Terms of Service & Data Retention Policy
Effective & Last Updated: September 2026 · Governed by FRISKYSOFTSELL
1. Purpose & Service Philosophy
Love Letter Studio is a bespoke, ephemeral digital storytelling platform crafted to celebrate intimate life milestonesโbirthdays, anniversaries, proposals, and expressions of love. Our design philosophy prioritizes privacy by design and fleeting digital intimacy.
2. The 15-Day Public Keepsake Window
When a creator finalizes and publishes a surprise keepsake, a unique, unlisted URL is registered in our database.
- Active Live Duration: Every generated surprise link remains publicly accessible to the recipient for exactly fifteen (15) consecutive calendar days from the exact moment of creation.
- Unlisted Indexing: Surprises are never submitted to search engine directories, web crawlers, or public feeds. Access is granted exclusively to those possessing the private alphanumeric link.
- Public Expiry: At the conclusion of the 15-day window, the public route immediately transitions to an expired status (HTTP 410). Public visitors can no longer view the private letter, cake blowout, or celebratory proposal.
3. 10-Day Post-Expiry Retention & Automatic Deletion
In accordance with digital privacy standards and strict data minimization, we uphold a transparent, multi-phase lifecycle for all customer data:
Days 1 to 15
Website is Live. The recipient can view the keepsake, blow out candles, listen to the soundtrack, and respond.
Days 16 to 25 (Grace Period)
Website is Closed; Data Retained in Backend. The public URL is deactivated. We retain the keepsake records securely in our backend for an additional 10 days.
Day 25 Onward
Automatic Permanent Deletion. Once the 10-day backend grace period elapses, the private letter and personal sentiment text are automatically purged from our backend database.
Summary: We maintain your active surprise while the website is live (15 days). After that, we keep the data for an additional 10 days, after which private written letter sentiment is automatically and permanently purged from our backend.
4. User Uploaded Media & Photos
Users have the option to upload personal photographs and custom musical soundtracks from their device gallery:
- Client & Server Optimization: All uploaded photos are automatically downscaled and stripped of unneeded EXIF camera metadata and geographic coordinates to conserve server storage and protect user privacy.
- Media Archival: Media files uploaded to our servers remain archived in our secured internal media vault for administrative auditability and record-keeping, accessible only by verified administrators.
- Content Integrity: Users certify that they hold the requisite rights, permissions, or copyright to upload all shared images and musical tracks. Content depicting unlawful, abusive, or non-consensual material is strictly prohibited and subject to immediate deletion.
5. Security, Access Controls & Zero-Leak Architecture
We deploy multiple layers of digital security to ensure that no customer details are exposed or leaked:
- Cryptographic Authentication: The central administration console is protected by PBKDF2-HMAC-SHA256 password hashing with 100,000 computation iterations and unique cryptographic salts.
- Session Tokenization: All administrative endpoints require valid high-entropy cryptographically random session tokens (32-byte hex). Unauthorized requests are rejected immediately with HTTP 401.
- Contact Protection: Creator email addresses and phone numbers provided for expiration receipts are never sold, shared, or displayed on public recipient pages.
6. Governing Brand & Inquiries
This service is conceived, architected, and maintained by FRISKYSOFTSELL in partnership with Simerdeep Singh.