Postmello
← Home

Privacy Policy

Last updated: September 29, 2026

Postmello (“we,” “us,” “our”) makes a cozy iPhone and iPad app for writing and exchanging digital letters with a small circle of approved contacts. We care deeply about privacy - especially because families and children use Postmello. This policy explains what we collect, why, and the choices you have.

Who we are. Postmello is operated by Postmello LLC, based in Palo Alto, California, USA. You can reach us at [email protected].

Where your data is stored. Your account, letters, and images are stored on servers in the United States (Amazon Web Services, US West / Northern California), operated on our behalf by Supabase. If you use Postmello from outside the United States, your information is transferred to and processed in the United States.

The short version

Information we collect

Sign in with Apple and Sign in with Google are available only to adult Postmello account owners. They are used to create or authenticate the adult's Postmello account, not an individual desk, and children do not sign in with Google or Apple. Both options are also optional - an adult can use an email address and password instead. The information we receive this way (the account identifier and, depending on your choices, a name or email address) is used for the adult's account: to create it, sign in to it, and keep it secure. Signing in with Google or Apple does not give that provider a child's Postmello desk identity, letters, drawings, contacts, or profile information. Postmello's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How we use information

We use diagnostic and analytics information only to understand reliability, to see where and on which devices Postmello is used, and to improve it. We do not use it to advertise to you or to build marketing profiles, and we do not sell it.

Children’s privacy

Children do not create Postmello accounts. A child uses a desk within an account created and managed by an adult, with the additional protections described here. The adult account owner creates the account, approves every contact, and can review or remove content and connections at any time. By design, a child can only exchange letters with contacts the account owner has approved - unapproved mail, incoming or outgoing, is not possible.

We do not knowingly use children’s personal information for advertising or sell it.

How parental consent works

When an adult creates a desk for a child under 16, Postmello requires parental consent and adult verification before that desk can communicate with other people: until both are complete it cannot send or receive letters or transmit anything the child creates. For a child under 13 in the United States, that is how we obtain verifiable parental consent under the US Children’s Online Privacy Protection Act (COPPA). We ask at 16 everywhere because the age at which a child’s own consent counts differs by country - 13 in the United States and the United Kingdom, 14 in Quebec, and up to 16 in the European Union - and one age that covers every one of them is clearer than a different rule for each. Verification is a safeguard applied to that particular kind of desk, not a step every desk goes through. There is a plain-language walkthrough on the Parent Privacy Notice.

  1. An adult creates the account and signs in with an email address and password, Sign in with Apple, or Sign in with Google.
  2. That adult sets an Admin PIN, which protects the admin area.
  3. The adult creates each desk, and we ask whether it is for a child under 16 so that we can apply the appropriate parental-consent protections. We store that answer and nothing more - we never ask a child for a birth date or exact age, and we never ask the adult for the child’s birthday either.
  4. For a child’s desk, the adult reads and approves our parental consent statement, and then confirms they are an adult through Kids Web Services, a verification service run by Epic Games. No identity document, card number, Social Security number or selfie ever reaches Postmello - that happens with the verification provider, and we receive only the fact that an adult was verified.
  5. Until both the approval and the verification are recorded on our servers, the desk cannot send, cannot receive, and nothing written on it leaves the device. This is enforced by our database, not by the app.
  6. An adult verifies once. Setting up a desk for another child later asks for approval again, but not for another verification.
  7. Every contact is approved by the adult, in the admin area, behind that PIN.
  8. Mail between people who are not approved contacts is refused by our servers - it is not merely hidden in the app, it cannot be sent or received at all.

We do not knowingly allow a child to create an account, and we never ask a child for a birthday, a phone number, or a location.

Desks that are not for a child under 16 - the account owner’s own desk, a grandparent’s - do not go through verification.

Rights of the parent or guardian

As the account holder you can, at any time and from inside the app: review the contacts approved for any desk and remove any of them; review and remove desks; and delete the account and its data outright (Settings → Delete Account), which also stops any further collection. You do not need to send us a written request to do any of these. If you would rather we help, or you want to review information associated with your account, contact us at [email protected].

Postmello contains no third-party advertising and no tracking SDKs. The only third-party component in the app that receives any data is Sentry, which receives crash reports, performance timings, and limited breadcrumbs describing what was happening in the app when a problem occurred. We use it to diagnose problems and to decide what to improve. It never receives your letters, drawings, names or contact labels. We do not use it to build profiles, and we do not sell or share this data or use it for advertising.

This website. postmello.com is served by Cloudflare, and we use Cloudflare Web Analytics to see which pages are read. Each page also reports, anonymously, which of its sections came into view, roughly how long it stayed open, and which links or buttons were tapped, so we can tell what helps. The website sets no cookies, builds no profile, and does not follow anyone between sites or sessions. Nothing a child creates in the app passes through this website, and no child signs in here.

How information is shared

We do not sell your personal information. We share information only in these limited ways:

The service providers we currently use are:

Letters exchanged with a friend by email

Most Postmello contacts are other Postmello desks, and those letters never leave the app. An adult can also approve an email address for a desk, whether or not that person also uses Postmello. That friend can receive letters by email and write to the desk from that approved address. Because mail then leaves and enters the service by email, here is exactly what happens.

When a letter is sent to a friend reached by email:

When that friend replies:

Data retention and deletion

We keep your information for as long as your account is active or as needed to provide the service.

How long we keep letters and drawings. Handwritten letters and their images are kept for as long as the account is active, because rereading old mail is the point of the product - a letter you were sent last year should still be there. We do not delete them on a schedule, we do not use them to train anything, and we do not show them to anyone outside the approved audience of that letter. You can remove letters from inside the app at any time, and deleting the account removes them as described below.

You can delete your account from inside the app, at any time: open the admin area, go to Settings, and choose Delete Account. The account is then scheduled for deletion 30 days later. During those 30 days its desks stop receiving mail and any sharing links are revoked straight away, and you can change your mind: sign back in, open the admin area, go to Settings, and choose Keep My Account. After 30 days the account and its data - desks, contacts, drafts, and the letters and images stored for them - are removed from our database and file storage, subject to any limited records we must keep for legal or security reasons, and to routine backups that are overwritten in time.

Letters you have already sent are not deleted from the people who received them. A delivered letter is part of the recipient's own mailbox, in the same way a posted letter belongs to the person who receives it, and we do not reach into someone else's account to remove it. Your desk, your profile and your account are still deleted.

Deleting your account does not cancel a paid subscription. Subscriptions are billed by the App Store, and only the App Store can cancel one - see Manage Subscriptions in your device settings.

Security

We use industry-standard measures to protect your information in transit and at rest. Letters are stored so they can be delivered to your approved contacts. No system is perfectly secure, but we work to safeguard your data and to limit access to it.

Your choices and rights

You can delete your account and its data yourself, from inside the app - see "Data retention and deletion" above.

Wherever you live, you can ask us for a copy of the personal information we hold about your account, ask us to correct it, ask us to delete it, or object to how we use it, by writing to [email protected]. We answer within a month and never charge for it. If you are in the United Kingdom, the European Union, Canada, Australia, New Zealand or another place whose law gives you these rights, that law applies to you and nothing here reduces it. You can also complain to your data-protection authority - in the United Kingdom that is the Information Commissioner’s Office, and in the European Union it is the authority in your country.

Why we process your information. For an adult’s account, we process information because it is needed to provide the service you asked for, and to keep that service secure and free of abuse. The country and device type recorded at sign-in rest instead on our legitimate interest in knowing, in aggregate, where Postmello is used and on what. For a desk marked as a child’s, the basis is the consent of that child’s parent or guardian, given and verified as described under “How parental consent works”; that consent can be withdrawn at any time by removing the desk or deleting the account. We collect no more than we need, and we use nothing for advertising.

International transfers. Postmello LLC is in the United States and your information is stored there, as described at the top of this policy. When you use Postmello from outside the United States, that transfer is necessary to provide the service you asked for. Our service providers hold contractual data-protection commitments with us, and Amazon Web Services, which stores the data, is certified under the EU-US Data Privacy Framework and its UK extension. Postmello LLC is not itself certified under that framework.

Changes to this policy

We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, provide additional notice.

Contact us

Questions about privacy? Email [email protected].