WHAT WE COLLECT,
WHAT WE DON’T

Effective August 12, 2026 · Version 1.1

deadletter is an underground postal service. We built it to be the opposite of a surveillance app. This page explains exactly what data the app touches, who can see it, and what we promise we will never do with it.

SHORT VERSION: We collect the minimum we need to make the app work. We do not sell data. We do not run ads. We do not have analytics SDKs that profile you. Direct messages are end-to-end encrypted — we cannot read them Direct messages require an in-person code exchange first — you can only write to someone whose code you have scanned face to face. Messages to private circles are encrypted on your device (a private circle re-keys itself the first time anyone opens it, and from that moment we hold nothing and cannot access its content at all; see Section 5). Messages to public circles work like open drops — anyone can join a public circle, so they are not encrypted and are screened before posting. You can use the app without giving us your name, email, or phone number. One big exception: open drops are public — the message and its exact location are visible to every user on the map for as long as the drop lasts, Open drops are ANONYMOUS: they carry no username and no account identifier, so they cannot be linked to you or to each other. Still, never leave an open drop anywhere you would not want publicly known — the location itself is public. Open-drop text is checked by an automated moderation service (OpenAI) before posting — used only to approve or reject it, never for training.

1. Who runs deadletter

The app is built and operated by Mad Infinitum Labs LLC (“we,” “us”), a California limited liability company based in Sacramento, California. Contact: contact@dead-letter.com.

2. What data we collect

2.1 Account data

2.2 Drops (your messages)

2.3 Location data

2.4 Notifications

2.5 Diagnostic data

2.6 Moderation data

2.7 Contacts and circle membership

3. How we use the data

We use the data we collect only to:

We do not use your data to: profile you for advertising, sell to data brokers, train AI models (our moderation vendor processes open-drop text solely to return a moderation decision, not for training), score you for credit/insurance/employment, or share with anyone for marketing purposes.

4. Who else can see the data

4.1 Sub-processors we use

To run the app we rely on a small number of vendors. They process data on our behalf under their own contracts and privacy policies:

When we add new sub-processors, we will update this list and notify users in advance of material changes.

4.2 Other deadletter users

4.3 Law enforcement and legal process

We will respond to valid legal process (subpoenas, court orders) but we will only produce data that we actually have. We cannot produce decrypted content of end-to-end encrypted direct drops because we do not have the keys. For private circles it depends on whether that circle has re-keyed yet: once it has, we no longer hold its key and cannot produce its content; before that, we can. Public-circle and open-drop content is not encrypted and can always be produced.

4.4 Business transfers

If Mad Infinitum Labs LLC is involved in a merger, acquisition, reorganization, or sale of assets, user data may be transferred as part of that transaction. Any recipient will be bound by the commitments in this policy, and we will notify you before your data becomes subject to a materially different privacy policy.

5. End-to-end encryption

This is the most important section. Every direct drop is encrypted on your device before it is uploaded to our servers, using keys derived from your account’s NaCl key pair. We do not have access to your private key. Direct drops require an in-person code exchange: you can only address someone whose rotating code you scanned in person. For direct drops this means:

Private-circle drops sit between the two. They are encrypted on your device before upload with a key shared by the circle’s members. When a circle is created, our servers briefly hold a copy of its key so the circle can be set up at all — and then the circle re-keys itself: a member’s device generates a fresh key, seals it individually to every current member, and our copy is deleted. From that point we hold nothing for that circle in the live database and cannot decrypt its letters — see the backup caveat below.

Three honest caveats. First, the re-key happens the first time a member opens the circle after it is created — usually within minutes, but the window is however long that takes. Second, older circles re-key when we prompt them to or when their membership next changes; until then, we still hold their key. While we hold a key, we are technically able to decrypt that circle’s letters and could be legally required to produce them. We do not read them in the ordinary course — we access circle content only to investigate a reported violation or as required by law.

Third, and least obvious: our database keeps recoverable point-in-time snapshots for up to seven days, so for that period after a circle re-keys, its old key is still recoverable from backup even though it is gone from the live database. “We can no longer decrypt this circle” becomes unconditionally true one week after the re-key, not the instant it happens. We would rather say this plainly than round it off — every service with backups has this property and most do not mention it.

A circle also re-keys whenever someone joins or leaves. New members can read what the circle receives from their arrival onward, not what came before it; someone who leaves can read nothing new after they go.

Public circles are different again: anyone can join one, so their drops are stored unencrypted and screened by automated moderation before publication — treat a public circle like an open room.

Open drops are not end-to-end encrypted because they are designed to be read by anyone who finds them.

6. How long we keep data

7. Your rights

You can:

California residents: you may request access to or deletion of your personal information by emailing contact@dead-letter.com; we honor these requests regardless of whether the CCPA technically applies to a service of our size, and we will not discriminate against you for making one. We do not sell or share personal information as those terms are defined in California law, and we do not track users across third-party sites or over time, so we do not respond to browser Do Not Track signals. If you are outside the United States, see Section 10 — we will honor reasonable access and deletion requests under local law, and you may lodge a complaint with your local data protection authority.

8. Children’s privacy

deadletter is intended for adults only and may not be used by anyone under the age of 18. We do not knowingly collect data from anyone under 18. If we learn we have collected data from a person under 18, we will delete it (except anything we are required by law to preserve). By using deadletter you represent that you are 18 or older. If you believe a user is under 18, email contact@dead-letter.com with the username; we will investigate and, if we determine the user is under 18, terminate the account and delete its data (except anything we are required by law to preserve). Every user must attest to being 18 or older when accepting our Use Policy, and we may require additional age confirmation before allowing use of some or all features.

9. Security

We protect your data using industry-standard practices:

No system is perfectly secure. If we discover a breach affecting your account, we will notify affected users without undue delay, consistent with applicable law.

10. International data transfers

deadletter is currently offered only in the United States, and we do not target or direct the app to residents of the EEA, the UK, or other regions. Our servers and our sub-processors’ servers are located in the United States. If you nonetheless use the app from outside the US, be aware that your data is processed in the US, where privacy laws may differ from those of your country.

11. Changes to this policy

We may update this policy when the app changes. If we make material changes (new data we collect, new sub-processors with sensitive access, changes to how we use your data), we will notify users via in-app notice or email at least 14 days before the change takes effect. We may make changes effective immediately where needed to protect users or comply with law (for example, raising the minimum age); in that case we will notify users promptly afterwards. Non-material changes (typo fixes, clarifications) we may make without notice. The “Effective” date at the top of this page indicates the most recent version.

12. Contact

Questions? Concerns? Want to delete your account, request your data, or report a privacy issue?

Email contact@dead-letter.com. We’ll respond within 7 days, usually faster.