We take your privacy seriously. Here is exactly what data we collect, why, and what we do with it.

1. What We Collect & Why

1.1 Account Information

What: Your email address, a hashed password (we never see the plaintext), and optionally passkey credentials (WebAuthn public keys) for password-free login. We also collect a timestamp of registration and your last login time.

Why: To create and maintain your account, authenticate you, and communicate with you about your subscription and the service.

1.2 Subscription & Billing Data

What: Your chosen subscription plan, billing history, and the last four digits of your payment card and its expiry date (provided to us by Stripe). We do not see or store full card numbers, CVV codes, or bank account details — those are handled entirely by Stripe, our payment processor.

Why: To manage your subscription, process payments, handle plan changes, and maintain billing records.

1.3 Your Messages & Attachments

What: Subject lines, message bodies, file attachments, and recipient email addresses and names. This is the core content you create in the service.

Why: To store them securely and dispatch them to your recipients when your timer expires. This is the service we provide.

How stored: Message bodies, subjects, and contact names are encrypted using envelope encryption (AES-256-GCM) before being written to disk. Attachments are encrypted with streaming AES-256-CTR + HMAC. We hold the master key and wrap a unique data-encryption key for every item. This means your message content is encrypted at rest and can only be read by us during dispatch (or if you access it through your authenticated session).

1.4 Contact Information

What: The names and email addresses you add as recipients. Contact email addresses are stored both in encrypted form and as a one-way hash so we can detect duplicates without exposing the plaintext.

Why: So you can save recipients for reuse across messages, and so we know where to send your messages when the switch fires.

1.5 Usage & Technical Data

What: Pages visited, timestamps, browser type and version, operating system, IP address, and a browser fingerprint (an anonymous hash derived from browser characteristics).

Why: To operate and improve the service, detect and prevent abuse, and provide analytics. The browser fingerprint helps us detect suspicious login attempts (e.g., a login from a new device triggers additional verification).

We also use Google Analytics 4 and Microsoft Clarity on the public-facing parts of the site (marketing page and legal pages) to understand how visitors find and navigate the site. These tools use cookies and similar tracking technologies. Clarity records session replays (mouse movements, scrolls, clicks) on anonymous visitors — this data is anonymized and cannot be linked to your account. These analytics are not loaded when you are logged in.

1.6 Security Logs

What: Every administrative action, login attempt (successful or failed), switch reset, account lockout, and authentication event is logged with a timestamp, IP address, user agent, and the action taken.

Why: To audit security events, investigate incidents, and comply with our security policy.

2. How We Use Your Data

We use your data only for the following purposes:

We do not sell your personal data. We do not use your message content for training AI models, advertising, or any purpose beyond what you explicitly asked us to do: hold and dispatch it.

3. Who We Share Data With

We share data only with the third-party services that make the service work, and only to the extent they need it:

Service What they see Where hosted
Stripe Payment info, billing details United States
Resend Recipient email, message body (for delivery) United States / Global
Hetzner Cloud All server-side data (encrypted at rest) Nuremberg, Germany
Cloudflare IP addresses, network-level traffic data Global edge network
Cloudflare R2 Encrypted attachments + encrypted backups Global
Google Analytics /
Microsoft Clarity
Anonymous visitor behavior (logged-out site only) United States

We do not share your message content with any third party except as described above (Resend dispatches, Stripe processes payment data only). We will never sell your data.

4. Data Retention & Deletion

4.1 Active Accounts

Your data is retained for as long as your account is active. Messages you delete from your account are permanently removed from our servers (including encrypted cloud storage) within a reasonable period.

4.2 Closed Accounts

When you close your account, all your messages, contacts, attachments, and personal data are permanently deleted. This is immediate and cannot be undone. Billing records (invoices) are retained for tax and accounting purposes as required by law, but payment card data is never in our possession to begin with.

4.3 Dispatched Messages

When your switch fires and a message is successfully sent, the message and its attachments are deleted from our servers. We do not keep a copy after dispatch (except in backup archives for a limited period, see below).

4.4 Backups

Database backups are encrypted and stored in Cloudflare R2 with a 14-day retention period. A message deleted from the live database may persist in backups until they naturally expire.

5. Data Security

We take the following measures to protect your data:

6. Cookies & Tracking

We use the following cookies and tracking technologies:

You can disable analytics cookies through your browser settings or by using a privacy extension (like uBlock Origin). Disabling these does not affect the core service.

The switch reset page (which contains a reset token) is explicitly blocked from crawling in our robots.txt and does not load analytics.

7. Your Rights

7.1 Access & Portability

You can view, edit, and export your data at any time through your account dashboard. If you need a full export of your data in a machine-readable format, contact us at [email protected] and we will provide one within a reasonable timeframe.

7.2 Correction & Deletion

You can edit your account information and contacts directly through the interface. To delete your account and all associated data, use the close-account option in your profile settings.

7.3 GDPR Rights (EEA Users)

If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation:

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

7.4 CCPA Rights (California Users)

If you are a California resident, the California Consumer Privacy Act gives you the right to:

To exercise your CCPA rights, contact us at [email protected].

8. Children's Privacy

Finally Send It! is not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

9. Data Transfers

Your data is primarily stored on servers in Nuremberg, Germany (Hetzner Cloud). Some third-party services (Stripe, Resend, Google Analytics, Microsoft Clarity) may process data in the United States and other jurisdictions. By using the service, you consent to this transfer of data. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email and/or a notice on the service. The “Effective” date at the top shows when the policy was last changed.

11. Contact

If you have questions, concerns, or requests regarding your data or this policy:

Email: [email protected]
Mail: Finally Send It! · Privacy Inquiries · Austin, Texas

← Back to Finally Send It!