Privacy Policy
Last updated: [DATE] · [LEGAL ENTITY] (“SayWhat!”).
Template — not legal advice. Review with counsel and adapt for GDPR/CCPA and your jurisdiction before launch. Fill in bracketed placeholders and your data-processor list.
Our stance: minimal data
SayWhat! is built to collect as little as possible. There are no user accounts. We do not sell personal data.
What we collect
- Your email — used only to verify you before a letter publishes and to send milestone notifications you can unsubscribe from. It is never shown publicly.
- Your pen name and letter content — published publicly by design.
- An optional image you attach to a letter.
- Limited technical data — e.g. an anonymised token and IP-derived signals used for rate limiting and abuse prevention.
Cookies
We use essential cookies only: a signed verification/session token, an anonymous reaction token (so a like isn't double-counted), and view de-duplication. These are functional, not advertising cookies. [If you add analytics, disclose and gate it behind consent.]
Service providers
We share data with processors that run the service: [Supabase] (database, storage, auth), [Resend] (email), [Inngest] (background jobs), [Upstash] (rate limiting), and [Anthropic] (content classification). Each processes data only to provide their function.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your data (GDPR/CCPA). To exercise them, or to request deletion of a letter tied to your email, contact [PRIVACY CONTACT EMAIL]. Recipients seeking removal should use the takedown process.
Retention
Published letters remain until removed by you, by a successful takedown, or by moderation. Moderation and takedown actions are logged for accountability.
Contact
Privacy questions: [PRIVACY CONTACT EMAIL].