Privacy Policy
Last updated: August 4, 2026
Introduction
- Welcome to Timedletter ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our timed message delivery service at timedletter.com (the "Service").
Please read this Privacy Policy carefully. By accessing or using our Service, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
Information We Collect
- We collect information you provide directly (account details, payment information, support requests, feedback, message content, recipient details, and check-in preferences), information collected automatically (device information, usage data, cookies, and analytics), and information from third-party services (authentication providers and payment processors).
How We Use Your Information
- We use your information to provide and maintain the Service (store encrypted messages, manage check-in schedules, and trigger delivery), process payments, manage your account, improve the Service, communicate with you (including the check-in requests we send to your account email once a check-in is missed), and ensure security.
- For EEA users, we process personal data based on contract performance, legitimate interests, consent, and legal obligations.
How We Share Your Information
- We share information with service providers: Stripe (payments), Resend (email and message delivery), cloud hosting providers, and anonymized analytics services.
- We also share information with your designated recipients upon delivery trigger, in the event of a business transfer (with advance notice), when required by law, or to protect the rights and safety of Timedletter and its users. We do not sell your personal information. Timedletter is funded entirely by the people who buy it.
Data Storage and Security
- Your data is stored on secure servers. Security measures include encryption at rest (message bodies and recipient addresses are encrypted, and decrypted only when you open them in your account and when they are delivered; subject lines are stored unencrypted so that you can search your own messages), SSL/TLS encryption in transit, access controls and an internal policy against staff reading your message content, secure authentication, and hashed passwords.
- While we implement industry-leading security practices, no electronic storage method is 100% secure. We cannot guarantee absolute security.
Data Retention
- We retain account information while your account is active and for a reasonable period thereafter. Messages are stored until you delete them or delete your account, including messages that have already been delivered. Delivery logs are retained for confirmation. Payment data is retained per financial regulations. Analytics data is kept in anonymized form. When data is no longer necessary, we delete or anonymize it.
Your Privacy Rights
- You have the right to access, correct, delete, object to, or restrict processing of your personal information, and to withdraw consent at any time. You may also pause check-ins directly from your dashboard during hospital stays or extended travel; messages you set for an exact date are unaffected by a pause. To exercise these rights, use your account settings or contact us at [email protected]. We will respond within 30 days.
- EEA residents have additional rights under GDPR, including the right to lodge a complaint with their local data protection authority. California residents have rights under the CCPA, including the right to know, delete, and opt out of the sale of personal information (we do not sell personal information).
Cookies and Tracking Technologies
- We use essential, functional, analytics, and performance cookies. You can control cookies through your browser settings, though disabling some may limit Service functionality. We do not currently respond to "Do Not Track" signals.
Children's Privacy
- Our Service is not directed to individuals under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.
Third-Party Links and Services
- Our Service may link to third-party websites we do not operate. We assume no responsibility for their content or privacy practices and encourage you to review their policies.
Changes to This Privacy Policy
- We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last Updated" date, notifying you by email, and providing notice through our Service. Continued use of the Service constitutes acceptance of the updated policy.
Contact Us
- If you have questions, concerns, or requests regarding this Privacy Policy, please contact us: Email: [email protected]
Response Time: We aim to respond to all inquiries within 48 hours.
For GDPR-related inquiries, please mark your communication as "GDPR Request" in the subject line.
This Privacy Policy is effective as of the "Last Updated" date indicated above.