Privacy Policy
Last updated 29 September 2026
1. Who is responsible
Ripenote (“we”, “us”, “our”) is responsible for this policy. Email contact@ripenote.com, or see the contact page.
2. What we collect: nothing personal
Using Ripenote — writing, sealing, sharing and opening — does not send personal data to us. We have no database, no user accounts and no email list.
3. Your sealed content never reaches us
Encryption happens in your browser. The sealed message, the unlock date, and any names or title you add are placed in the fragment of the link — the part after #. Browsers do not send the fragment to web servers, so when someone opens a capsule link, our server only sees a request for /o. We also send a Referrer-Policy: no-referrer header so links aren't leaked to other sites. Cards, keepsake PDFs and .seal files are generated on your device.
Before opening a capsule, your browser checks a short list of disabled capsules that ships with the app (see Report a link). The check runs on your device; nothing is sent to us.
4. Hosting and request logs
Ripenote is hosted by Vercel. Like any web host, Vercel automatically records basic information about each request — your IP address, user agent, the requested path and query string, and the time — to deliver the site, keep it secure and debug problems. These logs are kept by Vercel under its privacy policy. We don't add any logging of our own, and our code never logs license keys or capsule content.
5. The only other network requests Ripenote makes
a) drand relays (to open capsules and show the clock)
To open a capsule, your browser fetches one public beacon for the capsule's round from a drand relay. The home page also fetches the latest round number to show the live clock. We try these relays, in order:
https://api.drand.shhttps://api2.drand.shhttps://api3.drand.shhttps://drand.cloudflare.com
These relays are operated by drand / Protocol Labs and Cloudflare, not by us. Like any website, they receive your IP address and basic request information (such as your browser's user agent) and may keep standard server logs under their own policies. The request contains only a round number — never your message.
b) License routes (only if you use a paid key)
When you activate, validate or deactivate a key, your browser sends the key, the license instance ID and a randomly generated device label (for example “Ripenote iPhone 3f2a”) to our /api/license/* routes. These requests pass through Vercel (see section 4) and are forwarded to Dodo Payments, which answers whether the key is valid and which product it belongs to. Our routes store nothing on a server and add no logging. They pass back only the instance ID and product ID — not the name or email address Dodo holds for the buyer — and set one cookie in your browser (section 10). Vercel may also process your IP address transiently to apply a short-lived, in-memory rate limit.
6. Payments
Purchases are processed by Dodo Payments, which acts as the Merchant of Record: it is the seller of record, handles your payment details, tax and receipts, and emails you your license key. Dodo Payments processes your name, email address, billing details and payment information under its own privacy policy. We don't receive your card details.
After checkout, Dodo returns you to /thanks and adds your key, a payment ID, the payment status and your email address to the address. Because that is part of the request, it can appear in Vercel's request logs (section 4); we don't read or keep it. The page uses the key to activate this device and then immediately removes all of these values from the address bar and the browser history entry.
7. Emails you send us
Mail to contact@ripenote.com, legal@ripenote.com and security@ripenote.com is forwarded by Cloudflare Email Routing to a mailbox we use, hosted by Google (Gmail). We use your email only to reply, handle refunds, reports, security reports and legal requests. We delete support emails when they're no longer needed, and at the latest 24 months after the conversation ends, unless we must keep them longer by law (for example, legal notices).
8. Who processes data for us
We don't sell or share personal data with anyone else. These providers process data so the site can run:
| Provider | What they receive | Privacy policy |
|---|---|---|
| Vercel | Hosting and request logs (IP address, user agent, path, time). | Vercel privacy policy |
| Cloudflare | DNS lookups for ripenote.com, and the contents of email you send to our addresses (so it can be forwarded). | Cloudflare privacy policy |
| Dodo Payments | Payments and license keys, as Merchant of Record (name, email, billing and payment details). | Dodo Payments privacy policy |
| The mailbox that receives email forwarded from our addresses. | Google privacy policy | |
| drand relays | The relays your browser contacts (https://api.drand.sh, https://api2.drand.sh, https://api3.drand.sh, https://drand.cloudflare.com). They receive your IP address like any website, and the round number being requested — never your letter. | Cloudflare · Protocol Labs |
9. How long things are kept
- Hosting logs: kept by Vercel for a limited period under its policy; we don't copy or export them.
- Emails: as in section 7.
- Purchase records: kept by Dodo as required for tax and accounting.
- Letters and drafts: never on our side. They live only in your links, files and browser.
10. Stored on your device
ripenote.licenses.v2(localStorage): each key you activate, with its instance ID, device label, product and last validation time — only if you activate a key. Clear it from Your keys (Deactivate this device) or by clearing site data for ripenote.com.ripenote.deviceandripenote.device.name(localStorage): a random id and label for this browser, used only so a second paste of the same key isn't counted as a new device. Clear site data for ripenote.com to remove them.rn_lic(cookie): the same key, instance ID, product ID and a device ID, so the unlock can be restored on this device if site storage is cleared. It is not used to track you. Remove it by deactivating this device on Your keys, or by clearing cookies for ripenote.com.ripenote.draft.v1(localStorage): the letter you're writing, so a refresh doesn't wipe it.ripenote.draft.offremembers if you turned drafts off. Sealing or clearing site data removes the draft.ripenote.theme(localStorage): light or dark mode, if you choose one. Switch the theme again, or clear site data.ripenote.sound(localStorage): whether sounds are on. Change the sound setting, or clear site data.ripenote.campaign.dismissed(localStorage): which seasonal note you closed, so it stays closed. Clear site data to see it again.ripenote.code(sessionStorage): a discount code from a link you followed, so we can remind you to use it at checkout. It clears when you close the tab.ripenote.group.reuse(localStorage): the last shared-device setup you started, so you can reopen it. Clear site data, or start a new one and leave without saving.- Letters collected in shared-device mode stay in that browser tab until you send or save them. Leaving the page or reloading clears them. They are not written to storage and never sent to us.
- A service worker cache of the app's own files, so Ripenote works offline. Remove it from your browser's site settings (clear site data, including cached files).
We use one functional cookie only. No tracking or advertising cookies, so there's no cookie banner. None of the items above is sent to us except as described in section 5(b). Clearing site data for ripenote.com removes all of them at once. Deactivate this device on Your keys first if you want to free its license slot.
11. Legal bases (EEA/UK)
- Performing our contract with you, for purchases and license keys.
- Legitimate interests, for security and abuse prevention (hosting logs, rate limits).
- Legal obligation, for tax records (held by Dodo Payments).
12. Your rights, all regions
Under the GDPR and UK GDPR you have rights to access, correct, delete and port your personal data, and to object to or restrict processing. You may also complain to your local data-protection authority.
US state privacy rights, including Connecticut, California and others: you can ask to access, correct or delete personal data we hold, and to opt out of sale, sharing or targeted advertising — we don't do any of these. Email contact@ripenote.com; we'll respond within the time the law requires. You can appeal a decision by replying to our answer.
We honour Global Privacy Control and Do Not Track signals, though we don't track you in the first place. Because Ripenote holds no personal data from using the app, there is usually nothing for us to access, correct or delete. Requests about purchases — your name, email or payment record — should go to Dodo Payments, which holds that data as Merchant of Record. We're happy to help you reach them.
13. Children and schools
Ripenote isn't directed at children under 13 and we don't knowingly collect personal information from them. In classrooms, the teacher sets up and runs the activity. Students' letters are sent to the teacher, and we never ask for a student's email, phone number or other contact details. Teachers and schools are responsible for following their school's rules and getting any consent they need. If you think a child has sent us personal information (for example by emailing us), contact us and we'll delete it.
14. International transfers
We're based in the United States, and our providers may process data in the US and other countries. Where required, they rely on appropriate safeguards such as standard contractual clauses.
15. Security and breaches
The site is served over HTTPS with HSTS. Letters are encrypted in your browser before they become a link or a file, and we never store them. The personal data we hold is limited to email you send us and what our providers keep, as described above. If a security incident affects personal data we hold, we'll notify affected people and authorities as the law requires. See also Security.
16. Changes
When this policy changes, we announce it with a notice on the homepage and update the “Last updated” date above.