dear.youBack home

dear.you

Privacy policy

Effective July 27, 2026

This policy explains what personal data dear.you uses to store and deliver private video letters, and the choices available to you.

Who is responsible for your data

Mobile Apps Raw Company is the data controller for dear.you. Privacy requests can be sent to contact@rawmobile.app.

Data we collect

  • Draft and order details: when the sender selects “Next” on the first step, we save their email address, the recipient name, occasion, and chosen availability date. If they continue, we also save the recipient email address and order status.
  • Content: the private video or audio-video file you record or upload, including its format, size, and duration.
  • Payment information: Stripe Checkout session and payment status. Stripe and its Link service receive payment-card, billing, and transaction-support information directly; we do not receive complete card numbers.
  • Technical and security information: IP address, device and browser information, timestamps, and service logs generated when you use the site.
  • Product progress information: a random flow identifier, campaign attribution when present, and milestone timestamps such as opening the creation flow, saving details, preparing a recording, uploading the video, opening Checkout, and completing payment. We do not record form keystrokes or private video content as analytics events. After details are saved, the flow may be linked to the corresponding draft or order for support and funnel analysis.
  • Optional advertising measurement data, if you consent: page, Checkout, and purchase events; page URL; purchase value and currency; Meta browser identifiers; IP address; browser information; and a one-way hashed version of the purchaser's email for Checkout and purchase matching.
  • Support information: messages and information you choose to send when contacting us.

Why we use it

  • To create, store, secure, and schedule your private video letter, set up and troubleshoot an incomplete order, support manual delivery during early access, and provide order support. These steps are necessary to take action at your request before entering into a contract and to perform our contract with you.
  • To process payment, prevent fraud, maintain accounting records, and meet legal obligations.
  • To protect dear.you, diagnose errors, and improve service reliability, based on our legitimate interests in operating a safe and dependable service.
  • To send marketing or use non-essential advertising technology only when we have a valid legal basis and any consent required by law.
  • If you consent, to measure Meta advertising performance, attribute visits and purchases to campaigns, limit duplicate reporting, and build advertising audiences.

Who receives data

We disclose only the data needed for each provider to perform its service:

  • Incomplete first-step drafts that are not linked to an uploaded recording are ordinarily deleted within 30 days.
  • Stripe and Link process Checkout payments, applicable indirect taxes, fraud signals, receipts, and transaction-level support.
  • OpenAI Sites and Cloudflare provide application hosting, database, private object storage, content delivery, and security.
  • Meta receives optional browser Pixel and server-side Conversions API events when you consent to advertising measurement.
  • Professional advisers and public authorities may receive data where reasonably necessary or legally required.

We do not sell personal data. We do not send Meta the private recording, recipient name or email, occasion, message content, or chosen availability date.

International transfers

Some providers process data in the United States and other countries. Where European data-protection law applies, transfers are protected using an approved transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses, together with supplementary safeguards where required.

How long we keep data

  • Recordings uploaded without a completed payment are kept only for a short checkout-recovery period and are ordinarily deleted within 48 hours.
  • Paid recordings and delivery details are retained through the chosen availability date and manual delivery period. After the recipient's download is confirmed, the recording may be kept for up to 30 additional days for recovery and support.
  • If download is not confirmed, we may retain the recording while completing reasonable manual delivery attempts. The sender can ask us to delete it at any time, subject to mandatory legal retention.
  • Transaction, tax, fraud-prevention, and support records are kept only for the periods required by law or reasonably necessary to establish, exercise, or defend legal claims.
  • Product-progress events are ordinarily retained for up to 90 days so we can understand where people encounter difficulty in the creation and payment flow.

Your choices and rights

Depending on where you live, you may ask to access, correct, delete, restrict, or receive a copy of your personal data; object to or withdraw consent for certain processing; and opt out of targeted advertising, sale, or sharing where applicable. You will not be discriminated against for exercising a privacy right.

You can decline optional Meta tracking when first asked or change your decision at any time using the “Privacy choices” control on the site. Declining does not affect recording, storage, or payment.

Send a request to contact@rawmobile.app. We may need to verify your identity and authority before acting. You may also complain to the CNIL or the privacy regulator where you live.

Children and recipient information

Purchasers must be at least 18. Recordings may not depict a person under 18. A future recipient may be a minor, but the purchaser must have authority to provide the recipient information and should use a parent or guardian's email address for delivery.

Cookies and similar technology

dear.you uses essential technology to operate, secure, and complete Checkout. Stripe and Link may use their own essential fraud and payment technology on Stripe-hosted pages.

With your permission, we also load the Meta Pixel and use Meta's Conversions API. These tools use cookies or similar identifiers to connect ViewContent, InitiateCheckout, and Purchase events with Meta advertising. Browser and server events share an event identifier so Meta can count one action once. Optional identifiers used for Checkout attribution are removed from our order record after the purchase event is successfully sent.

Security and changes

We use access controls, encrypted transport, private object storage, and service-provider safeguards designed to protect recordings and personal data. No online system can be guaranteed completely secure.

We may update this policy as the service or law changes. Material changes will be identified on this page and communicated where required.