Privacy Policy
Effective August 24, 2026
The short version: we collect what a letter needs to reach someone, and we share it with the partners who print it, post it, take the payment, check that the address is deliverable, and host the app. We sell nothing and we track nothing.
1 · What we collect
Your email address, and the name and return address you save to your profile.
The names and postal addresses you save to your address book, and the ones snapshotted onto each letter and correspondence.
The letters themselves — the text you write, your sign-off, and which typeface you chose.
A record of each payment: an amount, a status, and the identifier Stripe gives the checkout. We never receive or store card numbers.
Sign-in records kept by our authentication library, which include the IP address and browser user-agent of the session, plus the time zone your browser sends with each request so dates read correctly.
2 · Who we share it with
thanks.io, our printing and mailing partner. To post a letter we send it the recipient's name and address, your return name and address, and the rendered letter itself. It prints and mails what we send.
Stripe, for payment. Your card details go directly to Stripe and never reach us; we send an amount, a reference for the letter, and your email address so Stripe can receipt you.
Google Maps Platform, for addresses. Text you type into an address field is sent to Google's Places and Address Validation services to suggest and verify a deliverable address.
Cloudflare, which hosts CherryMail, stores its data, and sends your six-digit sign-in codes.
We do not sell personal information, and we run no advertising trackers or third-party analytics.
3 · Letters, kept on purpose
We store your letters so that you — and the person you wrote to, once they have an account — can read the correspondence in the app. A sent letter is permanent history: editing a contact later never rewrites what was printed on a letter already posted.
Each printed letter carries a QR code containing an unguessable reply token. Anyone holding the physical letter can open the reply page and write back. That page does not reveal your email address or give access to your account.
4 · Cookies
One cookie, holding your signed session token, so the app knows it is you. No advertising or tracking cookies.
5 · How long we keep it
Letters, contacts and correspondences are kept while your account exists. Payment records are kept as long as we need them for accounting and tax.
Sign-in codes are short-lived and expire on their own.
6 · Your choices
Write to hello@cherrymail.love to see, correct or delete what we hold about you, or to delete your account entirely — which removes your letters, contacts and correspondences.
Two things deletion cannot undo: a letter already posted is a physical object we cannot recall, and records held by our partners — thanks.io, Stripe, Cloudflare — are governed by their own policies and retention rules.
7 · Children
CherryMail is not intended for children under 13, and we do not knowingly collect their information. If you believe a child has used CherryMail, write to us and we will delete the account.
8 · Where data is handled
We mail to United States addresses only. Data is processed in the United States and across Cloudflare's global network, and by the partners named above.
9 · Changes
We may update this policy. The effective date at the top of this page tells you when it last changed.
10 · Contact
Questions about privacy, or a request about your data: hello@cherrymail.love.