Loveletters

Safety & privacy

How Lovelettersactually works

You may keep a letter here for twenty years. This page explains exactly what happens to it in the meantime: what is encrypted, who can open it, and the things we have not built yet.

Locked by default

Everything here is closed unless it's you. That's not a setting — it's how it was built.

Your letters

  • Encrypted before it's stored

    What you write is scrambled before it ever reaches our database. What sits on disk is unreadable on its own.

  • The address is encrypted too

    Not just the letter — the email address you're sending it to is protected the same way.

  • The link in the email isn't a key

    If your letter's link gets forwarded, it still won't open. It only works for someone signed in with that exact email address.

  • No letter has a public address

    There's no page, no preview, no link that works without signing in. Your letters don't live on the open web.

Your account

  • We never store your password

    We keep a one-way scramble of it. We couldn't tell you your own password if you asked us to.

  • Security codes work the same way

    The codes we email are never kept in readable form. They expire in 10 minutes, and asking for a new one cancels the old.

  • Changing your password signs out everywhere else

    One change, and every other device is logged out immediately.

  • See every place you're signed in

    Your account lists each browser and device signed in to it. Sign out of any one of them, or of all but the one in your hand.

Your photos

  • Your photos have no public link

    Images in a letter are never openly reachable. Every view goes through a link that expires in 15 minutes, handed out only after we've checked you're allowed to see that letter.

  • We look inside every file, not at its name

    Each image is decoded and rebuilt before it's stored. That also strips hidden data most people don't know is there — like where the photo was taken.

  • Two people, nobody else

    An image belongs to exactly two people: the one who wrote the letter and the one who receives it. There is no third role.

Underneath all of it

  • Encrypted where it rests

    The database itself is encrypted on disk, and backed up every day.

  • Encrypted on the way, too

    Every connection is encrypted — your browser to us, and us to our own database. Nothing travels in the clear.

  • A key can be replaced without losing a word

    Every letter records which key sealed it, and older keys keep opening what they sealed. A new key can take over for everything written after it.

What we're building next

Still in progress. We'd rather name it than imply we already have it.

  • Signing out when your email changes

    Right now only a password change does that. An email change should too.

  • A second step when you sign in

    Optional two-factor, for an account that may act long after you can.

  • Take everything with you

    A full export of your letters, your people and your settings, whenever you want it.

  • Encryption only you can open

    Today the key lives on our server. Moving to a version where only you hold it.

If anything here changes

This page changeswhen the product does

If we build something that makes one of these paragraphs wrong, the paragraph changes on the same day. If something here does not match what you see in your account, tell us — that is a bug in the product or a bug on this page, and both are ours.

Start with someone you love