Privacy
A postbox holds a child’s name, their face and their family’s voices. Here is exactly what we do with all of it, and what we do not.
Last updated: 23 August 2026
The short version
- We do not sell your data.
- We do not use your posts to train anything.
- Postboxes carry no analytics at all: no third party script ever loads on one. Our public pages use analytics to see what is working, and where the law asks for consent, we ask first.
- Postboxes are unlisted and we tell search engines not to index them.
- You can ask us to delete a postbox and everything in it, and we will. What deletion can and cannot reach is set out below.
What we collect
When you buy a postbox
Stripe collects your email address, your billing name and your country in order to take the payment and work out the tax (for US buyers, a billing address too, because sales tax needs one). They pass those on to us, and we keep your email address because it is how you get back into your postbox. Your card details go to Stripe and never touch our systems.
The order we send to Stripe also includes the child’s first name and the parents’ first names, and for a gift the name the gifter gives us, so that the postbox can be created the moment the payment completes. They sit alongside the payment in Stripe’s records, which Stripe keeps under its own policy.
About the child
You give us the child’s first name to create the postbox, though a nickname is fine and you can change it whenever you like. You can also add their date of birth, whether they’re a boy or a girl, and a photograph, all of which are optional. We use these to show the postbox to the people who hold its links, to time the milestone reminders people ask for (that is the birth date’s job), and to choose the right words in invitations (the boy-or-girl answer picks pronouns, nothing more). The name also travels with the order, as described above, and is kept with the postbox’s usage records, described under Analytics below.
The parents or guardians decide who can post, what stays in the postbox, and who can see it.
From family and friends who post
When somebody posts, we record the name they choose to be known by, how they are related to the child, and what they posted. We also ask, optionally, for their email address, so we can remind them at the child’s milestones and let them know when the parents post an announcement. That address is theirs to give or withhold and it is never required in order to post. Before any reminder goes to a typed address, we email it once so its owner can confirm it is really theirs; an address that never confirms is never emailed again.
Anyone holding a sharing link can post without an account and without paying. By posting through one, you agree to this policy.
The posts themselves
Letters, photos, videos and voice notes, along with the date, the occasion and who wrote them. This is the whole point of the product, and it is the most personal thing we hold.
Photos and videos often carry hidden location data that records where they were taken, sometimes down to a home address. We remove that location data from photos and videos when they are uploaded, before they are stored. We leave the rest of the picture untouched, including the date it was taken and which way up it should show.
Technical information
Our host, Vercel, keeps standard server logs which include IP addresses, according to their own retention policy. We do not build profiles from them. What we measure deliberately is described in the next section.
Analytics, on our public pages only
Our public pages, meaning the homepage, the example postbox, the sign-up and sign-in screens, and reference pages like this one, use two analytics services so we can see what is working: PostHog, which runs in the EU and processes data only on our instructions, and Microsoft Clarity. They count visits, show us which pages people read, and record replays of how those public pages are used. A replay is pseudonymous rather than anonymous: what a visitor did, tied to a random id instead of a name, unless you go on to buy a postbox, in which case we connect that visit to the postbox you bought so we can see what leads to a purchase. Anything you type into a form is masked before a replay is recorded.
Real postboxes never load an analytics script. When family open a postbox, read a letter or play a voice note, no third party is told. Our own servers do keep a record of what happens in the product, that a post was added or a link shared, so we can run and improve it. Those records are kept against the postbox, with the child’s first name and the parents’ first names so we can tell postboxes apart, and they note what kind of post was added, how long it was, and how the person who added it is related to the child. They never include the names or email addresses of the family and friends who use the postbox, and never the words, photos or anything else anyone posted. Because they relate to a family, we treat them as personal data: when a postbox is deleted, we have them erased too.
One thing to know about Clarity: Microsoft also uses the data it collects for its own purposes, including advertising, as an independent controller under its own privacy statement. It is the only service we use that does. It runs only on the public pages, only when analytics is switched on, and you can opt out of interest-based advertising at optout.aboutads.info.
Whether any of this runs is your choice. In the UK, Europe and most other places we ask first: a banner offers analytics cookies as soon as you arrive, and declining is one tap. Until you answer, and if you say no, the only measurement is an anonymous count of visits: no cookie and no id on your device, just one browser flag that keeps analytics switched off. In a few countries whose law works on an opt-out basis, such as most of the United States, analytics is on unless you switch it off. Either way, the Cookies link in the footer opens the same choices at any time, and if your browser sends a Global Privacy Control signal we treat it as a no. If you would rather not be counted even anonymously, the same panel has a switch for that too.
Why we are allowed to hold it, in legal terms
- To provide what you bought (contract). Your email address as a buyer or an administrator, the payment, and your way back in: what we need to serve the person the contract is with.
- Because it is in our legitimate interests. Running each postbox for its family: holding the child’s details and everyone’s posts, and showing them only to the people the family lets in. The child cannot agree to any of this, so we rely on their parents’ choices and our own care. Also keeping the site secure and working, answering you when you get in touch, counting visits to the public pages anonymously, and understanding how the product is used through the usage records described above. We have considered whether all of this is fair to the people involved, the child above all, and we are satisfied it is.
- Because you agreed (consent). Milestone reminders, analytics cookies where we ask for them, and anything we ever send you about baby postbox itself. You can withdraw any of these at any time.
- Because the law requires it. Keeping records of sales for tax purposes, and reporting illegal content and preserving the information around it, as described further down.
Who else sees it
Only the companies we need in order to run the service. Most of them handle it purely on our instructions. Two also act for purposes of their own: Stripe, which as a regulated payments company uses payment data for its own fraud prevention and legal compliance, and Microsoft Clarity, flagged below.
- Stripe, to take payments. Stripe also processes payment data for its own purposes, such as fraud prevention and financial regulation, as an independent controller under its own policy.
- Vercel, who host the site and store the photos, videos and voice notes.
- Neon, who host the database.
- Resend, who send our emails.
- PostHog, who process the analytics for our public pages and the usage records, in the EU, on our instructions.
- Microsoft Clarity, for replays of the public pages. This is the other exception: Microsoft also uses what Clarity collects for its own purposes, including advertising, as described in the analytics section above.
- Slack, where a short internal alert is posted when something notable happens, such as a postbox being bought or a concern being reported, so we can act on it quickly. These alerts name the child but carry nothing more sensitive: never an email address, a postbox link, a code, or anything anyone posted.
We may also disclose information if the law requires it; the “Illegal content, and the law” section below says how that works in the hardest case. Beyond that, nobody sees it. We do not sell or rent personal data to anyone, for any purpose.
Where it is stored
The services above operate internationally, so your information may be processed outside the UK. Where that happens, it is covered by the safeguards UK data protection law requires, such as the International Data Transfer Agreement or an adequacy decision. Analytics data sits with PostHog in Frankfurt; Microsoft Clarity processes its replays in the United States, under the same kinds of safeguard.
Cookies, and what your browser remembers
We set a small number of cookies to do things you asked for, which need no consent. On the public pages only, there are also the analytics cookies described above, which run with your consent, or with an off switch, depending on where you are.
First, the ones that are just the product working:
bpb-sessionkeeps a postbox administrator signed in for up to 180 days. It holds nothing but a random token.bpb-passremembers, for each postbox and for up to 180 days, that this device has entered the postbox code. It holds a scrambled version of the code, never the code itself, and changing the code re-locks every device.bpb-accountkeeps a reminders account signed in on this device for up to 180 days, so you can manage your reminders and your own posts without digging out the email.bpb-knownrecords only that this browser has signed in before, for up to 400 days, so we do not send you a “new device signed in” alert every time you come back. It holds the digit 1 and nothing else.bpb-deletedexists for 30 seconds after you delete a postbox, so the goodbye page can say the child’s name without putting it in the address bar.bpb-regionremembers a currency you pick in the footer, for up to a year, so prices stay in it.bpb-attris set when you arrive from a link on our other site, Not Another Noah, and remembers which of those links you came through, for up to 90 days. It holds only a short label for the promotion, never a name, an email, or an id that could follow you anywhere, and its only use is to let us see which of those links lead to a postbox being opened.
Then the analytics ones, on the public pages only:
bpb-consentremembers the cookie choice you made, whichever way you made it, for 180 days. It is set only when you choose.ph_…_posthog, a PostHog cookie and a matching browser-storage entry holding a random visitor id, for up to a year. Only ever set after you accept analytics, or in the places where analytics is on by default and you have not switched it off._clckand_clsk, Microsoft Clarity’s ids, on the same terms. When Clarity runs, Microsoft may also set cookies on its own domains:CLID,ANONCHK,MR,MUIDandSM.MUIDidentifies a browser across Microsoft sites and is used by Microsoft for advertising as well as analytics; the others support fraud protection and syncing. They are Microsoft’s cookies, governed by its own privacy statement, and whether your browser stores them depends on how it treats third party cookies.
Decline, and the only thing set is the cookie that remembers you declined. No analytics cookie of any kind is ever set on a postbox page. We set no cookies of our own for advertising; the one advertising-related cookie above, Microsoft’s MUID, exists only if you accept analytics.
Your browser also stores a few things locally, on your device only, which are never used to build a profile: the name you last posted under, so grandparents do not have to reintroduce themselves; keys that let you edit or remove your own posts and comments; an unfinished letter, so you do not lose it; the name you sign love and comments with; which posts you have sent love to, along with a random id that stops one device counting twice; your reminder sign-up details, meaning the name, email address and manage link you gave, if you signed up on that device; on a gifter’s own device, the link back to their gift page; and which cards and notices you have dismissed. The marketing pages also remember your light or dark preference and which sample postbox you were browsing, neither of which says anything about you. If you arrive from a link on Not Another Noah that carries a baby’s name, that name waits in your browser only long enough to fill it into the create-a-postbox form, and is then cleared.
On a shared computer, “Forget me on this device”, in the About panel of any postbox, clears everything there that identifies you. The anonymous id stays, because it carries no name and only stops love being counted twice.
How long we keep it
A postbox is a keepsake, so we keep it for as long as it is wanted. We do not delete it on a timer.
- Posts are kept until somebody removes them. Removing a post, or removing a person, takes them out of the postbox at once; they then wait 30 days in case it was a mistake, and after that they are deleted for good, along with any photo, video or recording.
- Comments on an announcement follow the same rule as posts: removed at once, then deleted for good after 30 days.
- Sign-in links expire quickly: 30 minutes for signing in, 7 days for an invite, 30 days for the link in your welcome email, 60 days for a gift.
- Sessions end after 180 days, or as soon as you sign out.
- Milestone reminders stop the moment you unsubscribe, and no reminder is ever sent about a postbox that has been deleted. If you want the email address you gave for reminders removed entirely, tell us and we will remove it.
- Payment records are kept for six years, as tax law requires.
- The postbox itself is kept until an administrator deletes it, from inside the postbox or by writing to us.
- Abuse reports are kept while we need them: a report that led nowhere is cleared out after about a year, and one that is part of a legal matter is kept for as long as that requires.
- Analytics data lives on the vendors’ own schedules: PostHog keeps events for up to seven years and replays for up to 90 days; Clarity keeps replays for 30 days, or nine months for one we mark to keep, and heatmap data for nine months. When a postbox is deleted, we also ask PostHog to erase the usage records that referenced it.
- If we have to preserve a postbox while we look into a report, or because the law requires it, deletion is paused for that postbox until the matter is resolved.
One footnote: deleted information can linger briefly in our encrypted database backups, which age out on a 7 day cycle, before it is gone from there too. Photos, videos and recordings are not held in any backup: when they are deleted, they are gone. And if we ever restored from a backup to recover from a disaster, we would delete again anything that had already been deleted for good, so a restore cannot quietly bring something back.
Illegal content, and the law
We do not scan your posts, and we do not read them in the ordinary run of things: a person looks at a post only when a report or a legal duty makes it necessary, and no further than that requires. If something in a postbox is reported to us, or otherwise comes to our attention, and we believe it is illegal, especially if it is a sexual image of a child, we immediately disable access to the content or to the whole postbox, preserve the content and the information around it (who uploaded it, and when), and report it to the National Crime Agency or another appropriate authority, as UK law requires. We keep what the report requires for as long as the law says and no longer, and while that happens the deletion timers above are paused for that postbox. We will not warn the person who posted it where that could prejudice an investigation.
Beyond that, we disclose personal information only where the law requires it, and we tell you about any request when we are allowed to.
Emails we send
Most of our email is not marketing and you cannot turn it off, because it is the service itself: your way back into your postbox, an invitation, a gift handover. Without those emails the product does not work.
Milestone reminders, and anything about baby postbox itself, are optional, separate, and never ticked for you. Tell us at hello@babypostbox.com and we will stop them.
Your rights
Under UK data protection law you can ask us to:
- show you what we hold about you
- correct anything that is wrong
- delete it
- give you a copy in a portable form (an administrator can do this themselves, at any time, with “Download everything” inside the postbox)
- stop or limit what we do with it
- stop relying on your consent, at any time
Email hello@babypostbox.com and we will answer within a month. There is no charge.
A note on deleting a postbox: it belongs to the family, so we act on an administrator’s instruction. If you posted into someone else’s postbox and want your own posts taken out, you can usually remove them yourself from the device you posted from, and if not, tell us and we will do it.
Children
A postbox is created and controlled by adults, written about a child, and handed over when their parents judge the time right. The family circle a sharing link reaches can include older children: a teenage cousin can read and post like anyone else the family lets in. Beyond what a family chooses to share, we do not knowingly collect information from children. The rights above belong to the child from the start. While they are young, their parents exercise those rights for them; once they can act for themselves, we will help them do it directly.
Security
Connections are encrypted, administrator access needs a verified email address rather than a password you invent here, and postboxes carry a noindex instruction so search engines don’t index them.
Access to a postbox works by link, plus a postbox code, asked for once per device, where the family has set one. That is what makes it work for a grandparent with no account. Photos, videos and recordings are stored privately and handed out through short-lived signed addresses that expire within minutes, behind the same link-and-code check as the page itself; the one exception is the picture on an announcement’s share card, which lives at an unguessable address so it can be passed around. Posts sealed just for the child are held back by our servers, not merely hidden on the page. Even so, anyone who is given the link and the code, or a copy of a photo, has them, and we cannot take that back. An administrator can change the sharing link or the postbox code at any time; a new link stops every copy of it working, and a new code re-locks every device.
If you are unhappy
Please tell us first, at hello@babypostbox.com. A complaint about how we have handled personal data gets an acknowledgement within 30 days, a proper look, and an answer saying what we found. You also have the right to complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk.
Changes
If we change anything that materially affects you, we will email the administrators of every active postbox. The date at the top tells you which version you are reading.
Terms
Our terms cover the rest of the arrangement between us.
Who we are, and how to reach us
baby postbox (babypostbox.com) is operated by Elliot Robinson, a sole trader in the United Kingdom, who is the data controller for the information described here. For any privacy question at all, email hello@babypostbox.com.