Privacy policy
Last updated 10 October 2026
Letters to the future are personal. This policy explains what Kapivic Core Private Limited collects, why, and the control you have. We follow the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
The short version
- We collect only what’s needed to deliver your letters and take payment.
- No ads, no tracking or analytics cookies, and we never sell or rent your data.
- Nobody at Hello Dear Future reads your letters, except in the narrow cases in section 4.
- You can delete your account and everything in it yourself, at any time.
1. What we collect
| Data | Why |
|---|---|
| Your name, email address, profile photo and Google account id | To sign you in, show your account, send your own copies and put your name on letters you send |
| Letters: subject, text, chosen font, delivery date and up to 3 photos | To deliver them on the date you chose |
| Recipients’ names and email addresses | To deliver your letter to them |
| Credit history and payment records (order id, amount, date, status) | To keep your balance correct, handle refunds and meet tax and accounting law |
| Delivery records (which email service sent each email, and any error) | To retry failed deliveries and answer “did my letter arrive?” |
| Basic server logs (IP address, browser, time of request) | Security and fixing errors. Kept by our host for a short period. |
Unfinished drafts are saved only in your own browser, not on our servers, and are cleared when you sign out.
2. If someone sent you a letter
The writer gave us your name and email address so we could deliver their letter. We use them only for that delivery and never add you to a mailing list. If you don’t want to receive letters through Hello Dear Future, write to Kapivic.core@gmail.com and we will block your address from future deliveries.
3. Cookies and local storage
We use only cookies that are needed for the site to work:
- hfm_session: keeps you signed in for up to 30 days. Encrypted and unreadable by scripts.
- google_oauth_state, google_code_verifier, auth_next: protect the Google sign-in step and expire after 10 minutes.
Your browser’s local storage keeps your draft and which writing ideas you’ve already seen.
4. Who can see your letters
Sealed letters aren’t shown to anyone, including you, until their delivery date. Our team does not read letters. We would access a specific letter only to investigate a report of abuse, when required by law, or to fix a delivery problem you’ve asked us to look into. Photos are served only through private, signed links that work after delivery.
5. Services we use
We share data only with these providers, only to run Hello Dear Future, under their own security and privacy commitments:
| Provider | What for | Where |
|---|---|---|
| Sign-in. Tells us your name, email address and profile photo. | USA | |
| Vercel | Hosts the website and runs the code. | USA / global |
| Turso | Database that stores accounts, letters and photos. | Global (encrypted at rest) |
| Resend and Brevo | Send the delivery emails. | USA / EU |
| Razorpay | Processes payments. Card, UPI and bank details go to Razorpay, never to us. | India |
Some of these process data outside India. We otherwise disclose data only when required by law or a valid order from an Indian authority.
6. How long we keep it
- Undelivered letters: until they’re delivered or you cancel them.
- Delivered letters: in your archive until you remove them or delete your account.
- Your account: until you delete it.
- Payment records: 8 years, as Indian tax law requires. After you delete your account they are kept without your name or email.
- Your Google account id is kept after deletion only to record that its welcome credits were used, so they can’t be claimed twice.
7. Security
All traffic uses HTTPS. Sessions are encrypted, the database is encrypted at rest, and payment and email keys are kept out of the code. No system is perfect: if a breach affects your data we will tell you and the Data Protection Board of India as the law requires.
8. Your rights
Under the DPDP Act you can:
- see the data we hold about you, and get a copy;
- correct it (your name and email come from Google, so update them there and sign in again);
- erase it: delete your account from the Credits page, or ask us;
- withdraw consent, by deleting your account;
- nominate someone to exercise these rights if you die or become unable to;
- complain to our grievance officer, and then to the Data Protection Board of India.
We reply to requests within 30 days.
9. Children
Hello Dear Future is for people aged 18 and over. Younger writers may use it only with a parent or guardian, who is responsible for the account.
10. Changes
If we change this policy in a way that matters, we will email you before it takes effect.
11. Contact
- Operated by: Kapivic Core Private Limited
- Email: Kapivic.core@gmail.com
- Phone: +91 9893978973
- Address: 201, Phase 2, Crysta Ideal City, Awadhpuri
Grievance officer details are on the contact page.