Privacy Policy

Last updated 2026-08-02 · Beta terms — will be revised before general availability.

1. Who we are

Postly ("Postly", "we", "us") operates postly.now, a trust protocol for posting documents to a permanent address (a Postly Number). Postly is currently in private beta. This policy explains what data we collect, where it is stored, and how you can request its deletion.

2. What we collect

  • Account information — your email address, password (hashed, never stored in plain text), and any name you provide.
  • Organization details — the Mailroom/organization name and information you supply when claiming a Postly Number.
  • Documents you post — the PDF and JSON metadata of every Envelope posted to a Postly Number, plus the resulting append-only timeline of trust events.
  • Session and device data — IP address, device/browser identifiers, and session cookies, used for authentication and abuse prevention.
  • Communications — messages you send us at hello@postly.now or through in-app support.

3. Where data lives

Postly runs on Cloudflare's infrastructure (United States region) for compute (Cloudflare Pages/Workers), object storage (R2), and network/CDN services. Application data — accounts, organizations, Envelopes, and timelines — is stored in a PostgreSQL database cluster accessed via Cloudflare Hyperdrive. Uploaded documents are stored in Cloudflare R2 object storage.

4. Subprocessors

We share data with the following categories of service providers, only as needed to operate Postly:

  • Cloudflare — hosting, CDN, object storage (R2), and database connectivity (Hyperdrive).
  • Postal (self-hosted) — our self-hosted transactional email system, used to send account, notification, and Envelope-related emails. We do not use a third-party email marketing platform.
  • PostgreSQL host — the managed database cluster underlying application data.

We do not sell personal data, and we do not use third-party advertising or ad-tracking pixels on Postly.

5. How we use data

  • To operate your account, organization, and Postly Number;
  • To deliver, receipt, and timeline Envelopes posted to a Number;
  • To send transactional email (verification, notifications, receipts);
  • To secure the service against fraud, abuse, and unauthorized access;
  • To respond to support requests you send us.

6. Retention

Envelope documents and their timelines are retained consistent with Postly's permanence promise — an Envelope's record at a Postly Number is meant to be durable and is not silently deleted or altered, since that append-only guarantee is the product itself. Session data, authentication logs, and device/IP records are retained only as long as needed for security and abuse-prevention purposes and are periodically purged. Account and organization data is retained for as long as your account is active, or as described in Section 7.

7. Deletion requests

You may request deletion of your account and associated personal data by emailing hello@postly.now. We will act on verified requests as promptly as we can. Note that Envelope timelines tied to a Postly Number reflect trust events involving other parties (Senders, Keepers, Readers) and, per Section 6, cannot be selectively rewritten — deletion requests affecting shared records will be handled on a case-by-case basis, and we will explain any limits that apply.

8. Security

Passwords are hashed with a strong key-derivation function and a server-side pepper; sensitive settings are encrypted at rest. Access to production data is limited to the people operating the service. No method of transmission or storage is perfectly secure, and as a beta service we make no guarantee beyond reasonable, good-faith effort.

9. Changes to this policy

We may update this policy as the product evolves, especially during the beta period. We will update the "Last updated" date above when we do.

10. Contact

Questions about this policy, or requests to access or delete your data, can be sent to hello@postly.now.