Skip to content

  • ❀Love
  • ☾Thinking of You
  • ✶A Wish
  • ✺Playful
← back

Security.

People write things here they have never said out loud. That only works if the platform is worth trusting. This page is a plain-English record of what we actually do — not marketing language.

Erasure by design

The strongest security control is not storing the data. A letter body is destroyed on all sides — sender, recipient, and our servers — when it is read, when its retention window expires, or when the sender recalls it within the 60-second undo window. What remains afterwards is anonymised metadata (counts and timings) that cannot reconstruct what was written.

The only exception is a letter reported for safety reasons, which is preserved as evidence under a separate legal basis and reviewed by moderation.

Account protection

  • Two-factor authentication (authenticator app / TOTP) with single-use recovery codes.
  • Passkeys (WebAuthn) for phishing-resistant sign-in on supported devices.
  • Mandatory 2FA for staff. No administrator can reach an admin surface without it.
  • Step-up re-authentication before destructive actions such as account deletion.
  • Session control. See recent sign-ins with device and IP, and sign out every other device in one click.
  • Security alerts. We email you on password changes, 2FA changes, new-device sign-ins, and session revocations.
  • Bot protection on sign-in and password reset, plus rate limits on authentication.

Platform & infrastructure

  • TLS 1.2+ everywhere; HSTS on the production domain.
  • Encryption at rest for the database and file storage.
  • Row-level security on every user table — access is enforced by the database itself, not only by application code.
  • Payments are handled by Stripe. We never see or store card numbers.
  • Inbound webhooks are signature-verified before any write.
  • Least-privilege service credentials, held server-side only and never exposed to the browser.
  • Administrative actions are written to an immutable audit log with the acting account, reason, and timestamp.
  • Automated dependency and database security scanning.

Privacy posture

No behavioural advertising. No third-party trackers on letter or Companion content. Analytics are consent-gated and never tied to the contents of what you write. You can export or delete your account and data at any time from Account → Settings.

Incident response

We maintain a written incident-response process: detect, contain, assess, notify, remediate, and review. Where a personal-data breach is likely to result in a risk to you, we notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected users without undue delay where the risk is high. Notifications describe what happened, what data was involved, what we have done, and what you should do. Full terms are in our breach & incident-response policy.

Report a vulnerability

We welcome good-faith security research. Email security@support.unsaidx.com with steps to reproduce. We acknowledge within 72 hours and keep you updated until it is closed. Please do not access other people's data, degrade the service, or publish before we have fixed the issue. We will not pursue legal action against researchers who follow this policy. See also our security.txt.

What we don't claim

No platform is unbreakable, and anyone who tells you otherwise is selling something. We are a small team. We reduce risk by storing as little as possible, keeping it for as short a time as possible, and being honest when something goes wrong.

Questions? Write to security@support.unsaidx.com.