Intezaar

Private digital mail

Privacy Policy

This policy explains what Intezaar handles when you write, post, receive or open a private digital letter during the public beta.

Last updated 7 August 2026

Important beta notice

Intezaar uses encryption and private access tokens, but no online service can promise absolute confidentiality or uninterrupted availability. Do not use the beta for passwords, bank credentials, identity documents, medical records, privileged legal material or confidential business secrets.

1. Who this policy applies to

This policy applies to senders, recipients and visitors using the Intezaar website and public-beta letter service.

Intezaar is currently an early-stage project. The formal operating entity, registered address and dedicated privacy contact will be published before commercial launch. Until then, the service is offered only as a limited public beta.

2. Information you provide

Depending on how you use Intezaar, you may provide:

  • sender and recipient names;
  • sender and recipient email addresses when entered;
  • occasion, opening date and time, and optional origin or destination city;
  • the written letter, heading and closing;
  • photographs, voice notes, videos, captions and photo-layout choices; and
  • information included in a safety, support or legal request.

Only provide another person's email address or personal information when you have a legitimate reason to contact them and doing so respects their wishes and rights.

3. Information created automatically

The service may create or receive technical and operational information such as:

  • random private access and management tokens, which are stored as one-way hashes;
  • letter status, creation time, opening time, expiry time and delivery events;
  • security-check results from Cloudflare Turnstile;
  • basic request, error, device, browser, network and hosting logs;
  • email-delivery status and provider message identifiers; and
  • storage paths, file sizes, file types and encrypted-media upload status.

4. Browser-local information

Intezaar uses local storage and session storage to preserve a draft, optional email fields, the latest secure recipient link, posting state and parts of the recipient experience. This information remains on the device until it is removed by the browser, the user or site updates.

Selected media initially exists as a browser-local file and preview. It is uploaded only when the sender completes secure posting.

5. How private letters are protected

The written letter payload is encrypted before database storage. The private recipient token itself is not stored in readable form; Intezaar stores a one-way hash used to validate the secret URL.

Media is encrypted in the sender's browser before upload to a private Supabase Storage bucket. Before the opening time, the recipient's browser does not receive the letter content, media decryption key or signed media URLs.

After the opening time, Intezaar validates the private token, decrypts the stored letter payload on the server and issues short-lived media URLs. The recipient's browser then decrypts media locally.

6. Why information is used

Intezaar uses information to:

  • create, secure, schedule and deliver a private letter;
  • send an invitation email when requested;
  • preserve the selected photo layout and recipient experience;
  • prevent bots, abuse, fraud and unauthorised access;
  • diagnose errors and improve reliability;
  • enforce the User Agreement and Community Guidelines; and
  • respond to valid safety, legal or regulatory requirements.

Intezaar does not sell private letter content or personal information and does not use the contents of letters for behavioural advertising.

7. Service providers

Intezaar currently relies on specialist providers to operate the beta:

  • Vercel for website hosting, server functions, deployment and operational logs;
  • Supabase for the database and private encrypted-media storage;
  • Resend for optional invitation-email delivery; and
  • Cloudflare Turnstile for automated-abuse and bot protection.

These providers process limited information according to their own infrastructure, security and privacy terms. Data may be processed in countries outside the sender's or recipient's location.

8. When information may be disclosed

Information may be disclosed when reasonably necessary to:

  • operate the service through the providers listed above;
  • investigate credible abuse, threats, exploitation, fraud or security incidents;
  • protect users, Intezaar or the public from serious harm;
  • comply with a valid legal request or applicable law; or
  • support a future restructuring, transfer or formal launch, subject to appropriate notice and safeguards.

Private letters are not routinely read or manually reviewed.

9. Retention and deletion

A posted letter is assigned an expiry time 90 days after its selected opening time. A protected daily cleanup process deletes encrypted media from storage and marks the letter expired.

The current beta cleanup does not immediately erase every encrypted database field or operational event. Encrypted records, email-delivery data, security logs and backups may remain for a reasonable period for reliability, abuse prevention, debugging or legal compliance.

Browser-local drafts and session data remain under the user's browser controls. Clearing site data removes them from that device.

10. Your choices

  • Recipient and sender email addresses are optional.
  • Media attachments are optional.
  • You may choose to copy and share the private link manually instead of relying on email.
  • You can clear local browser data to remove saved drafts and local session information.
  • Do not share a private link you no longer want used.

A complete account dashboard, withdrawal tool, privacy-request portal and self-service deletion control are not yet available.

11. Children

The public beta is intended for adults aged 18 or over. Intezaar is not designed for children, and users must not send sexual, exploitative or otherwise inappropriate content involving anyone under 18.

12. Security limits

Intezaar uses encryption, private token links, short-lived media URLs, server-side time checks, restricted storage and Cloudflare bot protection. However, a recipient can forward a private link, a device can be compromised, software can contain defects and third-party infrastructure can fail.

Keep the recipient link private and retain your own copy of anything important.

13. Changes to this policy

This policy will change as the beta adds accounts, reporting, longer scheduling, payment or new storage controls. The last-updated date will identify the latest published version.

14. Privacy requests and formal contact

A verified privacy and safety contact address will be published before wider public or paid launch. During the limited beta, do not upload information that requires a formal confidentiality arrangement, guaranteed deletion deadline or regulated record-retention service.