deadletter is an underground postal service. We built it to be the opposite of a surveillance app. This page explains exactly what data the app touches, who can see it, and what we promise we will never do with it.
SHORT VERSION: We collect the minimum we need to make the app work. We do not sell data. We do not run ads. We do not have analytics SDKs that profile you. Direct messages are end-to-end encrypted — we cannot read them Direct messages require an in-person code exchange first — you can only write to someone whose code you have scanned face to face. Messages to private circles are encrypted on your device (a private circle re-keys itself the first time anyone opens it, and from that moment we hold nothing and cannot access its content at all; see Section 5). Messages to public circles work like open drops — anyone can join a public circle, so they are not encrypted and are screened before posting. You can use the app without giving us your name, email, or phone number. One big exception: open drops are public — the message and its exact location are visible to every user on the map for as long as the drop lasts, Open drops are ANONYMOUS: they carry no username and no account identifier, so they cannot be linked to you or to each other. Still, never leave an open drop anywhere you would not want publicly known — the location itself is public. Open-drop text is checked by an automated moderation service (OpenAI) before posting — used only to approve or reject it, never for training.
1. Who runs deadletter
The app is built and operated by Mad Infinitum Labs LLC (“we,” “us”), a California limited liability company based in Sacramento, California. Contact: contact@dead-letter.com.
2. What data we collect
2.1 Account data
- If you tap TUNE IN as a guest — you get an anonymous Firebase user ID. We never see your real name, email, or phone number.
- If you sign in with Apple — we receive your Apple-provided identifier and (optionally) the email or relay address you choose to share.
- If you sign in with Google — we receive your Google-provided identifier, your email address, and your display name.
- If you sign in with an email link — we receive the email address you typed.
- Username — the handle you claim. Public to other users.
2.2 Drops (your messages)
- Open drops — the message text and the exact GPS coordinates you anchored it to are stored unencrypted in our database. The drop’s location is visible on the radar map to any user, anywhere; the message text can be read by anyone who comes within about 15 meters and scans (the distance rule is enforced by the app; because the text is stored unencrypted, treat it as readable by anyone). Open drops may also carry an optional music/link enclosure — its title and URL are stored unencrypted and are public. Treat both the message and the location of an open drop as public. Open drops are ANONYMOUS — the public record carries no username and no account id, so open letters cannot be attributed to you or grouped together by anyone browsing. We retain authorship privately for moderation, ban enforcement and legal preservation only. Even so, do not anchor an open drop at your home or workplace: the LOCATION is public even though you are not.
- Direct drops (a message addressed to one person) — the message content is end-to-end encrypted using NaCl box (Curve25519 + XSalsa20-Poly1305) before it leaves your device. Only you and the intended recipient hold keys that can decrypt it — we do not. We literally cannot read these. Direct drops require an in-person code exchange: you can only address someone whose rotating code you scanned in person.
- Circle drops (a message addressed to a group) — messages to a private circle are encrypted before they leave your device with a key shared by the circle’s members, and are shown only to members inside the app. A private circle re-keys itself the first time a member opens it, and again whenever anyone joins or leaves; from that first re-key onward we hold no key for it and cannot read its letters (see Section 5 for the two caveats). Messages to a public circle (one anyone can join) are stored unencrypted, screened by automated moderation before publication, and shown to members.
- Drop metadata — we store the GPS coordinates of every drop, the time it was created, the recipient type (open / direct / circle), the chosen card style and stamp, any link enclosure (title and URL), altitude and AR surface-anchor data, the drop’s view count, and (for direct/circle drops only) the recipient’s identifier so we know who can decrypt.
- Location precision for private mail — for direct and circle drops, the coordinates in the publicly queryable record are rounded to roughly 110 meters. The exact anchor point is kept in a gated record that only the author and the intended recipients can read. This means other users can still see the approximate (roughly block-level) location of your private drops on the map — keep that in mind before anchoring private mail at your home or workplace.
- Photo attachments (possible on direct letters and on drops to private circles) — encrypted on your device before upload to Firebase Storage. Direct-letter photos are encrypted to the recipient and we cannot read them. Circle photos are encrypted with the circle’s shared key, so they follow that circle’s key exactly as its letters do (see Section 5). Open drops and public circles cannot include photos at all — the server refuses them, because a photo on a surface anyone can join is a photo nobody screened.
- Automated screening — the text of every open drop and every public-circle drop is sent to an automated moderation service (OpenAI) and screened before it is published; flagged text is rejected and never posted (see Section 4.1). If the screening service is temporarily unavailable, a drop may occasionally publish without pre-screening; reported content remains our backstop.
2.3 Location data
- We use your device’s GPS only when the app is in use, and only to (a) determine if you are within scanning range of a nearby drop, (b) anchor a drop you are creating, or (c) center the radar map.
- We do not store your continuous location history. Location-related records we do store: the GPS coordinates of drops you create, and a record of which drops your account has opened (see Section 2.5).
- We never use background location.
2.4 Notifications
- If you opt in to push notifications, we store a Firebase Cloud Messaging (FCM) device token so we can deliver mail alerts (such as replies and “someone found your drop”). The ME tab toggle stops direct-message alerts; to stop all push notifications, turn them off for deadletter in iOS Settings.
2.5 Diagnostic data
- When you open a drop, we record that your account opened it and when. This de-duplicates the drop’s views counter and powers the author’s read receipt. Because drops can only be opened near their location, treat this as a record that your account visited that drop’s location at that time.
- Cloud Functions log standard server-side errors. These logs do not contain decrypted message content. Logs roll over after 30 days.
- We do not run third-party analytics SDKs. There is no Mixpanel, Amplitude, Segment, Firebase Analytics, Google Analytics, or anything similar in the app.
- Like nearly every internet service, our servers and sub-processors automatically receive your IP address and basic device information (device model, OS version, app version) when the app communicates with them. These appear in short-lived server logs (30 days) and in Firebase’s own operational logs. This means “anonymous” use is anonymous to other users and to us in the ordinary course, but not perfectly anonymous at the infrastructure level.
2.6 Moderation data
- If you tap REPORT on a drop, we store a report record containing the offending drop’s content, the author’s identifier, your identifier, your email if you’re signed in (so we can follow up with you), and a timestamp.
- If you BLOCK another user, we store that user’s identifier in your blocklist so we can filter their drops out of your view.
2.7 Contacts and circle membership
- Contacts. Adding a contact requires scanning their code in person — there is no way to add someone remotely. A successful scan stores a contact record on both sides: each of you gets the other’s account identifier, their username if they have claimed one, and the time you connected. Both records are created at once, because a contact in deadletter is always mutual. Either of you can remove it at any time (ME → CONTACTS), which deletes both records — removing a contact also removes you from theirs.
- The codes themselves. A contact code is a random token that rotates every 60 seconds and expires with it. We store the token, the account that minted it, and its expiry, and we delete it shortly after it expires. A code carries no personal information and cannot be used to look anyone up.
- Circle membership. Joining a circle records which circles you belong to and when you joined, on your own account record. The join time is used to decide which letters you can see: joining a circle gives you access to what it receives from that moment on, never to the exact locations of letters left before you arrived. Circle owners and members can see the roster of who belongs to a private circle.
- Read records. When you open a letter, we record that your account opened that letter, so the author’s read count is accurate and so the same open is not counted twice. These records are automatically deleted after 90 days.
3. How we use the data
We use the data we collect only to:
- Operate the app (deliver drops to recipients, render the radar map, etc.)
- Send you push notifications you have opted into
- Screen the text of open drops with automated moderation before they are published
- Investigate user reports and respond to moderation requests — safety-related reports within 24 hours, others within a few days
- Detect and prevent abuse (spam, harassment, illegal content)
- Comply with legal obligations
We do not use your data to: profile you for advertising, sell to data brokers, train AI models (our moderation vendor processes open-drop text solely to return a moderation decision, not for training), score you for credit/insurance/employment, or share with anyone for marketing purposes.
4. Who else can see the data
4.1 Sub-processors we use
To run the app we rely on a small number of vendors. They process data on our behalf under their own contracts and privacy policies:
- Google (Firebase) — Authentication, Firestore database, Cloud Storage, Cloud Functions, Cloud Messaging. Servers are in the United States. Firebase Privacy
- Apple — Sign in with Apple, Push Notification Service. Apple Privacy
- Resend — Transactional email delivery: sign-in link emails and moderation correspondence. Resend Privacy
- OpenAI — automated content screening. Before an open drop or a public-circle drop is published, its text is sent to OpenAI’s moderation API to check for content that violates our Use Policy. Flagged text is rejected and never posted. OpenAI processes this text solely to return a moderation decision. If the screening service is temporarily unavailable, a drop may occasionally publish without pre-screening; reported content remains our backstop. OpenAI Privacy
- OpenStreetMap Foundation (Nominatim) — reverse geocoding for notifications. When we send a push about a drop, we convert the drop’s approximate coordinates (rounded to roughly 110 meters before sending) into a neighbourhood name using Nominatim. OSMF Privacy
When we add new sub-processors, we will update this list and notify users in advance of material changes.
4.2 Other deadletter users
- Open drops you create can be read by any user who comes within 15 meters of their location, and their exact location is visible on the radar map to any user, anywhere. Treat open drops — including where you left them — as public posts.
- Direct drops are visible only to the recipient.
- Circle drops are shown only to circle members inside the app. For a private circle we hold a copy of its key only until it re-keys itself, which happens the first time a member opens it after it is created (see Section 5).
- Open letters carry no username and no account identifier. They cannot be linked to you, or to each other, by anyone reading the app. Letters you address to a person or to a circle DO carry your username, so the people receiving them know who wrote to them.
4.3 Law enforcement and legal process
We will respond to valid legal process (subpoenas, court orders) but we will only produce data that we actually have. We cannot produce decrypted content of end-to-end encrypted direct drops because we do not have the keys. For private circles it depends on whether that circle has re-keyed yet: once it has, we no longer hold its key and cannot produce its content; before that, we can. Public-circle and open-drop content is not encrypted and can always be produced.
4.4 Business transfers
If Mad Infinitum Labs LLC is involved in a merger, acquisition, reorganization, or sale of assets, user data may be transferred as part of that transaction. Any recipient will be bound by the commitments in this policy, and we will notify you before your data becomes subject to a materially different privacy policy.
5. End-to-end encryption
This is the most important section. Every direct drop is encrypted on your device before it is uploaded to our servers, using keys derived from your account’s NaCl key pair. We do not have access to your private key. Direct drops require an in-person code exchange: you can only address someone whose rotating code you scanned in person. For direct drops this means:
- If our database is compromised, the contents of direct drops remain encrypted gibberish.
- If law enforcement compels us to produce direct drop content, we cannot.
- If you lose access to your account, we cannot recover direct drops on your behalf.
Private-circle drops sit between the two. They are encrypted on your device before upload with a key shared by the circle’s members. When a circle is created, our servers briefly hold a copy of its key so the circle can be set up at all — and then the circle re-keys itself: a member’s device generates a fresh key, seals it individually to every current member, and our copy is deleted. From that point we hold nothing for that circle in the live database and cannot decrypt its letters — see the backup caveat below.
Three honest caveats. First, the re-key happens the first time a member opens the circle after it is created — usually within minutes, but the window is however long that takes. Second, older circles re-key when we prompt them to or when their membership next changes; until then, we still hold their key. While we hold a key, we are technically able to decrypt that circle’s letters and could be legally required to produce them. We do not read them in the ordinary course — we access circle content only to investigate a reported violation or as required by law.
Third, and least obvious: our database keeps recoverable point-in-time snapshots for up to seven days, so for that period after a circle re-keys, its old key is still recoverable from backup even though it is gone from the live database. “We can no longer decrypt this circle” becomes unconditionally true one week after the re-key, not the instant it happens. We would rather say this plainly than round it off — every service with backups has this property and most do not mention it.
A circle also re-keys whenever someone joins or leaves. New members can read what the circle receives from their arrival onward, not what came before it; someone who leaves can read nothing new after they go.
Public circles are different again: anyone can join one, so their drops are stored unencrypted and screened by automated moderation before publication — treat a public circle like an open room.
Open drops are not end-to-end encrypted because they are designed to be read by anyone who finds them.
6. How long we keep data
- Drops you create — kept until they expire (some drops are ephemeral with 24-hour or 7-day lifetimes you choose) or until you delete your account.
- Reports — deleted from our active systems within 1 year of resolution; copies may persist for a limited period in operational email and backups before being purged.
- Server logs — kept for 30 days.
- FCM tokens — kept until you delete your account; revoking notification permission in iOS stops delivery.
- Account data (your user record, username, encryption public keys, blocklist) — kept until you delete your account.
- Unused circles — a circle that is more than 30 days old and has never contained a letter is automatically removed.
- Contacts — kept until either of you removes the contact or deletes their account. Removal is immediate and applies to both sides.
- Contact and circle codes — expire after 60 seconds and are deleted within the hour.
- Circle membership and join times — kept until you leave the circle or delete your account.
- Read records (which account opened which letter) — automatically deleted 90 days after the letter was opened.
- Photos attached to letters — deleted with their letter. A photo uploaded but never attached to anything is deleted within 24 hours.
- Appeals and moderation notices — kept until the appeal is resolved, and deleted with your account.
- Exception — legal preservation: content and records that we are required by law to preserve (for example, content reported to NCMEC under 18 U.S.C. § 2258A, or material subject to legal process or a litigation hold) are retained in a secured, access-restricted store for as long as the law requires, then deleted.
7. Your rights
You can:
- Delete drops from your collection at any time from the FOUND tab. Drops you have left for other people are not individually recallable — they expire at the end of any lifespan you chose, or stay where you left them. Deleting your account erases all of them at once (subject to the legal-preservation exception in Section 6). Copies of letters that other people already collected remain in their collections — like mail that has already been delivered.
- Delete your entire account and all associated data from the ME tab (ME → DELETE ACCOUNT) — deletion is immediate — or by emailing contact@dead-letter.com. We will complete deletion within 30 days for straightforward requests, and no later than 45 days — except for data we are required by law to retain (see Section 6). If you use deadletter as a guest, your anonymous account has no email attached — include your username (if you claimed one) or any details you can, and we will make reasonable efforts to locate and delete the account.
- Request a copy of your data — same email. We will provide a JSON export within 30 days for straightforward requests, and no later than 45 days.
- Block other users using the in-app BLOCK action.
- Report content using the in-app REPORT action.
- Opt out of push notifications in iOS Settings (the ME tab toggle stops direct-message alerts).
- Revoke location access in iOS Settings > Privacy & Security > Location Services. The app will lose its ability to find drops near you and to anchor new drops, but other functions continue to work.
California residents: you may request access to or deletion of your personal information by emailing contact@dead-letter.com; we honor these requests regardless of whether the CCPA technically applies to a service of our size, and we will not discriminate against you for making one. We do not sell or share personal information as those terms are defined in California law, and we do not track users across third-party sites or over time, so we do not respond to browser Do Not Track signals. If you are outside the United States, see Section 10 — we will honor reasonable access and deletion requests under local law, and you may lodge a complaint with your local data protection authority.
8. Children’s privacy
deadletter is intended for adults only and may not be used by anyone under the age of 18. We do not knowingly collect data from anyone under 18. If we learn we have collected data from a person under 18, we will delete it (except anything we are required by law to preserve). By using deadletter you represent that you are 18 or older. If you believe a user is under 18, email contact@dead-letter.com with the username; we will investigate and, if we determine the user is under 18, terminate the account and delete its data (except anything we are required by law to preserve). Every user must attest to being 18 or older when accepting our Use Policy, and we may require additional age confirmation before allowing use of some or all features.
9. Security
We protect your data using industry-standard practices:
- All traffic between your device and our servers is encrypted in transit (HTTPS / TLS).
- Direct drops are end-to-end encrypted; circle drops are encrypted before upload (see Section 5).
- Our database is protected by access controls and Firestore security rules. Only Cloud Functions running with admin credentials can perform privileged operations.
- Elevated access to moderation data is restricted to a minimal set of authorized administrator accounts.
No system is perfectly secure. If we discover a breach affecting your account, we will notify affected users without undue delay, consistent with applicable law.
10. International data transfers
deadletter is currently offered only in the United States, and we do not target or direct the app to residents of the EEA, the UK, or other regions. Our servers and our sub-processors’ servers are located in the United States. If you nonetheless use the app from outside the US, be aware that your data is processed in the US, where privacy laws may differ from those of your country.
11. Changes to this policy
We may update this policy when the app changes. If we make material changes (new data we collect, new sub-processors with sensitive access, changes to how we use your data), we will notify users via in-app notice or email at least 14 days before the change takes effect. We may make changes effective immediately where needed to protect users or comply with law (for example, raising the minimum age); in that case we will notify users promptly afterwards. Non-material changes (typo fixes, clarifications) we may make without notice. The “Effective” date at the top of this page indicates the most recent version.
12. Contact
Questions? Concerns? Want to delete your account, request your data, or report a privacy issue?
Email contact@dead-letter.com. We’ll respond within 7 days, usually faster.