Privacy Policy

Last updated: [DATE] · [LEGAL ENTITY] (“SayWhat!”).

Template — not legal advice. Review with counsel and adapt for GDPR/CCPA and your jurisdiction before launch. Fill in bracketed placeholders and your data-processor list.

Our stance: minimal data

SayWhat! is built to collect as little as possible. There are no user accounts. We do not sell personal data.

What we collect

Cookies

We use essential cookies only: a signed verification/session token, an anonymous reaction token (so a like isn't double-counted), and view de-duplication. These are functional, not advertising cookies. [If you add analytics, disclose and gate it behind consent.]

Service providers

We share data with processors that run the service: [Supabase] (database, storage, auth), [Resend] (email), [Inngest] (background jobs), [Upstash] (rate limiting), and [Anthropic] (content classification). Each processes data only to provide their function.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your data (GDPR/CCPA). To exercise them, or to request deletion of a letter tied to your email, contact [PRIVACY CONTACT EMAIL]. Recipients seeking removal should use the takedown process.

Retention

Published letters remain until removed by you, by a successful takedown, or by moderation. Moderation and takedown actions are logged for accountability.

Contact

Privacy questions: [PRIVACY CONTACT EMAIL].