Privacy Policy
Last updated: July 29, 2026
This Privacy Policy explains how Cachet (listed on the app stores as “Cachet: Cards & Love Letters”), operated by Niko Ng in Vietnam (“Cachet,” “we,” “us,” or “our”), handles information when you use the Cachet mobile app and this website, including the page where a sealed letter is opened.
Information we process
Depending on how you use Cachet, we may process:
- an anonymous Firebase Authentication identifier that lets the app reach the letters you have written. A recipient opening a letter on this website is also signed in anonymously, in memory only, for the duration of that page view;
- the content you put into a letter, including the recipient’s name, the sender name or initial, the message body, the date, any occasion details, and the wax colour, seal mark, and paper you choose;
- share links and their delivery state. Each sealed letter gets a random share link, and we record whether that letter has been sent, delivered, or opened, together with the time it was first opened. The sender can see that opening time in the app;
- a flag stored in the recipient’s browser recording that the seal on a given letter was already broken, so returning to the link does not replay the ceremony;
- device, app, and usage information collected through Firebase Analytics in the mobile app, including app interactions and technical diagnostics;
- advertising-related information and interactions when ads are shown in the mobile app through Google Mobile Ads;
- purchase status and transaction-related information needed to provide or restore in-app purchases. Apple App Store and Google Play process payments under their own privacy policies.
We do not ask for or collect your email address. This website has no sign-up form, no newsletter, and no waitlist.
Our servers also write short-lived technical logs when a letter is requested, which we use to diagnose errors. We do not sell your information.
How we use information
We use this information to store and deliver the letters you write, render the opening ceremony for the person you sent a letter to, tell you when a letter has been opened, restore eligible purchases, measure and improve app performance, prevent abuse, serve and measure advertising in the mobile app, and respond to support requests.
Share links and who can read a letter
A sealed letter is reachable through a share link containing a long random token. The link is not guessable, but it is not a password either: anyone who has the link can open the letter and read it. Treat a share link the way you would treat the envelope itself, and only send it to the person it is meant for.
Share links do not expire on their own. A sender can revoke a link from the app, after which the letter can no longer be opened through it.
Service providers
We use Google Firebase for anonymous authentication, cloud data storage through Cloud Firestore, and app analytics. We use Google Mobile Ads to show ads in the mobile app. Purchases are processed by Apple or Google through their respective app stores. This website is hosted on Vercel. These providers process information under their own policies and may process information outside your country of residence. This website does not use advertising or third-party analytics trackers.
Storage, retention, and your choices
Letters are stored in Cloud Firestore so that they can be opened from a share link and remain in your collection in the app. You can revoke a share link or delete a letter from the app. We retain information only for as long as needed to operate, secure, and improve the service, comply with legal obligations, or resolve disputes.
Because Cachet uses anonymous sign-in, we may not be able to identify an account after you lose access to the device that created it. Contact us if you have a privacy question or want help with a data request, and include the share link of any letter your request concerns so we can locate it.
Security
We use reasonable technical and organizational measures designed to protect information. Letter content is served over an authenticated, non-cacheable connection. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children’s privacy
Cachet is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, please contact us.
Changes to this policy
We may update this policy as the app or our data practices change. We will post the revised policy here and update the “Last updated” date.
Contact
For privacy questions or requests, email contact@anng.dev.