Privacy Policy
Last Updated: August 15, 2026
Introduction
Lingerlet is a personal project operated by Zifan Wang (“Lingerlet,” “we,” “us,” or “our”) — a letter formatting service that presents text in a way that mimics the look of physical letters in a digital or web environment (for example handwritten-style fonts, letter-paper backgrounds, and letter-sized pages). You may type or paste letter content and export a formatted PDF without signing in. Optionally, you may use sharing features (such as a shareable link) that may require sign-in. Access to the Service is currently free.
This Privacy Policy explains how we collect, use, share, and protect information in connection with the Service. It works together with our Terms of Service. By using the Service — including formatting or exporting a letter without signing in, or signing in to use optional sharing features — you acknowledge that you have read and understood this Privacy Policy and agree to our Terms of Service.
If you have questions about this Privacy Policy, see Contact us below.
1. Information we collect
We collect information needed to provide and operate the Service. What we collect depends on how you use the Service. Formatting and PDF export in your browser do not, by themselves, require you to send letter content to our servers. Optional sharing features do involve server-side storage, as described below.
a. Sign-in and authentication
Formatting letter content and exporting a PDF do not require sign-in. When you use optional sharing features that require sign-in — for example creating a shareable link, or opening shared letter content as an intended recipient — You sign in through a third-party authentication provider we support (currently Google, via Supabase Auth). From that provider, we may receive identifiers such as a subject or user id and your email address.
Authentication credentials are handled by the third-party authentication provider. Those providers have their own terms and privacy policies, and we do not control their practices.
b. Sharing-related information
If you create a shareable link, we may collect:
- the Gmail recipient you designate (you provide a local part; we store a normalized Gmail address used to decide who may open the link);
- the timezone you provide (used to set when shared content becomes viewable);
- your signed-in user id as the creator of the link; and
- metadata such as when the link was created, when content becomes viewable, and, after a successful open, identifiers related to who opened it (for example, a user id and first-opened time).
If you open a shareable link as a recipient, we may collect your signed-in identity and use it to check that you are the intended recipient and to record that the letter was opened.
c. Letter content and formatting
In your browser. Letter text and formatting choices (such as paper style and font style) that you use only for formatting and PDF export are processed in your browser for that purpose. If you turn on an optional keep a copy in this browser (or similar) feature, a draft copy may be stored in your browser (for example in local storage) on that device and browser profile. That browser-stored draft is under your control on that device; Lingerlet does not receive it solely because you typed it for formatting or PDF export, and we do not sync it across your devices.
On our servers (when you share). If you create a shareable link (or use another sharing method we offer), we store a snapshot of the letter content and related formatting as of the time you create the share, so we can make it available to the intended recipient under the Service’s rules (including delayed viewing and later deletion). Later edits in your draft editor do not change a share already created.
We do not currently offer image enclosures as part of sharing. If we later allow attachments or other media, we will describe what we collect in an updated Privacy Policy.
d. Technical and usage data
We may collect technical information when you use the Service, including IP address, device type and browser information (such as user agent), and log data, timestamps, and usage patterns (including infrastructure and security logs). When you sign in, we also use cookies and similar technologies needed for authentication, as described in Cookies and similar technologies.
e. Support and communications
If you contact us, we collect the information you provide in that message. We may also send you service-related communications when needed (for example, about security or a request you made).
f. Payments
The Service does not currently collect payment card data or purchase history. There is no in-app checkout. If we later offer optional paid features, we will update this Privacy Policy and describe any payment provider we use before those features are offered.
2. How we use information
We use the information we collect to operate, maintain, and improve the Service. This includes:
- letting you format letter content and export PDFs in your browser;
- providing optional browser keep-a-copy behavior when you turn it on (that copy stays in your browser unless you choose to share);
- letting you sign in for optional sharing features;
- creating and storing shareable-link snapshots; applying delayed viewing; checking that an intended recipient may open shared content; recording opens; and deleting shared content under our retention rules;
- applying usage limits (such as how many shareable links you may create over a period of time); and
- responding to support requests you send us.
We also use information to detect, prevent, and respond to fraud, abuse, and security incidents (including issues related to third-party sign-in); to communicate with you about the Service when needed (such as security or support-related messages); and to comply with applicable law and enforce our Terms of Service and this Privacy Policy.
Where the General Data Protection Regulation (“GDPR”) applies to our processing of your personal information, we rely on the following legal bases: performance of a contract (to provide the Service you use), our legitimate interests (such as maintaining security and preventing fraud), and your consent (where required, such as for certain communications).
3. How sharing works
Formatting and PDF export do not require a server-side copy of your letter. Optional sharing does.
When you create a shareable link, we store a snapshot of the letter content and related formatting and associate it with the recipient Gmail you designate and the delivery timing rules of the Service. Lingerlet does not email the link or letter to the recipient for you; you are responsible for sending the link. There is no sender outbox of shared letter bodies. Later edits in your draft editor do not change a link already created.
Shared letter content is not immediately viewable. It becomes viewable to the intended recipient only after a delayed delivery time set when the link is created (generally on the third calendar day after creation, counting the create day as day 1, at a daytime time chosen by the Service using the timezone you provide). Exact timing is approximate and not guaranteed. Before that time, a recipient who opens the link may see when the letter arrives, but not the letter content.
After the content becomes viewable, we delete the shared letter content and the shareable link from our systems about 90 days later. The Service does not provide read receipts, so we do not notify you when a recipient opens your letter. More detail is in our Terms of Service.
4. Sharing and disclosure
We do not sell your personal information. We share information only as described below.
a. Service providers
We share information with trusted third-party service providers that help us operate the Service, including:
- Google, for sign-in (OAuth) and, when we use Google Workspace or Gmail, for communication email such as support or other human correspondence.
- Supabase, for authentication (including Google sign-in session handling) and for hosting and storing shared letter data in our database (for example shareable-link snapshots, recipient matching, delayed viewing, and related metadata).
- AWS, for distributing static website assets (for example via CloudFront) and for legacy hosting, storage, or related infrastructure that may still hold or process older Service data while it exists.
- Resend, for automated email notifications such as service or security alerts when we send them.
- SendMailAs, for forwarding email sent to our support address (such as support@lingerlet.com) to Gmail so we can read and respond to human correspondence.
These providers may process information only as needed to provide services to us, and they have their own terms and privacy policies.
b. Recipients of shared letters
When you create a shareable link (or use another sharing method we offer), you choose to make that letter’s snapshot available to the intended recipient under the Service’s rules. The recipient can view (and may export) that content after sign-in and after delayed viewing, if they are authorized. Lingerlet does not email the link to the recipient for you.
Browser-only drafts (including an optional keep-a-copy in this browser) stay on your device. Other users cannot see them. Creating a shareable link stores a separate snapshot on our servers for the intended recipient; it does not give other people access to the draft still sitting in your browser.
c. Legal, safety, and fraud
We may disclose information if we believe in good faith that disclosure is reasonably necessary to comply with law, regulation, legal process, or governmental request; to enforce our Terms of Service or this Privacy Policy; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Lingerlet, our users, or the public.
d. Transfers of the project
If Lingerlet is transferred (for example, if the project is sold, assigned, or otherwise transferred to another operator), your information may be transferred as part of that change, subject to applicable privacy protections.
e. What we do not do
We do not sell personal information for advertising. We do not use letter bodies to create or deliver advertising.
5. Data retention and deletion
We retain personal information as needed to provide the Service and for the periods described below, unless a shorter or longer period is required by law. Formatting and PDF export that never leave your browser do not create a server-side letter we can retain or delete for you.
| Situation | Retention |
|---|---|
| Browser-only draft (including optional keep-a-copy in this browser) | Stored on your device/browser profile under your control. Turning the feature off, clearing site data, or otherwise deleting browser storage may remove it. Lingerlet does not keep a separate server copy of that draft unless you create a shareable link. |
| Shareable link before it becomes viewable | Retained on our servers from creation until the delayed delivery time (and afterward under the row below), so we can show arrival timing and then the letter content to the intended recipient. |
| Shared letter content after it becomes viewable | Deleted from our systems about 90 days after the delivery time (when the content becomes viewable), together with the shareable link, as described in How sharing works and our Terms of Service. |
| Sign-in / authentication records | Handled with our authentication provider (currently Supabase Auth / Google). Session cookies on your device last according to that sign-in flow; signing out ends the session on that device but does not by itself delete shared letter content from our servers. |
| Technical and security logs (IP address, device/browser info, infrastructure logs) | Retained up to about 90 days after collection, then deleted or de-identified so they are no longer reasonably associated with you. |
| Support messages you send us | Retained as long as needed to handle your request and for related security or legal purposes, then deleted or de-identified. |
| Legacy data on older infrastructure | If older Service data still exists on legacy systems (for example AWS), it is retained only as needed while that data exists and is then deleted or de-identified consistent with this Policy and applicable law. |
The Service does not currently offer in-app account deletion. Shared letter content is removed under the about-90-day rule above (or earlier if we remove it for a reason permitted by our Terms of Service, such as a prohibited-use violation). If you need help with access or a deletion request, contact us at the address in Contact us; we may require verification before acting.
We do not keep a separate archive of deleted shared letters for ordinary product use. In limited cases we may retain copies where required for legal, security, or similar legitimate purposes, as described in our Terms of Service.
6. Data export
Lingerlet holds relatively little personal information. For many people who only format and export a PDF without signing in or sharing, we may hold no letter content on our servers at all.
The Service does not currently offer a bulk in-app export of every record tied to a sign-in. In ordinary use, you get a local copy of letter content by:
- Exporting a PDF while drafting (in your browser, without signing in); or
- Exporting a PDF from a shareable link after the letter is viewable and you are signed in as the intended recipient.
Those PDFs are the main way to keep the letter. Creators do not get an outbox of shared letter bodies. After a shared letter is deleted under our retention rules (about 90 days after it becomes viewable), it is no longer available from the link.
What we may still hold on our side is limited — for example sign-in identifiers from Google/Supabase when you use sharing, a recipient Gmail and timezone you provided when creating a link, shared letter snapshots until they are deleted, open-related metadata, support emails you send us, and short-lived technical logs. If you need help accessing or deleting that kind of information, email us at the address in Contact us. We may require verification so we do not send information to the wrong person.
7. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or otherwise control certain personal information. Because Lingerlet holds relatively little personal information, many everyday choices happen in the product or in your browser rather than through a large account settings surface. For example:
- Access / export — export a letter PDF while drafting, or from a viewable shareable link if you are the intended recipient (see Data export). For other personal information we may hold (such as sign-in identifiers or sharing metadata), email us at the address in Contact us.
- Correct or update — primary email and Google sign-in identity are generally updated with Google (or your other sign-in provider), not inside Lingerlet. When creating a shareable link, you choose the recipient local part and timezone at create time; a snapshot already created is not freely editable afterward. You can change or clear an optional keep-a-copy draft in your own browser.
- Delete — there is no in-app account deletion. Shared letter content is deleted about 90 days after it becomes viewable (see Data retention and deletion). You can remove browser-only drafts by turning off keep-a-copy or clearing site data. You may also request deletion of personal information we hold by emailing us; we may require verification before acting.
- Sign out — you can sign out to end your session on that device. Signing out does not by itself delete shared letter content from our servers.
- Cookies / browser controls — we use cookies needed for sign-in and session when you use sharing features. You can clear or block cookies in your browser; doing so may prevent sign-in or use of sharing features. Formatting and PDF export without sign-in do not require those auth cookies.
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (“CCPA”) / California Privacy Rights Act (“CPRA”), such as the right to know, delete, and correct personal information, subject to applicable exceptions. We will not discriminate against you for exercising your privacy rights under California law.
Depending on your location, you may have additional rights under other applicable privacy laws. You may exercise applicable rights through the Service where available, or by emailing us (see Contact us). Some features require certain data to function.
8. Data security
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, loss, misuse, or alteration. However, no system is completely secure, and we cannot guarantee absolute security.
The Service is not a backup or archival service. Do not rely on Lingerlet as your only copy of important letters or other content. Shared letter content is deleted about 90 days after it becomes viewable; browser-only drafts can be lost if you clear storage or change devices; and content can become unavailable through technical failure or events beyond our reasonable control. Keep your own copies of anything important — for example by exporting a PDF while drafting or from a viewable shareable link (see Data export). See also our Terms of Service.
9. International data transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers (such as Supabase, AWS, Google, Resend, or SendMailAs) operate.
Where required, we rely on appropriate safeguards for these transfers, including standard contractual clauses and other contractual protections offered by our service providers.
10. Children's privacy
The Service is not intended for individuals under the age of 17 (or the higher minimum age required in your jurisdiction, if any), consistent with our Terms of Service. We do not knowingly collect personal information from anyone under 17.
If we learn that we have collected personal information from a child under 17, we will delete that information and related Service data (including shared letter content tied to that use, where reasonably practicable) as soon as we reasonably can. If you believe a child under 17 has provided us personal information, please contact us.
11. Cookies and similar technologies
We use cookies and similar technologies as needed to operate the Service. When you sign in for optional sharing features, this includes cookies that authenticate you and keep you signed in (such as session cookies used for access and refresh tokens) and temporary cookies that support sign-in flows.
Formatting letter content and exporting a PDF without signing in do not require those authentication cookies.
We do not currently use third-party analytics cookies. You can control or delete cookies through your browser settings. Blocking or clearing authentication cookies may prevent you from signing in or using sharing features.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. We will post the revised Privacy Policy and update the Last Updated date. Continued use of the Service after a posted change constitutes acceptance of the updated Privacy Policy. If we make material changes, we may provide additional notice when reasonably practicable (for example, a notice in the Service).
13. Contact us
If you have questions about this Privacy Policy or our data practices, or want to make a privacy-related request (including access or deletion requests), please contact us at:
Zifan Wang (operating Lingerlet)
Email: support@lingerlet.com