Back to home

Love Letters · Draft document

Love Letters Privacy Policy Draft

Product draft only. Human/legal review required before public launch.

Last updated: 2026-08-09

1. What we collect

When a creator signs in, Firebase Authentication provides an account identifier and the Google account information required by the selected authentication flow.

When a creator publishes a letter, the service stores the recipient name, letter text, paper style, selected YouTube video ID/title, ownership identifier, status, and timestamps.

The service may receive ordinary technical request data from Firebase and Cloudflare. The prototype must not log letter bodies, recipient names, or account emails in application logs.

2. Public letters

A published letter is readable by anyone who has its link. Recipients do not need to sign in. The link, letter text, and selected presentation metadata should be treated as public after publishing.

Social previews use generic text:

  • A love letter has been sent for you.
  • Someone left you a letter to open.

3. How data is used

Data is used to authenticate creators, store and display letters, provide an owner-only published-letter manager and creator deletion, and operate the service. The prototype does not sell letter content or use it for advertising or content analytics.

4. Providers

The final policy must identify the relevant processing roles and link to current policies for Firebase, Google, Cloudflare, and YouTube. Provider locations, transfers, cookies, and retention details require human review.

5. Retention and deletion

Published letters remain stored until the creator chooses Delete. After signing in, a creator can recover a bounded list of their own published letters through the My Letters manager. Deletion removes public access and permanently deletes the letter record immediately.

Drafts are local-only in the prototype and are not included in the published-letter manager. If server drafts are added later, their inactivity retention must be documented separately.

If a creator deletes their account, their owned letters should be permanently deleted as part of the account-deletion workflow. Account deletion is not available until that workflow is implemented and verified.

6. Security

Firestore security rules restrict drafts and mutations to their authenticated owner. No service-account credentials are sent to the browser. The final launch must include security-rule tests and an incident/contact process.

7. Rights and contact

Before launch, add processes for access, correction, deletion, complaints, and applicable regional rights. Add a real privacy contact: [PRIVACY CONTACT EMAIL].

This document is not legal advice and is not ready to publish without review.