Security & privacy
You're writing something
personal. We know.
A letter to your future self is not a password reset or a shipping address. It's the thing you're thinking at 11pm on New Year's Eve, or the morning before a move, or the week after a diagnosis. It deserves to be handled like what it is.
Here's what happens to it.
The moment you hit save, your letter is encrypted. What sits in our database is ciphertext that can only be opened with a key held separately. After payment and once you provide an address, the letter is decrypted in memory, rendered as a PDF, and transferred to Stannp so they can print and post it on the scheduled date. The plaintext is not stored in our database or sent by email.
We should be honest about one thing: we hold the key. An authorised operator could technically decrypt a letter. We do not do that outside the print workflow. Stannp necessarily receives the printable PDF. If your words absolutely cannot be seen by another person under any circumstances, a sealed envelope in your own drawer is safer than any digital service, including ours.
After payment, we ask for the delivery address. Once you submit it and the booking succeeds, our UK print partner holds the posting schedule, printable PDF and address. Their system triggers the print and posts the envelope.
A letter is not safely scheduled until your account shows “Sealed at print partner.” From that point, the print partner's queue is the durable record. The chosen date is the posting date; Royal Mail controls arrival.
Your address is access-controlled in our database and transferred to Stannp to create and post the letter; it is not stored with the same content encryption as the letter body. We do not sell it or use it for marketing. Ask us to delete it after the mailing is complete.
We use your email for magic sign-in links, purchase and service messages, and support. The separate newsletter is optional and requires its own consent.
Email us to request account deletion. We remove data we still control within 30 days where the law permits. A job already booked with the print partner may no longer be cancellable; we will explain the status before acting.
UK GDPR applies. You can request access, correction, export, restriction or deletion. Email writeself@rogergroup.xyz.
Technical details
Encryption: AES-256-GCM with random nonce per letter. Key stored separately from ciphertext. Auth: passwordless magic links via Resend. Payments: Stripe (PCI DSS compliant — we never touch card data). Hosting: Netlify. Database: Netlify Database. Print partner: Stannp UK.