Privacy Policy
Last updated: 12 August 2026
In short: no accounts, no tracking, no ads, no analytics.
Your letter never reaches our servers — encryption happens on your device. The one
exception: if you tap "Get a literary suggestion," your draft is sent through our
relay to an AI service (details below).
Letter content
Your letter is encrypted on your device (AES-256-GCM) before it goes anywhere, and it is
written as QR codes only onto the paper/PDF you produce. The plaintext is never sent to us
or to any third party, never stored, never logged. The capsule is shown to you once; we
keep no copy — we cannot. Photos and files you attach are likewise encrypted on your
device and live only inside the digital capsule file — they never reach us or any server.
Gallery/camera access is used only to read the attachments you choose.
Accounts and identity
There are no accounts. At sealing time your e-mail address is verified via your device's
Apple/Google sign-in to prevent impersonation; that address and timestamp are stamped
only inside the encrypted letter. The e-mail address itself is never sent to our
servers — only the person who opens the letter on its date can see it. Solely to stop the
one free letter per device from being reset by reinstalling the app, we keep a
counter. Where that counter lives depends on your operating system:
-
iPhone / iPad: we use Apple's DeviceCheck service —
a single bit per device (whether the free letter was used) is stored
on Apple's servers. The app sends us a single-use, opaque token; only Apple can
tell which device it belongs to.
We store nothing.
-
Android: Android has no equivalent, so
we have to keep the counter ourselves. The device's persistent identifier is
irreversibly digested (SHA-256) on the device itself; only that digest reaches
our server and the raw identifier never reaches us. On the server the digest is
mixed again with a secret key before being stored, so even if our records leaked they
could not be traced back to a device identifier or matched against records held by any
other service. This record is used solely to prevent abuse; it is not linked to
your e-mail, your name or your letters, is never shared, and is
deleted after two years of disuse.
In both cases we hold no e-mail, no e-mail digest and no user record, and the counter
cannot be linked to any letter.
What leaves your device?
-
Letter fingerprint (hash): at sealing, the letter's SHA-256 digest is sent to our
relay to be written to the Polygon chain. A hash is one-way; it contains no content or
personal data and cannot be reversed. The relay stores nothing related to your
letter — but our hosting provider (Vercel) may keep technical access records (IP, time,
path) for each request, and we can access those.
-
Your draft never leaves your device — no exceptions. Earlier versions of the app
had an optional "literary suggestion" feature that sent your draft to an AI service when
you tapped it. That feature has been removed. There is no longer any path that
takes your letter text off your device; the encryption happens there too.
-
Time lock: when opening a letter, the app fetches that day's signature from the
public drand network. That request carries no information about your letter.
What we keep to prevent abuse
We keep three short-lived records that have nothing to do with letters and exist only to
stop bots and abuse. None of them can be linked to your name, your email or any letter:
-
Request counter (IP): we count how many requests come from the same connection
each day. The IP address is not stored in the clear: only a version mixed with a
secret key we hold is used as the counter's name, and the record expires by itself after
48 hours. The counter cannot be turned back into an IP.
-
App verification (iPhone/iPad only): to confirm a request really comes from our
app, Apple's App Attest is used. The public key your device generates, plus a
counter, is kept by us. It does not identify you, cannot be matched with your record at
any other service, and is never linked to your letters.
-
Free-letter ledger (Android only): the twice-hashed device digest described
above.
None of this is used for advertising, measurement or profiling, and none of it is shared
with third parties.
What stays on your device?
Only contentless "seal memories" (recipient name, dates, hash), your language/theme
preferences and any reminders you enabled. They never leave the device and can be deleted
in the app.
Two small exceptions, both of which stay on your device: (1) from the moment you
tap "Seal" until the process finishes, an encrypted draft of your letter is kept,
so that nothing is lost if the phone closes the app in the meantime. The encryption key
lives in the device's secure store (Keychain); the draft is deleted as soon as the process
ends, and on the next launch you are asked to restore or discard it. (2) Whether
your one free letter has been used (a single number, containing nothing about any letter)
is kept in the device's secure store; on iPhone, deleting and reinstalling the app does
not reset it.
Reminders are local notifications: they are scheduled by your own device. We do not
use remote push (APNs/FCM) — no device token and no unlock date ever reaches us. You can
turn them off in Settings.
Analytics, ads, cookies
None. No behavioral tracking, no ad identifiers, no crash reporting, no cookies.
Purchases
In-app purchases are processed by Apple App Store / Google Play; your payment details
never reach us in any form.
Contact
Questions: mail@cagricakir.com.tr