deadletter is an underground postal service. We built it to be the opposite of a surveillance app. This page explains exactly what data the app touches, who can see it, and what we promise we will never do with it.
SHORT VERSION: We collect the minimum we need to make the app work. We do not sell data. We do not run ads. We do not have analytics SDKs that profile you. Direct messages are end-to-end encrypted — we cannot read them. Circle messages are encrypted and locked to their group. You can use the app without giving us your name, email, or phone number.
1. Who runs deadletter
The app is built and operated by Mad Infinitum Labs LLC (“we,” “us”), a California limited liability company based in Sacramento, California. Contact: contact@dead-letter.com.
2. What data we collect
2.1 Account data
- If you tap TUNE IN as a guest — you get an anonymous Firebase user ID. We never see your real name, email, or phone number.
- If you sign in with Apple — we receive your Apple-provided identifier and (optionally) the email or relay address you choose to share.
- If you sign in with Google — we receive your Google-provided identifier, your email address, and your display name.
- If you sign in with an email link — we receive the email address you typed.
- Username — the handle you claim. Public to other users.
2.2 Drops (your messages)
- Open drops — the message text and the GPS coordinates you anchored it to are stored unencrypted in our database. They are visible to other users who physically come within 15 meters of the drop and scan.
- Direct drops (a message addressed to one person) — the message content is end-to-end encrypted using NaCl box (Curve25519 + XSalsa20-Poly1305) before it leaves your device. Only the intended recipient holds the keys to decrypt. We literally cannot read these.
- Circle drops (a message addressed to a private group) — the message content is encrypted before it leaves your device with a key shared by the circle’s members, and is shown only to members of that circle.
- Drop metadata — we store the GPS coordinates of every drop, the time it was created, the recipient type (open / direct / circle), the chosen card style and stamp, the drop’s view count, and (for direct/circle drops only) the recipient’s identifier so we know who can decrypt.
- Location precision for private mail — for direct and circle drops, the coordinates in the publicly queryable record are rounded to roughly 110 meters. The exact anchor point is kept in a gated record that only the author and the intended recipients can read.
- Photo attachments (when you attach one) — uploaded to Firebase Storage. For open drops, stored unencrypted. For direct/circle drops, encrypted client-side before upload.
2.3 Location data
- We use your device’s GPS only when the app is in use, and only to (a) determine if you are within scanning range of a nearby drop, (b) anchor a drop you are creating, or (c) center the radar map.
- We do not store your continuous location history. We only store the GPS coordinates of drops you create.
- We never use background location.
2.4 Notifications
- If you opt in to push notifications, we store a Firebase Cloud Messaging (FCM) device token so we can deliver direct-message and reply alerts. You can revoke this at any time in iOS Settings or in the ME tab.
2.5 Diagnostic data
- We store a views counter on each drop — an integer that goes up when other users open it.
- Cloud Functions log standard server-side errors. These logs do not contain decrypted message content. Logs roll over after 30 days.
- We do not run third-party analytics SDKs. There is no Mixpanel, Amplitude, Segment, Firebase Analytics, Google Analytics, or anything similar in the app.
2.6 Moderation data
- If you tap REPORT on a drop, we store a report record containing the offending drop’s content, the author’s identifier, your identifier, your email if you’re signed in (so we can follow up with you), and a timestamp.
- If you BLOCK another user, we store that user’s identifier in your blocklist so we can filter their drops out of your view.
3. How we use the data
We use the data we collect only to:
- Operate the app (deliver drops to recipients, render the radar map, etc.)
- Send you push notifications you have opted into
- Investigate user reports and respond to your moderation requests, aiming to act on objectionable content within 24 hours
- Detect and prevent abuse (spam, harassment, illegal content)
- Comply with legal obligations
We do not use your data to: profile you for advertising, sell to data brokers, train AI models, score you for credit/insurance/employment, or share with anyone for marketing purposes.
4. Who else can see the data
4.1 Sub-processors we use
To run the app we rely on a small number of vendors. They process data on our behalf under their own contracts and privacy policies:
- Google (Firebase) — Authentication, Firestore database, Cloud Storage, Cloud Functions, Cloud Messaging. Servers are in the United States. Firebase Privacy
- Apple — Sign in with Apple, Push Notification Service. Apple Privacy
- Resend — Transactional email delivery for moderation correspondence only. Resend Privacy
When we add new sub-processors in the future (for example, an AI moderation assistant), we will update this list and notify users in advance for material changes.
4.2 Other deadletter users
- Open drops you create are visible to any user who comes within 15 meters of their location. Treat open drops as public posts.
- Direct drops are visible only to the recipient.
- Circle drops are visible only to circle members.
- Your username is publicly visible on every drop you create.
4.3 Law enforcement and legal process
We will respond to valid legal process (subpoenas, court orders) but we will only produce data that we actually have. We cannot produce decrypted content of direct drops because we do not have the keys.
5. End-to-end encryption
This is the most important section. Every direct drop is encrypted on your device before it is uploaded to our servers, using keys derived from your account’s NaCl key pair. We do not have access to your private key. Circle drops are encrypted on your device before upload with a key shared by the circle’s members. For direct drops this means:
- If our database is compromised, the contents of direct drops remain encrypted gibberish.
- If law enforcement compels us to produce direct drop content, we cannot.
- If you lose access to your account, we cannot recover direct drops on your behalf.
Open drops are not end-to-end encrypted because they are designed to be read by anyone who finds them.
6. How long we keep data
- Drops you create — kept until they expire (some drops are ephemeral with 24-hour or 7-day lifetimes you choose) or until you delete your account.
- Reports — kept for 1 year after resolution, then deleted.
- Server logs — kept for 30 days.
- FCM tokens — kept until you disable notifications or delete your account.
7. Your rights
You can:
- Delete drops from your collection at any time from the FOUND tab. Drops you have left for other people are not individually recallable — they expire at the end of any lifespan you chose, or stay where you left them. Deleting your account erases all of them at once.
- Delete your entire account and all associated data by emailing contact@dead-letter.com. We will complete deletion within 30 days.
- Request a copy of your data — same email. We will provide a JSON export within 30 days.
- Block other users using the in-app BLOCK action.
- Report content using the in-app REPORT action.
- Opt out of push notifications in iOS Settings or via the ME tab toggle.
- Revoke location access in iOS Settings > Privacy & Security > Location Services. The app will lose its ability to find drops near you and to anchor new drops, but other functions continue to work.
If you are in the European Economic Area, the United Kingdom, California, or another jurisdiction with specific privacy rights (GDPR, UK GDPR, CCPA, CPRA, etc.), you have additional rights including the right to object to processing, restrict processing, and lodge a complaint with your local data protection authority. Contact us to exercise any of these rights.
8. Children’s privacy
deadletter is not intended for and may not be used by anyone under the age of 13. If you are between 13 and 16 and located in the European Economic Area, you must have a parent or guardian’s permission to use the app. We do not knowingly collect data from children under 13. If we learn we have collected such data, we will delete it.
9. Security
We protect your data using industry-standard practices:
- All traffic between your device and our servers is encrypted in transit (HTTPS / TLS).
- Direct drops are end-to-end encrypted; circle drops are encrypted before upload (see Section 5).
- Our database is protected by access controls and Firestore security rules. Only Cloud Functions running with admin credentials can perform privileged operations.
- The maintainer’s admin account is the only account with elevated access to the moderation collection.
No system is perfectly secure. If we discover a breach affecting your account, we will notify you within 72 hours of becoming aware of it.
10. International data transfers
Our servers and our sub-processors’ servers are primarily located in the United States. If you use the app from outside the US, your data will be transferred to and processed in the US. By using the app, you consent to this transfer.
11. Changes to this policy
We may update this policy when the app changes. If we make material changes (new data we collect, new sub-processors with sensitive access, changes to how we use your data), we will notify users via in-app notice or email at least 14 days before the change takes effect. Non-material changes (typo fixes, clarifications) we may make without notice. The “Effective” date at the top of this page indicates the most recent version.
12. Contact
Questions? Concerns? Want to delete your account, request your data, or report a privacy issue?
Email contact@dead-letter.com. We’ll respond within 7 days, usually faster.