Privacy Policy
Last updated: July 16, 2026
This Privacy Policy explains what we collect, why, and your choices.
1. Information We Collect
Account Information: When you create an account, we collect basic information such as your email address, name, and profile details to create and manage your link-in-bio page.
Sending a Message (Sender Privacy): Sending is anonymous to the recipient, not untracked. When you send an anonymous message, we record connection and device metadata: your approximate, IP-based location (see "How We Estimate Location" below), timezone, network/ISP (ASN), whether you appear to be using a VPN, proxy, or Tor, your browser, operating system, device type, language, screen size, and a device fingerprint combining signals such as WebGL and graphics traits, installed fonts, and the full browser user-agent string — used to detect ban evasion and abuse, not to identify a real person. The recipient never sees your name, email, or identity. A paid recipient may see a coarsened subset of these signals presented as anonymous "hints" (for example, a city or "VPN detected") — never a value that identifies you. The underlying data is retained so we can enforce safety and respond to lawful requests.
Messaging Data: When someone sends you an anonymous message, we collect the message content along with the sender metadata described above, so we can protect our users and give you context.
Threading & Repeat-Contact Signals: To group a back-and-forth into a single conversation and to spot coordinated abuse, we record a session identifier and a count of how many times a given sender has contacted you. These are used only for threading and safety.
Guest Accounts: The first time you send a message, we create a temporary guest account so we can thread the conversation and notify you if the recipient replies. If you never create a full account, that guest account and its data are automatically deleted within 30 days.
Notifications: If you enable push notifications, we store the browser push subscription needed to send them. We use your account email to send message and reply notifications, which you can turn off at any time.
Usage & Analytics Data: On logged-in surfaces such as your dashboard, we collect anonymized product-analytics data on how features are used to help improve the say4real experience. We do not run product analytics on public profile or message-send pages. See "Cookies & Analytics" below for details.
Link and Visit Analytics (LinkBlip): When someone opens your say4real page or clicks one of your links, a paid creator can see it on the LinkBlip. We record the event with an approximate, IP-derived location (never GPS or precise location — see "How We Estimate Location" below), device type, browser, and the referring site. We rely on our legitimate interest in giving creators audience insight; the data is coarse and the visitor key is used for unique-visitor counting within one creator's audience, not real-world identification. We honor the Global Privacy Control (GPC) and Do-Not-Track browser signals — if either is set, we record nothing. Pro click data is kept for 7 days and Creator data for up to 1 year, after which it is deleted.
Payment Information: If you subscribe to Pro, your payment is handled by our Merchant of Record (authorized third-party reseller), which may use Stripe as its underlying card processor. They collect and process your payment details directly under their own privacy policy — we do not receive or store your full card number.
2. How We Estimate Location
All location data we hold — country, region, city, postal code, and any approximate map coordinates — is derived from the sender's or visitor's IP address through a third-party lookup service. We never use GPS or device location. An IP-based location is a coarse estimate: it is typically accurate only to a city or region, and the coordinates we store are a centroid for that area that can be off by many kilometres. It is never the person's exact position.
3. How We Use Your Information
We primarily use your data to operate the say4real service. This includes delivering messages to your dashboard, generating your personalized link page, and offering auto-generated story graphics based on activity.
Crucially, we also use metadata (like IP boundaries and device signatures) to enforce our Safety Policy. We employ this data alongside AI models to automatically flag, filter, and shadow-ban bad actors who attempt to use our platform for harassment.
4. Cookies & Analytics
We keep our use of cookies and analytics minimal. On logged-in surfaces such as your dashboard, we use PostHog for product analytics; it sets cookies and localStorage values to tell devices apart across visits. We do not load product analytics on public profile pages or the anonymous message-send page. Session recording, autocapture, and heatmaps are turned off. We do not use advertising or cross-site tracking cookies.
5. Data Sharing and Sub-processors
We do not sell, rent, or trade your personal information to third parties. To run the service we rely on a small set of trusted sub-processors, each bound by confidentiality obligations and used only for the purpose listed:
- Vercel — application hosting.
- Turso — encrypted database.
- ip-api.com — IP geolocation and VPN/proxy detection; the IP address is transmitted to perform the lookup.
- OpenAI — message content is sent to score it for abuse and toxicity.
- PostHog — product analytics on logged-in surfaces only.
- Resend — transactional and notification email.
- Stripe and/or our Merchant of Record — payment processing (see Payment Information above).
- CARTO — map basemap tiles, requested from your browser when you view the visitor map.
We will also disclose information if required to do so by law or in the good faith belief that such action is necessary to comply with legal obligations or protect the rights and safety of say4real, its users, or the public.
6. Data Security
Message content and sender data are encrypted at rest (AES-256-GCM) under a separate encryption key for each account. Values required for safety matching (rate limiting, bans, thread grouping) are stored as one-way keyed hashes rather than raw identifiers. Our servers decrypt data as needed to operate the service — for example to run moderation, deliver notifications, and render your inbox.
7. Your Privacy Rights
You have full control over your profile and can permanently delete your account, and by extension your message inbox and personal data, at any time through your dashboard settings. Deleting your account destroys its encryption key, rendering the encrypted data permanently unrecoverable — including by say4real. Residual copies inside our encrypted database backups age out automatically within 30 days at most; after that, nothing remains anywhere.
Depending on where you live, you may have the right to access, correct, delete, export, or object to our processing of your personal data; deleting your account satisfies a request for erasure. We do not sell or share your personal information as those terms are defined under the California Consumer Privacy Act (CCPA). To exercise any of these rights, contact the data controller, say4real, at contact@say4real.com.
8. Children's Privacy
say4real is not directed to, and not intended for, anyone under 13 — or under the minimum digital-consent age where they live, which is higher in some places (for example, 16 in parts of the European Union). When you create an account we ask for your birth year to confirm eligibility; if it shows you are under 13 we do not create the account and delete the data gathered during that attempt. For accounts under 18, the anonymous message inbox and public Q&A are turned off. We do not knowingly collect personal data from children under 13, and we remove accounts we learn belong to underage users.
9. Embedding
You can embed your public profile on other websites. When your profile is embedded, it loads inside an iframe on that site; a message sent from an embed is processed exactly like one sent on say4real, including the safety metadata described above. We use partitioned cookies scoped to the embedding site so a logged-in sender can be recognized without sharing your session across unrelated sites.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or your data, please contact us at contact@say4real.com.