What we collect and what we don’t.
PenPigeon is run by one person. This page is written to be read, not to cover us. If something here is unclear, email support@penpigeon.com.
Last updated: September 2026
The short version
- The free Create tool runs entirely in your browser. Your photo and note are never sent anywhere unless you sign in and place an order.
- To send a real postcard we need your email, the photo for the front, your note and the recipient’s mailing address. We keep those to make and mail the card and to show you your order history.
- Card details go straight to our payment processor. We never see or store your full card number.
- Delete your account and everything tied to it is removed.
- We don’t sell your data and we don’t run advertising trackers.
What we collect
When you just browse
Our host (Cloudflare) logs standard request data, your IP address, the pages you request, your browser type, for security and to keep the site up. We don’t add our own analytics or advertising cookies. The only thing we store in your browser is a small preference for light/dark theme.
When you create an account
- Email address, for signing in, order confirmations and password resets.
- If you sign in with Google, Google shares your email address and basic profile (name, profile picture) with us. We only use the email.
- A password, if you don’t use Google, stored hashed by our auth provider, never in plain text.
When you set up your handwriting
You can upload one photo of your own handwriting. We store that photo and a derived “font” (a set of letter shapes) so you can reuse it on future cards. It’s private to your account.
When you place an order
- The photo you choose for the front and how you framed it.
- Your note, the text drawn on the back.
- The recipient’s name and mailing address and your return address if you add one.
- Payment, your card is handled by Stripe. We receive only a confirmation, the card brand and the last four digits so you can recognise a saved card.
- The finished files we generate for that order (images of the front and back, the pen path, a print PDF), plus a log of the order’s progress.
Who we share it with
We use a small number of service providers to run PenPigeon. They only get the data they need to do their job and they aren’t allowed to use it for anything else:
- Supabase, database, file storage and login. This is where your account, handwriting and orders live. (Hosted in the United States.)
- Cloudflare, serves this website and sits in front of our servers.
- Stripe, processes card payments.
- Resend, sends our emails (order confirmations, password resets).
- Google, only if you choose “Continue with Google” to sign in.
- The United States Postal Service, we print the recipient’s address on the card and hand it to USPS for delivery.
To actually make your postcard, a person (currently just the operator of PenPigeon) prints your photo, runs the pen plotter over your note, addresses the card and mails it. Your recipient’s address is necessarily seen by that person and by USPS.
We will also disclose data if the law requires it, or to protect PenPigeon or someone’s safety.
How long we keep it
- Account, handwriting, saved cards, until you delete them or close your account.
- Order records and generated files, kept while your account is open so you can re-download them. Basic records of a completed sale (date, amount) may be kept longer where we’re required to for tax and accounting.
- Emails we send, Resend keeps delivery logs for a limited period on their side.
Deleting your data
In your account, Account → Delete my account removes your login, your saved handwriting, your orders and every uploaded file. This is immediate and can’t be undone. If you can’t sign in, email support@penpigeon.com from your account address and we’ll do it for you.
Your rights
You can ask us to show you what we hold about you, correct it, or delete it, email support@penpigeon.com. If you’re in the EU, UK, or a US state with a privacy law (California and others), you have those rights under that law too, including the right to complain to your local regulator. We don’t sell personal information and we don’t “share” it for cross-context advertising.
Children
PenPigeon isn’t intended for anyone under 16. We don’t knowingly collect data from children. If you believe a child has given us information, email us and we’ll remove it.
Security
Data is encrypted in transit (HTTPS) and at rest by our providers. Uploaded photos and generated files are stored in private buckets that require a signed link to access. No system is perfectly secure, but we keep the amount we collect small on purpose.
Changes
If we change this policy in a way that matters, we’ll update the date at the top and, for material changes, email account holders. Continuing to use PenPigeon after a change means you accept it.
Contact
PenPigeon support@penpigeon.com
This is a plain-language draft written by the person who built PenPigeon. It is not legal advice. If PenPigeon starts taking real payments and mailing real cards at any volume, have a lawyer review this and the Terms.