Legal
Privacy Policy
Last updated: 1 October 2026
toiyp is built on the principle that your correspondence is private. We collect only what we need to run the service, and we never sell your data.
1. Who we are
toiyp (“we”, “us”) is an independent correspondence service accessible at toiyp.me. For data protection enquiries, contact us at [email protected].
2. What we collect and why
- Account information — your email address and display name, used to create and identify your account.
- Your @handle — the correspondence address you choose, visible to people you correspond with.
- Letter content — the text of letters you write and receive. This is the core of the service. Letters are private between the two parties in a correspondence.
- Metadata — timestamps (when letters were sent, delivered, opened), delivery state, and read counts. Used to operate the letter transit mechanic.
- Relationship data — the connection between two accounts that have exchanged letters.
We do not collect your phone number, location, device identifiers, or browsing history.
3. Cookies and session data
We use a single HTTP-only session cookie, set when you sign in to the app at app.toiyp.me. This cookie is strictly necessary for authentication — without it the app cannot function. It is not used for tracking or advertising, and it expires after 30 days or when you sign out.
This landing page (toiyp.me) sets no cookies of its own. Google Fonts is used for typography; Google’s own privacy policy applies to that request, though no cookies are set by the Fonts API.
4. How we use your data
- To deliver letters between correspondents at the scheduled time.
- To show you your inbox and outbox.
- To authenticate you when you sign in.
- To send transactional emails (password reset, delivery notifications) if enabled.
We do not use your data for advertising, profiling, or any automated decision-making that affects you.
5. Data retention
- Active account — your data is retained for as long as your account exists.
- Letters — retained indefinitely as part of your correspondence history, unless you request deletion.
- Deleted accounts — on account deletion, your profile and letters are permanently removed within 30 days.
- Session data — session tokens are deleted when you sign out or after 30 days of inactivity.
6. Sharing your data
We do not sell, rent, or share your personal data with third parties for their own purposes. Letter content is visible only to the two parties in a correspondence. We use the following service providers, each bound by data processing agreements:
- Railway — infrastructure hosting (EU/US regions).
- Cloudflare — DNS, CDN, and Pages hosting.
- OpenAI — optional tone analysis on letter drafts (letter text is sent to the API for analysis; it is not used to train OpenAI models under our API agreement).
7. Your rights
If you are in the UK or European Economic Area, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Erasure — ask us to delete your account and all associated data.
- Portability — receive your data in a structured, machine-readable format.
- Rectification — ask us to correct inaccurate personal data.
- Objection — object to processing where our legal basis is legitimate interest.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Security
All data is transmitted over HTTPS. Session tokens are stored in HTTP-only cookies inaccessible to JavaScript. Letter bodies are stored encrypted at rest. We follow security best practices and will notify you promptly in the event of a breach that affects your personal data.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to registered users. The “last updated” date at the top of this page reflects the most recent revision.
10. Contact
Questions or concerns about this policy? Email us at [email protected].