We never store or see your plain password.
- Letter content you create, which is encrypted before it is stored (see Section 4).
- Profile details you choose to add, such as a display name or short bio.
- Limited technical information such as IP address and timestamps, used for security and abuse prevention.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and secure the Service.
- Authenticate you and keep your account safe from unauthorized access.
- Send transactional messages, including email verification and retrieval notifications by email or text.
- Detect, prevent, and respond to abuse or security issues.
We do not sell your personal information, and we do not use your letters for advertising.
4. Encryption and Security
Letters are encrypted using AES-256-GCM before they are written to our database. Retrieval codes are stored only as hashes. We use industry-standard measures to protect your information, but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
5. Letter Content and Access
Under normal operation we do not read the contents of your encrypted letters. A letter is delivered only when a valid retrieval code is used and the author does not decline within the safety window described in our Terms of Service. We may access or disclose information where required by law or to address a credible safety concern (see Section 9).
6. Service Providers
We rely on a small number of trusted providers to run the Service. They process data only on our behalf and only as needed:
- A managed PostgreSQL database provider for secure storage.
- An email delivery provider for verification and notifications.
- A text messaging provider for retrieval notifications.
- A cloud hosting provider that serves the application.
7. Cookies and Sessions
We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not use advertising or third-party tracking cookies.
8. Data Retention and Deletion
We keep your information for as long as your account is active or as needed to provide the Service. After a letter is retrieved, the author's account may enter a deactivation period during which it can be reactivated. You may request deletion of your account and associated data at any time by contacting us, subject to any retention required by law.
9. Legal Disclosure
We may disclose information when we believe in good faith that it is required by law, valid legal process, or is necessary to protect the rights, property, or safety of our users or the public. This may include responding to lawful requests from law enforcement.
10. Your Rights
Depending on where you live, you may have the right to access, correct, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. We will respond within the time required by applicable law.
11. Children's Privacy
The Service is intended for adults. You must be at least 18 years of age to create an account. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can remove it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the date at the top of this page. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy or how your information is handled, please contact us at support@whileican.com.
By using While I Can, you acknowledge that you have read and understood this Privacy Policy.
