Privacy Policy
Last updated: September 29, 2026
Postmello (“we,” “us,” “our”) makes a cozy iPhone and iPad app for writing and exchanging digital letters with a small circle of approved contacts. We care deeply about privacy - especially because families and children use Postmello. This policy explains what we collect, why, and the choices you have.
Who we are. Postmello is operated by Postmello LLC, based in Palo Alto, California, USA. You can reach us at [email protected].
Where your data is stored. Your account, letters, and images are stored on servers in the United States (Amazon Web Services, US West / Northern California), operated on our behalf by Supabase. If you use Postmello from outside the United States, your information is transferred to and processed in the United States.
The short version
- Postmello accounts are created and managed by adults. An account can include desks for adults or children in the household - each person writes from a desk of their own.
- Children do not create accounts of their own; a child uses a desk within an adult-managed account, and the adult account owner approves every contact.
- We collect what’s needed to deliver letters and keep accounts secure, and a little about how and where Postmello is used.
- We do not sell your information, show third-party ads, or use your letters to build advertising profiles.
- Letters only travel between approved contacts - never to or from anyone else.
Information we collect
- Account information. When an account owner signs up, we collect an email address and authentication details. If you choose Sign in with Apple or Sign in with Google, we receive the account identifier (and, depending on your choices, a name or email) from that service to create your account.
- Profile and desk details. Display names, nicknames, icons, and contact labels you create for desks and mailboxes inside the app.
- Letter content. The handwritten letters, drawings, and stationery you create, and the records needed to deliver them to your approved contacts.
- Contacts. The approved connections that determine who may exchange letters with whom.
- Diagnostic information. Limited technical and usage information - app version, error reports, performance timings, and which parts of the app were in use when a problem occurred - that helps us keep Postmello reliable and decide what to improve.
- Country and device type. When an account owner signs in, the app records on that account the country the device is set to (from its region setting - not a location reading) and whether it is an iPhone, an iPad or a Mac. Each is recorded once and never updated, and only when the account owner signs in - never while a child is using a desk. For a few accounts created in late September 2026, the country was instead estimated from the internet connection when the first desk was set up. We do not keep your IP address for this.
- Purchases. Records of the collections and memberships bought for your account through the App Store, so we know what your account has access to. Payment details go to Apple and never reach us.
Sign in with Apple and Sign in with Google are available only to adult Postmello account owners. They are used to create or authenticate the adult's Postmello account, not an individual desk, and children do not sign in with Google or Apple. Both options are also optional - an adult can use an email address and password instead. The information we receive this way (the account identifier and, depending on your choices, a name or email address) is used for the adult's account: to create it, sign in to it, and keep it secure. Signing in with Google or Apple does not give that provider a child's Postmello desk identity, letters, drawings, contacts, or profile information. Postmello's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
How we use information
- To operate the service - storing your letters and delivering them between approved contacts.
- To create and secure accounts and to verify approved connections.
- To provide customer support and respond to your requests.
- To diagnose problems, prevent abuse, and improve the app.
- To understand, in aggregate, where Postmello is used and on which devices.
We use diagnostic and analytics information only to understand reliability, to see where and on which devices Postmello is used, and to improve it. We do not use it to advertise to you or to build marketing profiles, and we do not sell it.
Children’s privacy
Children do not create Postmello accounts. A child uses a desk within an account created and managed by an adult, with the additional protections described here. The adult account owner creates the account, approves every contact, and can review or remove content and connections at any time. By design, a child can only exchange letters with contacts the account owner has approved - unapproved mail, incoming or outgoing, is not possible.
We do not knowingly use children’s personal information for advertising or sell it.
How parental consent works
When an adult creates a desk for a child under 16, Postmello requires parental consent and adult verification before that desk can communicate with other people: until both are complete it cannot send or receive letters or transmit anything the child creates. For a child under 13 in the United States, that is how we obtain verifiable parental consent under the US Children’s Online Privacy Protection Act (COPPA). We ask at 16 everywhere because the age at which a child’s own consent counts differs by country - 13 in the United States and the United Kingdom, 14 in Quebec, and up to 16 in the European Union - and one age that covers every one of them is clearer than a different rule for each. Verification is a safeguard applied to that particular kind of desk, not a step every desk goes through. There is a plain-language walkthrough on the Parent Privacy Notice.
- An adult creates the account and signs in with an email address and password, Sign in with Apple, or Sign in with Google.
- That adult sets an Admin PIN, which protects the admin area.
- The adult creates each desk, and we ask whether it is for a child under 16 so that we can apply the appropriate parental-consent protections. We store that answer and nothing more - we never ask a child for a birth date or exact age, and we never ask the adult for the child’s birthday either.
- For a child’s desk, the adult reads and approves our parental consent statement, and then confirms they are an adult through Kids Web Services, a verification service run by Epic Games. No identity document, card number, Social Security number or selfie ever reaches Postmello - that happens with the verification provider, and we receive only the fact that an adult was verified.
- Until both the approval and the verification are recorded on our servers, the desk cannot send, cannot receive, and nothing written on it leaves the device. This is enforced by our database, not by the app.
- An adult verifies once. Setting up a desk for another child later asks for approval again, but not for another verification.
- Every contact is approved by the adult, in the admin area, behind that PIN.
- Mail between people who are not approved contacts is refused by our servers - it is not merely hidden in the app, it cannot be sent or received at all.
We do not knowingly allow a child to create an account, and we never ask a child for a birthday, a phone number, or a location.
Desks that are not for a child under 16 - the account owner’s own desk, a grandparent’s - do not go through verification.
Rights of the parent or guardian
As the account holder you can, at any time and from inside the app: review the contacts approved for any desk and remove any of them; review and remove desks; and delete the account and its data outright (Settings → Delete Account), which also stops any further collection. You do not need to send us a written request to do any of these. If you would rather we help, or you want to review information associated with your account, contact us at [email protected].
Postmello contains no third-party advertising and no tracking SDKs. The only third-party component in the app that receives any data is Sentry, which receives crash reports, performance timings, and limited breadcrumbs describing what was happening in the app when a problem occurred. We use it to diagnose problems and to decide what to improve. It never receives your letters, drawings, names or contact labels. We do not use it to build profiles, and we do not sell or share this data or use it for advertising.
This website. postmello.com is served by Cloudflare, and we use Cloudflare Web Analytics to see which pages are read. Each page also reports, anonymously, which of its sections came into view, roughly how long it stayed open, and which links or buttons were tapped, so we can tell what helps. The website sets no cookies, builds no profile, and does not follow anyone between sites or sessions. Nothing a child creates in the app passes through this website, and no child signs in here.
How information is shared
We do not sell your personal information. We share information only in these limited ways:
- With your approved contacts. A letter you send is delivered to the contact you addressed it to.
- With service providers who help us run Postmello - for example, our cloud hosting, database, storage, and authentication providers - who process data on our behalf under appropriate confidentiality and security obligations.
- For legal reasons, if required by law or to protect the safety of our users and the service.
The service providers we currently use are:
- Supabase - hosting, database, file storage, and authentication (servers in the United States).
- Resend - delivery of account and notification emails, of the App Store link the website emails to someone who asks for it, and of the message that tells a friend reached by email that a letter is waiting for them.
- Postmark - receiving mail from a friend reached by email, so it can arrive on the desk as a letter.
- Sentry - crash and error reporting.
- Apple - app distribution, subscriptions and billing, and Sign in with Apple.
- Google - Sign in with Google, if an adult account owner chooses that option for their own sign-in. Google receives no information about a child’s desk, letters, drawings, or contacts.
- Kids Web Services (Epic Games) - confirming that the adult approving a child’s desk is an adult. They receive the adult’s email address; they receive nothing about the child.
Letters exchanged with a friend by email
Most Postmello contacts are other Postmello desks, and those letters never leave the app. An adult can also approve an email address for a desk, whether or not that person also uses Postmello. That friend can receive letters by email and write to the desk from that approved address. Because mail then leaves and enters the service by email, here is exactly what happens.
When a letter is sent to a friend reached by email:
- The letter itself is not sent by email. The email carries a picture of the envelope - the outside, with its stickers and address - and a private link. The letter is read on a web page opened by that link.
- The link expires after 30 days, and an adult can revoke it sooner from the admin area. Anyone holding the link can open that page, so it is private in the same way a posted letter is: treat it as something not to forward.
- The email also carries a private return address belonging to that one friend and that one desk, so they can write back.
When that friend replies:
- Postmark receives the reply and passes it to us. We keep the reply's text and a few technical details - who it came from, when it arrived, and the result of the checks below. We do not keep the original email message.
- We check the reply really came from the approved address, using the standard anti-spoofing signals that mail providers publish. A reply we cannot confirm is held for an adult to review in the admin area and is never shown to the desk unless that adult delivers it.
- The reply becomes a typewritten letter on the desk. Only the words carry over: web links are replaced with "[link removed]", emoji are left out, and photos and attachments are not delivered at all. A long reply arrives as several letters in a row.
- We email the sender a short confirmation that their letter is on its way, listing anything that changed - so they are never left guessing. It never says whether the letter was read.
- An adult stays in control. A friend reached by email has to be approved by an adult in the admin area, like any other contact, and can be removed at any time.
Data retention and deletion
We keep your information for as long as your account is active or as needed to provide the service.
How long we keep letters and drawings. Handwritten letters and their images are kept for as long as the account is active, because rereading old mail is the point of the product - a letter you were sent last year should still be there. We do not delete them on a schedule, we do not use them to train anything, and we do not show them to anyone outside the approved audience of that letter. You can remove letters from inside the app at any time, and deleting the account removes them as described below.
You can delete your account from inside the app, at any time: open the admin area, go to Settings, and choose Delete Account. The account is then scheduled for deletion 30 days later. During those 30 days its desks stop receiving mail and any sharing links are revoked straight away, and you can change your mind: sign back in, open the admin area, go to Settings, and choose Keep My Account. After 30 days the account and its data - desks, contacts, drafts, and the letters and images stored for them - are removed from our database and file storage, subject to any limited records we must keep for legal or security reasons, and to routine backups that are overwritten in time.
Letters you have already sent are not deleted from the people who received them. A delivered letter is part of the recipient's own mailbox, in the same way a posted letter belongs to the person who receives it, and we do not reach into someone else's account to remove it. Your desk, your profile and your account are still deleted.
Deleting your account does not cancel a paid subscription. Subscriptions are billed by the App Store, and only the App Store can cancel one - see Manage Subscriptions in your device settings.
Security
We use industry-standard measures to protect your information in transit and at rest. Letters are stored so they can be delivered to your approved contacts. No system is perfectly secure, but we work to safeguard your data and to limit access to it.
Your choices and rights
You can delete your account and its data yourself, from inside the app - see "Data retention and deletion" above.
Wherever you live, you can ask us for a copy of the personal information we hold about your account, ask us to correct it, ask us to delete it, or object to how we use it, by writing to [email protected]. We answer within a month and never charge for it. If you are in the United Kingdom, the European Union, Canada, Australia, New Zealand or another place whose law gives you these rights, that law applies to you and nothing here reduces it. You can also complain to your data-protection authority - in the United Kingdom that is the Information Commissioner’s Office, and in the European Union it is the authority in your country.
Why we process your information. For an adult’s account, we process information because it is needed to provide the service you asked for, and to keep that service secure and free of abuse. The country and device type recorded at sign-in rest instead on our legitimate interest in knowing, in aggregate, where Postmello is used and on what. For a desk marked as a child’s, the basis is the consent of that child’s parent or guardian, given and verified as described under “How parental consent works”; that consent can be withdrawn at any time by removing the desk or deleting the account. We collect no more than we need, and we use nothing for advertising.
International transfers. Postmello LLC is in the United States and your information is stored there, as described at the top of this policy. When you use Postmello from outside the United States, that transfer is necessary to provide the service you asked for. Our service providers hold contractual data-protection commitments with us, and Amazon Web Services, which stores the data, is certified under the EU-US Data Privacy Framework and its UK extension. Postmello LLC is not itself certified under that framework.
Changes to this policy
We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, provide additional notice.
