Safety & privacy
How Lovelettersactually works
You may keep a letter here for twenty years. This page explains exactly what happens to it in the meantime: what is encrypted, who can open it, and the things we have not built yet.
Locked by default
Everything here is closed unless it's you. That's not a setting — it's how it was built.
Your letters
Encrypted before it's stored
What you write is scrambled before it ever reaches our database. What sits on disk is unreadable on its own.
The address is encrypted too
Not just the letter — the email address you're sending it to is protected the same way.
The link in the email isn't a key
If your letter's link gets forwarded, it still won't open. It only works for someone signed in with that exact email address.
No letter has a public address
There's no page, no preview, no link that works without signing in. Your letters don't live on the open web.
Your account
We never store your password
We keep a one-way scramble of it. We couldn't tell you your own password if you asked us to.
Security codes work the same way
The codes we email are never kept in readable form. They expire in 10 minutes, and asking for a new one cancels the old.
Changing your password signs out everywhere else
One change, and every other device is logged out immediately.
See every place you're signed in
Your account lists each browser and device signed in to it. Sign out of any one of them, or of all but the one in your hand.
Your photos
Your photos have no public link
Images in a letter are never openly reachable. Every view goes through a link that expires in 15 minutes, handed out only after we've checked you're allowed to see that letter.
We look inside every file, not at its name
Each image is decoded and rebuilt before it's stored. That also strips hidden data most people don't know is there — like where the photo was taken.
Two people, nobody else
An image belongs to exactly two people: the one who wrote the letter and the one who receives it. There is no third role.
Underneath all of it
Encrypted where it rests
The database itself is encrypted on disk, and backed up every day.
Encrypted on the way, too
Every connection is encrypted — your browser to us, and us to our own database. Nothing travels in the clear.
A key can be replaced without losing a word
Every letter records which key sealed it, and older keys keep opening what they sealed. A new key can take over for everything written after it.
What we're building next
Still in progress. We'd rather name it than imply we already have it.
Signing out when your email changes
Right now only a password change does that. An email change should too.
A second step when you sign in
Optional two-factor, for an account that may act long after you can.
Take everything with you
A full export of your letters, your people and your settings, whenever you want it.
Encryption only you can open
Today the key lives on our server. Moving to a version where only you hold it.
If anything here changes
This page changeswhen the product does
If we build something that makes one of these paragraphs wrong, the paragraph changes on the same day. If something here does not match what you see in your account, tell us — that is a bug in the product or a bug on this page, and both are ours.
Start with someone you love