Privacy policy

This policy explains what DearEver collects, why we use it, and how we protect personal stories.

1. What we collect

Depending on how you use DearEver, we may collect your name, email address, optional phone number, story type, desired date, order details, recipient names, dates, memories, letters, photo captions, ordering and focal points, rights and terms consent, and the photos you choose to submit. When you use the client portal, we also keep content changes, payment and publication records, expiry notices, and the security records needed to protect access. The support form collects only the information needed to answer your message.

Payment card details are entered with our payment provider; DearEver does not ask for or store your full card number.

Self-service photos are optimized in your browser to WebP with a maximum edge of 2400 pixels and an output limit of 5 MiB. Only the optimized files are uploaded. Customer music uploads are unavailable. Existing legacy orders may retain their previously accepted original media formats.

2. Why we use it

We use information to answer questions, process and support a self-service Birthday or Anniversary Story order and existing legacy orders, provide private previews, publish and host your story, meet legal or accounting obligations, prevent abuse, and maintain the security of the service. We do not sell personal information or use customer stories for marketing unless the purchaser separately opts in.

3. Who processes it

DearEver uses carefully selected service providers for website hosting, secure file storage, email delivery, payment processing, and basic operational security. They process information only as needed to provide those services and under their own privacy terms. We provide additional vendor information where applicable law requires it.

Information may be processed in countries where DearEver or its providers operate. Where applicable, we use appropriate safeguards for international transfers.

Payment processing uses Lemon Squeezy. We send the verified purchaser email and an internal order reference to create checkout. Hosting, private storage, and security checks use Cloudflare; recovery and expiry emails use our email-delivery provider. Rate limits store salted hashes of IP and customer identifiers, rather than raw IP addresses in rate-limit records.

4. How long we keep it

We keep information only for as long as it is reasonably needed for the purpose collected, to provide support, resolve disputes, meet accounting or legal obligations, and protect the service. Inquiry records are scheduled for deletion after 12 months. Unpaid or unconverted intake records and their private uploads are scheduled for deletion after 30 days.

Published optimized media is kept through the three-year hosting term. Editing ends after 30 days, but the public story remains available until expiry. We send expiry notices 60 and 7 days before removal. A refunded story is immediately unavailable, and its media is scheduled for deletion after 30 days. Limited payment, consent, and support records may be retained for legal, accounting, or dispute purposes. Providers apply their own retention obligations.

5. How photos and stories are protected

We use access controls, encryption in transit, private storage, authenticated uploads, one-time magic links, expiring portal sessions, file-type and size checks, and non-indexing defaults to reduce unnecessary exposure. No internet service can guarantee absolute security, so please use the service only for content you are authorized to share.

Customer stories are unlisted and non-indexed by default. An unlisted link is not password protection: anyone who receives a final link may be able to open it. Do not forward a story link more widely than intended.

6. Marketing permission and children

Marketing permission is optional and off by default. It may be withdrawn by contacting DearEver. If submitted content includes a child, the purchaser confirms that they are a parent or guardian or have the appropriate parent or guardian's permission to share it for the requested story.

7. Your choices and rights

You may ask us to access, correct, or delete inquiry, intake, or story information by emailing support@dear-ever.com. Please write from the email address used in the form and include an order reference where available. We may need to verify identity and may retain limited information where required for legal, accounting, fraud-prevention, or dispute-resolution purposes. Depending on where you live, you may also have rights to restrict or object to processing, request portability, or complain to a data protection authority.

8. Cookies and changes

DearEver does not use advertising cookies or sell browsing activity. The client portal uses strictly necessary session and request-protection cookies after draft creation or sign-in. A new draft session can access only that draft until you verify your email. Sessions expire automatically.

The creator saves local text drafts, purchaser name, and email on your device for up to 30 days. Photos and consent are not saved in this local draft. Other people using your browser profile may be able to access the locally stored writing. You can clear it through your browser’s site-data controls.

We may update this policy as the service changes. The date above shows when it was last revised. We will not quietly apply a material change to an active paid order where notice is required.

9. Contact

Questions, deletion requests, and privacy concerns can be sent to support@dear-ever.com.