Privacy Policy
Last updated July 2, 2026.
What we collect
We collect your email address (used to sign you in with a one-time code), the return address you save, the letters you draft and their recipients, the text and details we extract from any files you upload for context (uploaded files are screened for malicious content and then read in memory to extract their text; the files themselves are not stored, but the extracted text becomes part of your letter content and follows the same retention period), and payment receipt details (card brand, last four digits, billing address) from our payment processor. To enforce our US-only availability and help prevent fraud and abuse, we also use your device's IP address to estimate your country (approximate location only — never precise GPS).
How we use it
We use your information to draft, verify addresses for, print, and mail your letters, to take payment, to keep a receipt of your orders, and — only if you opt in — to send occasional product updates. You can change your newsletter preference any time on your account page. We also process your letters and account activity to screen for prohibited content and to detect tampering, fraud, and abuse, which lets us refuse or cancel anything that violates our Terms.
Letter and conversation retention
We retain the content of your letters, your conversation with Genie, and any text extracted from uploaded files, encrypted in transit and at rest, for safety and security — to detect and prevent fraud and abuse, support investigations, protect you and us in the event of a dispute or legal claim, and meet legal obligations — generally for up to 6 years from the date of the transaction (the date you pay and submit the letter for mailing) or the release of any legal hold, after which it is deleted. We also keep an order receipt (order number, addresses, tracking, and payment summary) so you have a record of what was sent. Files you upload for context are not stored as files — they are read in memory to extract text, which becomes part of your letter’s content and follows the same 6-year retention. We try our best to detect and remove sensitive personal information — such as a full payment card number or a Social Security / government ID number — from a letter before we archive it, masking it (keeping only the last four digits) in the copy we retain, so full sensitive numbers are not stored. This detection is automated and best effort, so we can’t guarantee it catches every instance — please avoid including such sensitive numbers in your letter unless they are necessary. Where the law requires it (for example, an active investigation, legal request, subpoena, or other legal obligation), we may retain relevant information longer, until the matter is resolved. We keep only what is necessary, limit access to this information, and never sell your data.
AI processing of your conversation and draft
To understand what you want to send and to draft your letter, your conversation with Genie and the draft are processed by U.S.-based third-party AI providers, reached through an AI gateway. Images you upload for context are sent to our AI provider to extract their text. The providers do not use your chat inputs or outputs to train their models. We do not enable any optional prompt-logging or model-training features, and we pin zero-data-retention routing so the underlying provider does not retain your prompts or the model’s output. Our own copy of the conversation and draft is encrypted and retained for safety and security as described under “Letter and conversation retention” above.
Voice input (dictation)
If you dictate text instead of typing, the speech-to-text conversion is handled by your device or browser’s built-in speech-recognition feature — not by PostalGenie. We do not record, collect, store, or transmit your voice or audio; only the resulting text you choose to submit reaches us. Your browser, device, or operating system (and its provider, such as the maker of your browser) may process the audio under its own privacy policy, over which we have no control. To avoid this, simply type your text instead.
Service providers
We share data with providers strictly to run the service: U.S.-based AI providers (accessed through an AI gateway) to draft and review letters, address lookup and verification providers to find and validate mailing addresses, a print-and-mail provider to post your mail, a payment processor, an email provider to send sign-in codes, an error-monitoring provider that receives technical diagnostics (scrubbed of letter content and personal information), and a customer-support chat provider (used only if you start a support conversation; support communications are retained only as long as needed for support, security, legal claims, or legal compliance). They may only use the data to perform their service for us.
Additional recipients. We also share data with a sanctions and denied-party screening service (using U.S. government data via trade.gov) — we send sender and recipient names to comply with U.S. sanctions and export-control laws; a fraud-prevention service (proxycheck.io) — we send your IP address at sign-up to detect VPN/proxy or datacenter connections; and an analytics / business-intelligence service (Grafana Cloud) that accesses de-identified usage metadata (account status, timestamps, amounts, audit events, and a PII-free one-sentence summary) — never decrypted letter content.
Analytics. We use a privacy-friendly, cookieless web analytics service to understand aggregate, anonymous usage (such as page views and referrers). It does not use cookies, does not track you across other sites, and does not collect personally identifying information.
Cookies. We use a small number of strictly necessary cookies to keep you signed in and to operate the Service securely (for example, your authentication session). We do not use advertising or cross-site tracking cookies, and our analytics is cookieless (above). Because the cookies we set are essential to providing the Service, they are not used to track you.
Data security
We use reasonable administrative, technical, and organizational measures to protect your information — including encryption in transit and at rest, access controls that limit who can view your data, and retention and deletion governed by the timeframes described under “Letter and conversation retention” above. Access to encrypted letter and conversation content is limited to a small number of authorized personnel, who may decrypt and review it only when necessary to investigate fraud, abuse, or safety issues, to comply with law, or to respond to your requests — and each such access is logged. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to safeguard your data and to limit how long we keep it. In the event of a data breach that compromises your personal information, we will notify you and applicable regulators as required by applicable law.
We don’t sell your data
We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising. We share data only with the service providers described above, strictly to operate the Service. Wherever you live in the United States, you may ask us to tell you what personal information we hold about you, to correct it, or to delete it, and we will not discriminate against you for exercising these rights. Email us to make a request.
State privacy rights. Depending on your state of residence (including California residents under the CCPA/CPRA), you may have the right to know the categories and specific pieces of personal information we collect and how we use and disclose it, to access a copy of it, to delete it, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not “sell” or “share” your personal information as those terms are defined under applicable state privacy laws, and we have not done so in the past 12 months. We will continue to monitor the expansion of state consumer privacy laws as our service grows nationwide.
Categories of personal information we collect. In the past 12 months we have collected: identifiers (email address, IP address, return and recipient mailing addresses); commercial information (order and payment-receipt details — card brand, last four digits, billing address); internet or network activity (basic, aggregate usage); approximate geolocation (country level, derived from IP — never precise GPS); and the contents of the letters and conversations you create, which may contain whatever personal information you choose to include. We collect this from you directly and from our service providers (for example, our address-verification and payment providers). We use it for the business purposes described under “How we use it,” and we disclose it only to the service providers listed above so they can perform services for us.
Sensitive personal information. A letter you write could contain sensitive personal information (such as a financial-account or government-ID number). We use any such information only as needed to provide the Service (to render and mail your letter) and to retain a masked copy for safety and security — never to infer characteristics about you — so the CCPA right to limit the use of sensitive personal information does not apply to that limited use. As described above, we try to detect and mask such numbers in the copy we retain.
How to exercise your rights. To make a request to know, access, correct, or delete, email support@postalgenie.app. We verify your request by matching the email address associated with your account, and may ask for additional information to confirm your identity. You may use an authorized agent to submit a request on your behalf, with proof of authorization. We aim to respond within 45 days and will tell you if we need more time, as the law allows. We may decline to delete personal information that we are required to retain to exercise or defend against potential legal claims, to detect security incidents, or to comply with legal obligations. We will not deny you service or charge you a different price for exercising these rights.
Your choices
You can update your email and return address, opt out of product updates, and request deletion of your account at any time. To request deletion of your personal information, email support@postalgenie.app with the subject “Personal Data Deletion Request.” Audit records contain metadata only (never letter body text).
Children’s privacy
The Service is intended only for adults aged 18 and older located in the United States. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete it. If you believe a child has provided us information, please contact us at support@postalgenie.app and include the email and physical mailing addresses of the people involved so we can locate and delete it.
Where your data is handled
The Service is operated in, and intended for users located in, the United States. We do not offer the Service to users outside the United States.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, provide additional notice. Continued use of the Service after a change means you accept the updated policy.
Contact
Privacy questions? Email support@postalgenie.app.