Stray Note

Last updated 6 September 2026

Privacy & your data

Here’s what Stray Note stores, why it is needed, and what stays deliberately separate.

Letters are anonymous

We store the letter, chosen paper pattern, time sent, moderation status and whether it has been delivered. If you choose a country from the optional list, only that country code is kept with the letter. We do not ask for device location. Until delivery, we store a one-way tag made from a random device token so your own letter is not delivered back to you. The tag is removed when the letter is delivered. We don’t attach your name, email, account or IP address to it. Links and contact details are removed before the letter can be opened.

Your unfinished letter

Your draft is saved in this browser tab so it survives navigation and refreshes. It is not sent to us until you choose Send letter. Sending or discarding it removes the saved draft. Browser session restoration may restore the tab and its draft; use Discard draft to remove it on a shared device.

If you sign in

We store your email address and credit balance so your credits work on other devices. When you receive a letter while signed in, we also store a separate private archive receipt. That receipt uses an irreversible server-generated code instead of your account ID and contains no sender identity. It exists only so you can reopen that letter from your archive. Guest letters are not archived and disappear when the reading session ends.

We also store the letter appearance you choose in account settings. When you send, the server copies only the paper pattern onto the anonymous letter; it does not copy your account or email.

A signed-in sender may receive one anonymous return reply. To route it, we store a private one-way routing code in a service-only table, separate from the letter. The reader never receives that code and the sender never learns who replied. Return replies appear only in the private archive; Stray Note does not send arrival email notifications.

There is no public profile. Deleting your account also deletes its archive receipts, wallet and purchase records. The anonymous letter itself may remain for moderation and safety records without an account attached.

Payments

Credit purchases are currently disabled. If purchases are introduced later, Stripe will handle card details and we will update this notice before enabling them.

Moderation & spam

Letters are checked before delivery. The text may be sent to our moderation provider, but it is not sent with your email or account details. We use IP addresses briefly to derive expiring, one-way spam-limit buckets; the raw address is not stored in the database or with letters.

If you report a letter, we store the letter, your reason and a one-way hash of your session. This stops one person from reporting the same letter repeatedly. We do not store the raw session, email or IP with a report.

If you block a sender, we store a private one-way exclusion between the two participants. It is used only to stop them being matched again. Admin restrictions and audit records use the same kind of irreversible reference rather than a raw account id.

How long we keep it

A delivered letter is deleted once it can no longer be read by anyone — not archived, not awaiting a reply, not under an open report — typically 90 days after delivery. Rate-limit records expire within a day of being written; they exist only to throttle abuse in the moment. Reward-ad attempt records are removed within 5 weeks, and a guest wallet that never held a balance is cleared after 180 days of no activity. A resolved moderation case is the one record we keep longer than its content: the decision and who reviewed it stay on file after the letter itself is gone, so a repeat problem can be recognised. Your account row, wallet and archive receipts exist for as long as the account does and are removed together on deletion, as described above.

Where this is processed

The database, moderation checks and (when enabled) payments run through infrastructure providers — currently Supabase for storage and Stripe for payments — that may process data outside your own country, including in the United States. Each provider is bound by its own data-processing terms, and where a transfer crosses into a country without an adequacy decision it relies on standard contractual clauses. We do not run our own servers in a different jurisdiction to route around this — the providers above are the entire list.

Your rights, and who to ask

You can see the email on file and remove the account entirely from account & data. For anything else — a copy of what’s held, a correction, a question about a specific record — email [email protected] marked privacy request; see the complaints process for what happens after that. If you’re in the UK or EEA, you can also take a concern straight to your data protection authority (the ICO, if you’re in the UK) — writing to us first is never a condition of that right.

What we don’t do

We don’t sell your data, reveal who sent a letter or expose archive ownership to other users. Advertising is currently disabled. We do not load advertising scripts or offer rewarded ads.

See something harmful? Use Report this letter after opening it.

Privacy | Stray Note