Privacy Policy

Effective August 8, 2026 · NextPath Ventures LLC

NextPath Ventures LLC, trading as FamilyLetter ("we", "us"), operates familyletter.io. This policy explains what we collect, why, who we share it with, how long we keep it, and what you can ask us to do about it. It covers three groups of people, because they give us different information for different reasons: the account holder who pays for and approves the postcards, the contributors who send photos and messages, and the recipients the postcards are mailed to.

Information we collect

What we hold about you depends on your role in a family.

  • Account holders — name, email address, phone number, and billing information. Card numbers go directly to Stripe and are never stored on our systems.
  • Contributors — the name and mobile number you enter yourself when you join a family through an invite link, and the photos and messages you send us.
  • Children — a first name, and photos or messages submitted on a child's behalf by a parent or guardian. See 'Children's information' below for what we do and do not ask when someone joins.
  • Recipients — the household name and mailing address supplied by the account holder, so a postcard can be printed and delivered.
  • Technical and advertising information — IP address, device and browser information, cookie or similar identifiers, pages viewed, referring links, timestamps, and actions such as starting checkout, registering, or purchasing. We also keep server logs and error diagnostics needed to operate and debug the service.

Sensitive personal information

Family content may include information about children or other information a family considers private. We treat that information with additional care whether or not a particular law classifies it as sensitive personal information.

We use family content to provide and support the FamilyLetter service. We do not use it to infer characteristics for advertising. You may contact us to ask about or limit our use of information you consider sensitive, and we will explain what we can do and how that may affect the service.

How we use information

We use family information to operate and support the service: to verify participants, collect and store contributions, assemble postcard previews, let the account holder review and approve them, process payments, provide support, and keep the service secure. When recurring messaging or print fulfillment is enabled, we also use the information needed to send service messages and produce and mail approved postcards.

On a limited set of marketing and measurement pages, we use browser and server-side tools to measure Meta and TikTok campaigns, attribute registrations and purchases, improve ad delivery, and reach audiences that may be interested in FamilyLetter. For Meta measurement, we may share securely hashed account-holder or purchaser contact identifiers, an opaque account identifier, purchaser billing city, state, postal code and country, purchase amount, advertising click and cookie identifiers, IP address and browser information. We do not share family photos, messages, children's information, recipient information or mailing-destination data for advertising. Meta and TikTok may combine permitted information with information they already hold, subject to their own privacy policies.

We do not sell personal information for money. Our disclosure of technical and advertising information to Meta and TikTok may be considered a sale, sharing for cross-context behavioural advertising, or targeted advertising under some state laws. You can opt out through the 'Your Privacy Choices' link in the footer or a browser Global Privacy Control signal. We do not use family photos, messages, children's information, recipient names or mailing addresses in advertising or to train machine-learning models.

Advertising cookies and your choices

Meta Pixel and TikTok Pixel use cookies and similar technologies on selected pages. Meta's Conversions API may also receive matching and conversion information from our server when a registration, checkout or verified purchase occurs. These tools help us understand whether an ad led to a visit, registration or purchase, optimize campaigns, and support audience measurement or retargeting.

These tools operate by default on the limited pages and events described above. Select 'Your Privacy Choices' in the footer to disable future advertising tracking and server-side advertising disclosures associated with that browser or signed-in account. Opting out does not affect the price or service you receive. Clearing browser storage may remove a device-level choice, but an account-level choice remains effective when associated with your account.

We treat a browser Global Privacy Control signal as a request to opt out, so advertising pixels remain off and server-side advertising disclosures are suppressed while that signal is enabled.

We currently use text messages to verify mobile numbers. FamilyLetter may also send recurring service prompts when that feature is enabled, but only to a person who enters and verifies their own number and agrees to receive those messages. An account holder shares an invite link rather than giving us someone else's number. Messages may be sent using automated technology.

All the above categories exclude text messaging originator opt-in data and consent; this information won’t be shared with any third parties.

You can revoke consent to recurring messages at any time. Reply STOP — or cancel, end, quit, unsubscribe, revoke or opt out — or contact us by another reasonable method. We will process the request promptly and within the period required by law.

We retain enough information about an opt-out to avoid resuming recurring messages without new consent. A person may later choose to opt in again where permitted.

Message and data rates may apply. Message frequency varies with family activity, up to seven messages per monthly postcard cycle for each family, plus one confirmation when a person opts in.

If you are receiving messages you did not expect — for example because a number was mistyped when someone joined — reply STOP or contact us and we will remove the number straight away.

Children's information

FamilyLetter is intended for adults and is not directed to children. The intended way to include a child is for a parent or guardian to add them to the family and submit a photo or a few words on their behalf.

We do not ask a joining contributor for their age. Account holders should not share the family invite link with a minor, and we rely on them not to. We do not knowingly collect a mobile number directly from a child. If we learn that a child joined directly, we will stop messaging that number and take reasonable steps to remove the child's direct-participant information. A parent or guardian who believes their child joined can contact us.

We do not capture, scan or model anyone's handwriting. Where a postcard appears handwritten, that is one of a set of preset typefaces chosen by the family — no sample of a real person's writing is collected.

We use a child's information solely to produce that family's postcards. We do not make children's photos or messages public, do not use them for advertising, and do not disclose them to third parties for any purpose that is not integral to printing and mailing the postcard.

A parent or guardian may at any time review the information we hold about their child, ask us to correct or delete it, refuse to permit any further collection, and end the child's participation. Contact us and we will verify the request and act on it. Deleting a child's information may mean we can no longer include that child in future postcards.

How long we keep information

Retention depends on the information, the feature involved, and whether the account is active. We may also retain records when reasonably necessary for security, dispute resolution, legal compliance, consent records or suppression of unwanted messages.

  • Family content — generally kept while the account is active so postcards remain available within the service. You may contact us to request deletion, subject to legal, security, backup and operational limitations.
  • Children's information — kept only for as long as reasonably necessary to support the family's use of the service or another permitted purpose. A parent or guardian may request review, correction or deletion.
  • Contributor records — may remain after participation ends to preserve postcard history, document consent, secure the service, and honor messaging opt-outs. Access to inactive records is restricted.
  • Account and billing records — retained as needed for account administration and for tax, accounting, dispute and legal purposes.
  • Technical logs — retained according to operational, security and provider requirements, then deleted, de-identified or aggregated when reasonably practicable.

Service providers and contractors

We use the following providers to run the service. Each receives information needed for its function under our agreements with it. This list covers service providers and contractors; Meta and TikTok are separately described as advertising partners above because they may also process advertising information under their own policies.

  • Supabase — Database and file storage
  • Vercel — Website and application hosting
  • Stripe — Subscription payments. Card details go to Stripe, not to us
  • Telnyx — Mobile-number verification and, when enabled, service text messages
  • Lob — Printing and mailing postcards when fulfillment is enabled
  • Google Places — Address autocomplete and validation

Other disclosures

We may disclose information where we are legally required to, to enforce our terms, to protect the rights or safety of a person, or in connection with a merger or sale of the business — in which case we will tell account holders and the buyer remains bound by this policy.

Your privacy rights

Depending on where you live, you may have the right to know what we hold about you, to get a copy of it, to have it corrected or deleted, to limit our use of sensitive personal information, and to opt out of sale, sharing, targeted advertising or certain profiling. You can opt out of advertising disclosures with the 'Your Privacy Choices' link or a Global Privacy Control signal. You also have the right not to be treated differently for exercising a privacy right.

To exercise a right, contact us using the details below. We will verify your identity before acting, which usually means confirming control of the email address or phone number on the account. An authorised agent may act for you with written permission.

If we decline a request, we will explain why, and you may appeal by replying to that decision. Residents of several states have a right to appeal and, if still dissatisfied, to complain to their state attorney general.

Security

Family photos are stored privately rather than at publicly reachable URLs, access is limited to what is needed to operate the service, and payment card details never reach our systems. No system is completely secure. If a breach materially affects you, we will notify you as required by law.

Where we operate

The service is intended for use in the United States, and information is processed there. We do not knowingly offer the service to people outside the United States.

Changes and how to contact us

If our practices change we will update this page and the effective date above. Where required by law, we will provide additional notice of a material change.

For questions about this policy, or to make a request about your information or your child's information, contact support@familyletter.io. Our postal address is 347 Berry Street, Brooklyn, NY 11249.