✦

Privacy Policy

Our Love Letters — wrcxsa.com

Last updated: 29 August 2026


What this is

Our Love Letters is a private website used by exactly two people — a couple. It is not a product. There are no public signups, no customers, no ads, no analytics, and no revenue. Two accounts exist, they are fixed, and nobody else can register.

This policy is written plainly because the honest version is short. If something here is unclear, email me and I will tell you exactly what the app does.

What the app stores

That is the whole list. There is no tracking, no profiling, no behavioural logging, and no third-party analytics anywhere in the app.

Where it is stored, and who can see it

Everything lives in Supabase (Postgres and Storage, hosted on AWS). The site itself is static and hosted on Vercel.

Letters and photos are visible only to the two signed-in accounts. Database access is restricted by Postgres row-level security, so an anonymous key on its own grants nothing. Images sit in a private storage bucket and are served through short-lived signed URLs rather than public links.

Nobody else is given access to the contents. Supabase and Vercel, as the companies operating the infrastructure, technically hold the data on their servers — that is unavoidable for any hosted app, and it is worth being straight about.

Google user data

The app connects to the owner's own Google account (wrezachow@gmail.com). No one else signs in with Google, and the app never requests access to anyone else's Google account.

It uses exactly two scopes:

The Google refresh token is stored as an encrypted secret in Supabase Edge Functions. It is never sent to the browser and is never exposed in client-side code. It is used only for the two operations above.

Data obtained through these Google APIs is not used for advertising, is not sold, is not transferred to anyone else, is not used to train any AI or machine-learning model, and is not read by a human.

Limited Use disclosure. Our Love Letters' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

The photobooth

The photobooth opens a live video connection directly between the two partners' devices using WebRTC, so we can take a photo strip together. The video stream is peer-to-peer and is never recorded or stored by the app. Only the finished, composited photo strip is saved, and only when someone chooses to save it. The connection setup messages (signaling) pass through Supabase Realtime.

Third parties

These services necessarily see something:

No data is sold or shared with anyone beyond what those services require to work.

Retention and deletion

Data stays until it is deleted. Nothing expires on its own.

Either person can delete their own letters inside the app, which also removes the images attached to them from storage. To delete an account entirely, or to get a copy of what is stored, email me and I will do it by hand.

Security, honestly

What actually protects this data: row-level security policies in Postgres, a private storage bucket reached only through short-lived signed URLs, password hashing handled by Supabase Auth, encrypted server-side storage for the Google refresh token, and ordinary HTTPS transport encryption.

What does not exist, and I am not going to pretend otherwise: end-to-end encryption, a SOC 2 audit, a formal GDPR compliance programme, a security team, or an incident response process. This is a personal project maintained by one person. The data is protected reasonably well for what it is, and if something went wrong the two people affected would find out directly from me.

Changes

If the app changes in a way that affects any of this, I will update this page and the date at the top.

Contact

Questions about anything here, or requests for access or deletion: wrezachow@gmail.com.