LEGAL DOCUMENT
Privacy Policy
Version 1.0 · effective 2026-07-29
1. About this Policy
- This Policy explains how The Old Letters, referred to as “TOL” or the “Service”, processes personal data when a person uses https://theoldletters.com, an Account, private correspondence, a Subscription, support or security features.
- It reflects in particular Regulation (EU) 2016/679, the General Data Protection Regulation or “GDPR”, the Polish Personal Data Protection Act, Polish Electronic Communications Law and the Polish Act on Providing Services by Electronic Means.
- Cookies, local storage and similar technologies are described separately at https://theoldletters.com/en/cookie-policy.
2. Controller
- The controller is Joanna Szamota, carrying on a sole-trader business under the registered name “Joanna Szamota Blackgrain Workshop”, ul. Zachodnia 24, 05-822 Milanówek, Masovian Voivodeship, Poland, NIP 5291840195, REGON 521704456.
- Privacy enquiries may be sent to support@theoldletters.com.
- The controller has not appointed a data protection officer unless that obligation arises in the future. Questions should be sent to the address above.
- TOL Users remain the independent authors and recipients of their correspondence. The controller determines the purposes and means of processing needed to operate the Service but does not use private Letter content for its own advertising, profiling or AI-model training purposes.
3. Key points
- TOL processes Account data, technical data, correspondence metadata, Subscription information and content supplied to support.
- Letter content and attachments are end-to-end encrypted on the User’s device before transmission to TOL infrastructure. Content encryption does not automatically cover the technical metadata required to deliver a message.
- TOL does not sell personal data or disclose private correspondence to advertisers.
- TOL does not use Letter content for behavioural advertising, marketing profiles or training artificial intelligence models.
- Complete payment-card data is processed by the payment provider rather than stored by TOL.
- Data may be processed by infrastructure, authentication, payment, anti-bot, transactional-email and support suppliers only to the extent needed to provide the Service.
- Users have GDPR rights including access, rectification, erasure, restriction, portability, objection and the right to complain to a supervisory authority.
4. Data we process
4.1. Account and identity data
We may process:
- email address;
- display name, first name, nickname or initials supplied by the User;
- internal Account identifier;
- Account creation date, last sign-in, Account status and language;
- sign-in method, email confirmation and active-session information;
- security settings and access-recovery information; passwords are stored only in a technically protected form and TOL does not have access to plaintext passwords;
- an avatar or other profile data if enabled;
- an 18-or-over declaration and verification data only where necessary to resolve a reasonable age concern;
4.2. Private correspondence data
We process:
- encrypted Letter content;
- encrypted attachments;
- sender and recipient identifiers;
- creation, sending, delivery, opening, archiving or deletion time;
- thread, mailbox or Space identifier;
- delivery status and technical error information;
- selected stationery, envelope, seal, theme and visual settings;
- message or attachment size;
- information necessary for key distribution and synchronisation, where required by the feature.
Letter content and attachments are encrypted end-to-end on the User’s device. Metadata necessary to deliver a message cannot be completely hidden from the system because the Service must know where and when to route encrypted data.
4.3. Contacts, invitations and Duo or Family Spaces
We may process:
- Account and relationship identifiers;
- an invitee’s email address where they do not yet have an Account;
- the sender, date, status, expiry and use of an invitation;
- membership, role, permissions and billing administrator of a Space;
- blocking or relationship termination information;
- sharing settings chosen by members;
An inviter should provide only the address of a person whom they have a reasonable basis to contact and must not use invitations for spam or marketing.
4.4. Payment and Subscription data
We may process:
- selected Plan, currency, price, Billing Period and Subscription status;
- Stripe customer, Subscription, payment, invoice or coupon identifiers;
- payment, renewal, cancellation, refund or failure status;
- billing information required for an accounting document;
- country, postcode and tax information where required;
- limited payment-method information such as card brand and last digits where provided by the operator.
TOL does not store the complete card number, CVC or online-banking credentials.
4.5. Technical, log and security data
We may process:
- IP address and an approximate country or region derived from it;
- date, time, session identifier and sign-in events;
- device type, operating system, browser, application version and language;
- technical identifiers, session tokens and local-storage data necessary for operation;
- requested resources, response codes, errors and performance diagnostics;
- attempted abuse, rate limits, blocks, suspicious sign-ins and security changes;
- signals generated by Cloudflare Turnstile or a comparable anti-bot mechanism;
- consent and document-acceptance history, including version, date and technical evidence.
We do not use these data to build an interests profile from correspondence content.
4.6. Support, complaints and abuse reports
We may process:
- email address, name and report content;
- support communication history;
- technical identifiers required to solve the issue;
- documents or screenshots supplied voluntarily;
- decrypted Letter content only where the User supplies it themselves;
- request, decision, remediation and appeal information;
- risk category, confidentiality preference, and urgency assessment;
- an evidence package selected by the reporter containing only specific Letters, attachments or metadata knowingly disclosed for the report;
- access logs for evidence, escalation and contact with competent authorities or specialised bodies.
Users must not send passwords, complete card details or a recovery phrase.
4.7. Marketing data
Where a User separately subscribes to a newsletter or marketing, we may process:
- email address;
- language and market;
- date, source and scope of consent;
- opt-out information;
- opening or click information only where lawful and covered by any required consent to optional technologies.
A newsletter is not a condition of using TOL.
4.8. Aggregated Service-use events
To assess whether the Service's core journeys work, TOL counts only predefined product events such as a public-page view, registration start, first Letter sent or Subscription start. An event may include language, a coarse interface placement, Plan identifier, currency or billing period. Events are immediately combined into daily totals and do not contain an Account identifier, email address, invitation code, Letter or Correspondence identifier, text, title, attachment, key or other free-form field. TOL does not use cookies, localStorage or a third-party analytics pixel for this purpose and does not create an individual User journey.
5. Sources of data
We receive data:
- directly from the User during registration, Service use, payment and support contact;
- from other Users when they invite a person, address a Letter to them or add them to a Space;
- automatically from the device and infrastructure during use;
- from payment, hosting, authentication, security and transactional-email suppliers;
- from competent authorities or persons reporting abuse where circumstances require it.
6. Purposes and legal bases
| Purpose | Example data | Legal basis |
| Create and administer an Account | email, identifier, settings, sessions | Article 6(1)(b) GDPR, performance of an agreement or pre-contract steps |
| Create, encrypt, store and deliver Letters | encrypted content, recipient, metadata, status | Article 6(1)(b) GDPR and applicable electronic-service and communications-secrecy rules |
| Duo, Family, contacts and invitations | membership, roles, invitee email | Article 6(1)(b) for the User and Article 6(1)(f) for a limited, reasonably expected invitation |
| Consent management | privacy preferences and evidence of consent or withdrawal | Article 6(1)(a) GDPR, or another appropriate basis for the function |
| Subscription and payment | Plan, Stripe identifiers, status, invoice data | Article 6(1)(b); Article 6(1)(c) for tax and accounting duties |
| Transactional messages | email, Account status, relevant event | Article 6(1)(b) or 6(1)(f), depending on the message |
| Security and prevention of bots, fraud and Account takeover | IP, sessions, logs, Turnstile, blocks | Article 6(1)(f), legitimate interests in protecting Users and the Service; Article 6(1)(c) where a legal duty applies |
| Diagnostics and maintenance | errors, logs, device configuration | Article 6(1)(b) or 6(1)(f) |
| Support and complaints | Account data, report, payment | Article 6(1)(b), 6(1)(c) or 6(1)(f) |
| Abuse handling and legal claims | report, evidence, logs, decisions | Article 6(1)(f); Article 6(1)(c) where required by law |
| Tax, accounting and legal obligations | invoices, transactions, identification | Article 6(1)(c) |
| Newsletter and electronic marketing | email, consent, preferences | Article 6(1)(a) and the required consent for marketing communications |
| Optional analytics or marketing device technologies | identifiers, events, preferences | Article 6(1)(a) and consent required under Electronic Communications Law |
| Service development using aggregated data | usage statistics excluding Letter content | Article 6(1)(f), and prior consent where a non-essential device technology is used |
7. Legitimate interests
Where Article 6(1)(f) GDPR is used, our legitimate interests are:
- protecting Accounts, correspondence, payments and infrastructure;
- detecting abuse, spam, bots, intrusion and fraud;
- maintenance, diagnosis and stability improvement without analysing private Letter content;
- support, dispute handling and legal claims;
- sending a limited, expected invitation within a User relationship;
- aggregated business statistics without profiling private correspondence.
A User may object for reasons relating to their particular situation. An objection to direct marketing is unconditional.
8. Special-category data and data about other persons
- TOL does not require health, religion, political opinion, origin, sexuality or other special-category data in a profile.
- A User may nevertheless include private information in an encrypted Letter. TOL technically processes encrypted data to transmit and store it without using the semantic meaning for its own purposes.
- Users should respect recipient and third-party privacy and provide only data that they are entitled to use.
- If a User voluntarily discloses special-category data in a decrypted support report, they should limit it to what is necessary. Depending on the matter, the basis may be explicit consent, legal claims or another basis provided by law.
9. Encryption and limits of confidentiality
- TOL encrypts Letter content and attachments end-to-end on the User’s device. The server stores encrypted content and does not hold the key needed to read it.
- Private keys are protected by the User’s password. Losing both the password and recovery code may permanently prevent access to encrypted correspondence.
- Even where content is encrypted, TOL may see metadata needed to supply the Service, including participant identifiers, time, status, size and technical information.
- Content decrypted on a recipient’s device is outside TOL’s exclusive control. The recipient may copy, photograph or disclose it, even where that would violate law or agreed rules.
- The Provider may be required to disclose data it holds to a competent authority pursuant to a valid legal request. This does not create a capability to decrypt data where the Provider lacks the relevant key.
- TOL does not create hidden key access solely to enable future reading of private Letters. A material architectural change affecting this statement requires documentation updates and User notice.
10. Whether data are required
- Required data are necessary for an agreement, security or settlement.
- Without an email address or required authentication data, an Account cannot be created.
- Without payment data, a paid Plan cannot be purchased, although a free Plan may remain available.
- Profile data, newsletters and optional preferences are voluntary.
11. Recipients and suppliers
Data may be disclosed only as necessary to the following recipients:
| Recipient or category | Role and scope |
| Supabase | backend, database, authentication, storage and server functions |
| Netlify | website and Application hosting, CDN, deployments, technical logs and infrastructure protection |
| Stripe and affiliates | payments, Subscriptions, invoices, refunds, fraud prevention and regulatory duties; Stripe may act as an independent controller for some processing |
| Cloudflare | Turnstile and protection of forms against bots, abuse and attacks |
| home.pl S.A. | transactional email/SMTP provider; sign-in, security, payment and support messages |
| Accountants, legal advisers and auditors | settlement, compliance, legal claims and professional advice under confidentiality duties |
| Public authorities and courts | where disclosure is legally required or supported by a valid request |
| Specialised child-safety teams and trusted reporting bodies | only as necessary for suspected child sexual exploitation, a threat to life or another serious abuse matter, on an appropriate legal basis |
| Purchaser of a business or part of it | only in a lawful transaction, subject to confidentiality and User notice where required |
- Processors receive data under data-processing agreements and the controller’s instructions.
- The table above is the current list of key suppliers and their roles.
- TOL does not give advertisers data enabling them to read or profile private correspondence.
12. Transfers outside the EEA
- Some suppliers have entities or infrastructure outside the European Economic Area, particularly in the United States.
- Where data are transferred outside the EEA, the GDPR transfer mechanism used may include:
- a European Commission adequacy decision;
- the recipient’s participation in a recognised adequacy framework where the transfer is covered;
- European Commission Standard Contractual Clauses together with a transfer assessment and supplementary safeguards;
- another lawful instrument or derogation.
- Processing scope and location depend on the selected project region, account configuration and supplier subprocessors.
- Information about safeguards may be requested at support@theoldletters.com, subject to trade-secret and security restrictions.
13. Retention
We apply the following retention periods:
| Category | Period |
| Active Account data | for the duration of the agreement |
| Account data after deletion request | deletion or anonymisation in active systems without undue delay and no later than 30 days |
| Residual isolated backups | until overwritten under the backup cycle, no longer than 90 days and not restored to ordinary use |
| Encrypted Letters and attachments | until deletion by an authorised User, Account deletion or expiry of an implemented retention feature |
| Unaccepted invitation metadata | up to 30 days after invitation expiry unless needed to prevent abuse |
| Security and authentication logs | generally 90 days; longer only for an incident, abuse matter or legal obligation |
| Support cases | up to 24 months after closure unless a shorter period is sufficient |
| Abuse reports and evidence | up to three years after closure or until proceedings and limitation periods end |
| Subscription records and invoices | for the period required by tax and accounting law, generally five years calculated under Polish tax rules |
| Evidence of Terms acceptance, consent and withdrawal | for the agreement and applicable limitation period |
| Adult declaration and verification data | the declaration for the Account lifetime and applicable claim period; additional verification material only as long as needed to complete a review and document its outcome |
| Newsletter data | until consent withdrawal, opt-out or permanent delivery failure; evidence of consent may be kept for the claim limitation period |
| Daily aggregated usage statistics | up to 400 days; without Account, correspondence or device identifiers |
| Claim-related data | until final resolution and expiry of the relevant limitation period |
- Data are erased or anonymised after the period unless a further legal retention duty applies.
- Backup data are not used for ordinary business purposes and are removed when the copy is overwritten.
- Anonymous statistics that cannot reasonably be linked to an individual may be retained longer.
14. Data-subject rights
A person may request:
- access and a copy;
- rectification of inaccurate and completion of incomplete data;
- erasure where a legal ground exists;
- restriction of processing;
- portability of supplied data processed automatically on consent or contract;
- objection to legitimate-interest processing for reasons relating to the person’s situation;
- unconditional objection to direct marketing;
- withdrawal of consent at any time without affecting earlier lawful processing;
- protection from a solely automated decision producing legal or similarly significant effects, subject to legal exceptions;
- notice of a personal-data breach where law requires it.
Exercising rights
- Send a request to support@theoldletters.com.
- To protect the Account, we may request reasonable identity confirmation and will not ask for more data than necessary.
- We respond without undue delay, normally within one month. A complex request may be extended as permitted by GDPR, with notice.
- Requests are generally free. GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
- Access and portability must not adversely affect other persons’ rights and freedoms, particularly their correspondence secrecy.
- If TOL cannot technically decrypt content without a User key, we may provide encrypted data and available metadata but cannot promise plaintext recovery.
15. Supervisory complaint
- A person who believes data are processed unlawfully may complain to the President of the Polish Personal Data Protection Office, or another competent supervisory authority under GDPR.
- Contact details are available at https://uodo.gov.pl.
- We encourage prior contact so that TOL can investigate, but this is not a condition of a complaint.
16. Automated decisions and bot protection
- TOL does not make solely automated decisions producing legal or similarly significant effects without a lawful basis and safeguards.
- Security systems may automatically assess sign-in, sending, payment or traffic risk and temporarily require additional verification, apply a limit or block a suspicious request.
- Cloudflare Turnstile may analyse technical device and traffic signals to distinguish a person from automated abuse.
- A User may report an erroneous automated block and request human review where this does not undermine other persons’ security.
17. Data security
Measures in use include:
- HTTPS/TLS transport encryption;
- client-side Letter-content encryption as documented;
- password hashing by the authentication supplier;
- access control, least privilege and separation of administrative roles;
- database Row Level Security and access policies;
- multi-factor authentication for administrative accounts;
- privileged-operation logging and access reviews;
- anti-bot measures, rate limiting and abuse detection;
- backups and restoration procedures;
- vulnerability, update and secrets management;
- confidentiality obligations and access authorisations;
- incident and breach response procedures.
Security is a process, not a guarantee. Users must also protect devices, email and recovery materials.
18. Data and communications-security breaches
- We maintain procedures to assess incidents, mitigate impact and document breaches.
- Where a breach is likely to create a risk to rights and freedoms, it is reported to the competent authority within the period required by law.
- Where the risk is high, affected persons are notified unless a statutory exception applies.
- For data covered by communications secrecy, applicable duties under Polish Electronic Communications Law are also followed.
19. Adults only
- The Service is intended only for persons aged 18 or over. We do not operate accounts for minors, do not direct the Service to children, and do not knowingly collect data from anyone under 18.
- Registration requires a declaration of adulthood. The current registration form does not request a date of birth and we do not store it. If a different proportionate age-assurance method becomes necessary, we will explain its scope, purpose, legal basis and retention period before collecting additional data.
- Because the Service is not offered directly to a child, Article 8 GDPR and the varying national child-consent thresholds do not apply to it.
- If we obtain credible information that an Account belongs to a person under 18, we promptly restrict the Account, then close it and erase the associated data, except data required by law. We do not use such data for any other purpose.
- Anyone may report a suspicion that an Account belongs to a minor to support@theoldletters.com. No Account is required, and such reports are prioritised.
- We do not apply behavioural advertising, marketing profiling, or use of Letter content for training artificial intelligence models to any User.
- Reports concerning child sexual abuse material continue to be handled regardless of the Service's age profile. An adult User can report such content, and we escalate the matter to the competent authorities and specialist organisations.
19a. Users outside Poland
- The Service is available globally. The controller is established in Poland but processes data of Users in other countries.
- The Service is not directed to children. We nevertheless assess child-specific obligations by reference to how the Service is actually used, not only its 18+ declaration. Our current position is that the UK Age Appropriate Design Code does not apply because access is intended to be effectively restricted to adults. We keep that position under regular review, including the likelihood of significant child access and the effectiveness and proportionality of the age-assurance measures used.
- Regardless of jurisdiction, the controller does not use behavioural advertising, does not profile Users for marketing, and does not use Letter content to train artificial intelligence models.
- A person invited to the Service who is not yet a User receives an Article 14 GDPR notice in the body of the invitation email, together with the ability to decline the invitation and block further invitations without creating an Account.
- The Provider's current position, subject to continuing review and independent advice from a qualified UK specialist, is that The Old Letters is designed to fall within the email-service exemption in paragraph 1 of Schedule 1 to the UK Online Safety Act 2023. This is not a determination by Ofcom or a court. A change to features or actual use may change the assessment. Safety and reporting information for UK users is available at https://theoldletters.com/legal/uk-illegal-content.
20. External links and services
- The Service may link to external sites or services. Their operators are separate controllers with their own policies.
- Opening a link may disclose data to that operator. Users should review its privacy information.
- TOL is not responsible for practices of entities it does not control, subject to mandatory law.
21. Cookies and similar technologies
- TOL may use cookies, local storage, session storage, tokens and other device technologies.
- Necessary technologies may operate without consent where required to transmit a communication or provide a function explicitly requested by the User.
- Optional technologies, particularly analytics or marketing, are enabled only after voluntary consent where required.
- Details, controls and the current inventory are in the Cookie Policy.
22. Changes to this Policy
- This Policy may change because of law, functions, suppliers, security or processing practices.
- Material changes will be communicated in the Service, by email or on another Durable Medium before they take effect where required or reasonable.
- A change to consent-based processing cannot be obtained by silence or continued use. Any required consent will be collected separately.
- We retain evidence of previous versions and provide it on request where required.
23. Contact
Privacy questions, requests and reports may be sent to:
Joanna Szamota Blackgrain Workshop ul. Zachodnia 24 05-822 Milanówek, Poland Email: support@theoldletters.com