Last updated: May 2026
When you create a card, we store the content you enter (recipient name, your message, card type) and the email address you provide at payment. We also store the Razorpay order/payment ID and a session cookie to let you resume drafts.
When someone opens a card, we record a timestamped open event (no personal data beyond a hashed IP address).
Card content is used only to generate and display the recipient’s card. Email addresses are used to send you a magic link (your card access link) and, if you opt in, to send the card to your recipient. We do not share your data with third parties except as necessary to operate the service (Razorpay for payments, Resend for email, Supabase for storage).
Cards and associated data are retained for 12 months after creation, then permanently deleted. Draft cards (unpaid) are deleted after 7 days.
We use a single session cookie (anonymous, 7-day expiry) to identify your browser session. We do not use tracking or advertising cookies.
So you can find a card again after closing the page, we save a list of the cards you create in your browser’s local storage — the card’s short code, the recipient’s name, the date, and an access key. This never leaves your device and we cannot read it. It powers the “My cards” page.
Because it is stored on the device rather than behind a password, anyone who can unlock this browser can open those cards. Clear your browser’s site data to remove the list; your cards themselves are unaffected.
You may request deletion of your card and associated data at any time by emailing support@whatheartsays.com. Include the card link (whatheartsays.com/c/…) in your request.
Questions about privacy? support@whatheartsays.com