Stray Note

Last updated 24 July 2026

Privacy & your data

Here’s what Stray Note stores, why it is needed, and what stays deliberately separate.

Letters are anonymous

We store the letter, chosen paper pattern, time sent, moderation status and whether it has been delivered. If you choose a country from the optional list, only that country code is kept with the letter. We do not ask for device location. Until delivery, we store a one-way tag made from a random device token so your own letter is not delivered back to you. The tag is removed when the letter is delivered. We don’t attach your name, email, account or IP address to it. Links and contact details are removed before the letter can be opened.

If you sign in

We store your email address and credit balance so your credits work on other devices. When you receive a letter while signed in, we also store a separate private archive receipt. That receipt uses an irreversible server-generated code instead of your account ID and contains no sender identity. It exists only so you can reopen that letter from your archive. Guest letters are not archived and disappear when the reading session ends.

We also store the letter appearance you choose in account settings. When you send, the server copies only the paper pattern onto the anonymous letter; it does not copy your account or email.

A signed-in sender may receive one anonymous return reply. To route it, we store a private versioned HMAC value in a service-only table, separate from the letter. The reader never receives that value and the sender never learns who replied. Return replies appear only in the private archive; Stray Note does not send arrival email notifications.

There is no public profile. Deleting your account also deletes its archive receipts, wallet and purchase records. The anonymous letter itself may remain for moderation and safety records without an account attached.

Payments

Credit purchases are currently disabled. If purchases are introduced later, Stripe will handle card details and we will update this notice before enabling them.

Moderation & spam

Letters are checked before delivery. The text may be sent to our moderation provider, but it is not sent with your email or account details. We use IP addresses briefly to derive expiring, one-way spam-limit buckets; the raw address is not stored in the database or with letters.

If you report a letter, we store the letter, your reason and a one-way hash of your session. This stops one person from reporting the same letter repeatedly. We do not store the raw session, email or IP with a report.

If you block a sender, we store one symmetric exclusion made from two versioned HMAC values. It is used only to stop those two pseudonymous participants being matched again. Admin restrictions and audit records use the same kind of irreversible reference rather than a raw account id.

How long we keep it

A delivered letter is deleted once it can no longer be read by anyone — not archived, not awaiting a reply, not under an open report — typically 90 days after delivery. Rate-limit records expire within a day of being written; they exist only to throttle abuse in the moment. Reward-ad attempt records are removed within 5 weeks, and a guest wallet that never held a balance is cleared after 180 days of no activity. A resolved moderation case is the one record we keep longer than its content: the decision and who reviewed it stay on file after the letter itself is gone, so a repeat problem can be recognised. Your account row, wallet and archive receipts exist for as long as the account does and are removed together on deletion, as described above.

Where this is processed

The database, moderation checks and (when enabled) payments run through infrastructure providers — currently Supabase for storage and Stripe for payments — that may process data outside your own country, including in the United States. Optional rewarded ads, when enabled, run through Google Ad Manager on the same basis. Each provider is bound by its own data-processing terms, and where a transfer crosses into a country without an adequacy decision it relies on standard contractual clauses. We do not run our own servers in a different jurisdiction to route around this — the providers above are the entire list.

Your rights, and who to ask

You can see the email on file and remove the account entirely from account & data. For anything else — a copy of what’s held, a correction, a question about a specific record — email [email protected] marked privacy request; see the complaints process for what happens after that. If you’re in the UK or EEA, you can also take a concern straight to your data protection authority (the ICO, if you’re in the UK) — writing to us first is never a condition of that right.

What we don’t do

We don’t sell your data, reveal who sent a letter or expose archive ownership to other users. Optional rewarded ads are loaded from Google Ad Manager only after you expressly choose to watch one. Google may process device and advertising data under its own privacy terms; closing or declining an ad does not restrict ordinary use of Stray Note. One qualifying ad can unlock one additional send or receive per day; it does not add general-purpose credits.

See something harmful? Use Report this letter after opening it.