Privacy
What we keep, where it sits, and who is able to see it.
What we keep
When you make a page we keep your name and the email address you sign in with.
The page holds what you put on it: the baby’s name if you give one, the month they are due, the colour you picked, the birth date once you announce it, and the web address of your registry if you add one.
When someone writes on your page we keep their name, an email address or phone number so you can thank them, how they know you if they say, and the words they wrote.
We keep the photos and the story entries you add, along with the day each one is of and anything you wrote under it.
We keep the email addresses you type in to invite people, and your settings for which emails you want.
We keep a count of how many people followed the registry link on your page. It is a number for the page, with nobody attached to it.
What we do not keep
We never ask how a pregnancy came about, and there is no field for it anywhere in the product.
We do not ask for health information of any kind.
Photos have their metadata removed before they are stored, including the location a camera writes into the file. That happens in your browser as the photo is prepared, and again on our side when it arrives.
We do not buy information about you from anybody.
Where it lives
The words live in a Postgres database run by Supabase, on servers in the United States.
The photos live in Cloudflare R2 storage. That store has no public web address. Every photo is served through a short-lived link that checks who is asking before it hands anything over.
Email is sent through Resend. The site itself runs on Cloudflare.
Who can see it
You choose who can open your page. It can be only the people you invited, or anyone holding a link you sent, or anyone who has the address.
The story, meaning the photos and the dated entries, is only ever visible to people you invited as members. That holds in every setting, with no exception and no switch to turn it off.
Pages are never listed in search results. Every page carries the instruction that keeps crawlers out, and the whole address range is disallowed as well.
The email address or phone number somebody leaves with a message is for you. It is shown to you on your own screens and it never appears on the page.
Cookies
One cookie keeps you signed in.
If you open an invitation link, a second cookie remembers it for twelve hours so you do not have to find the link again.
We count page views with PostHog so we know which screens people use. The web address is replaced with a blank template before anything is sent, so the count never carries a baby’s name or a link to a family’s page. PostHog keeps a cookie in your browser to avoid counting you twice. Nobody is identified and nothing you do on a screen is recorded.
Keeping and deleting
We keep what you put here until you take it away.
Today you can hide or delete a message on your page, delete a photo, remove somebody from a page, and pause the whole page.
Deleting your account is not something you can do for yourself yet. Write to hello@elliepost.com and we will delete your account and everything on your pages by hand, and write back when it is done.
If you wrote a message on somebody else’s page and want it taken down, write to the same address. We will take it down even if you have already left that page.
Children
ElliePost is made for adults. You need to be 18 to make a page or to write on one.
The photos on a page are of children, and they are there because a parent put them there. We do not run facial recognition, nothing is tagged automatically, and no photo is used to train anything.
If this changes
When any of this changes we will change the date at the top of this page. The terms say what you agree to, and the page about registry links says whether we earn anything from them.