Privacy Policy
Postcards for iOS · Effective 30 July 2026
Postcards has no accounts. You never tell it who you are, and it never asks. This page describes exactly what the app does with your data, in the order the app does it.
The app is published by Dobreon sp. z o.o. If anything here is unclear, write to support@dobreon.com.
What stays on your phone
Your cards, your photos, your handwriting and the shoebox live on the device and are not uploaded anywhere — unless you choose to send a card as a link, which is covered below.
- Photos. You pick photos through the system picker, which hands the app only what you selected. The app does not hold permission to read your photo library. It asks for add-only access, and only at the moment you tap “Save to Photos”.
- Location. The app never asks for your location at launch. If you tap “Where I am now” in the postmark editor, iOS asks once, and the coordinates are turned into a place name on the device using Apple’s own geocoder. A photo’s own coordinates, if it has any, are read the same way. Neither the coordinates nor the place name are sent to our servers. They end up printed into the card as pixels, and only if you put them there.
- Handwriting and text. Never transmitted as text. See below.
What happens when you send a card as a link
Sending a link is the only thing that puts a card on our servers, and it uploads two flat images — the front and the back, already flattened. Your message, your handwriting, the names you wrote and any postmark are printed into those images on your phone before anything leaves it. There is no field on our server that could hold what you wrote, because it arrives as pixels.
Alongside the two images we store one small row:
- a random 22-character link id, not derived from you, your device or the time;
- the date it was created and the date it expires;
- the card’s shape and the language the app was in;
- a one-way hash of the link’s edit token, so “unsend” can be authorised;
- a one-way hash of a random installation identifier, used only to stop one device flooding the service;
- how many times the link has been opened, and when it was first opened.
Both hashes are SHA-256 with a secret held only on the server, so a copy of the database cannot be turned back into device identifiers. We do not store IP addresses. The images sit in private storage and are reachable only through short-lived signed links.
How long it is kept, and how to take it back
- Links from the free tier expire 30 days after they are made. With Postcards Pro they expire after a year.
- You can unsend any card at any time from the app. The images are deleted and the link stops working immediately.
- Expired cards are deleted by a nightly job.
A card you send is readable by anyone holding the link, in the same way a real postcard is readable by anyone who handles it. Send links to people you mean to send them to.
Purchases
Payment is handled entirely by Apple. We never see your card number, your Apple Account or your billing address.
To know whether a subscription is active we use Adapty, a subscription platform. Adapty receives a randomly generated profile identifier for the install, your purchase history for this app, which paywall was shown, and its own error diagnostics. It is configured so that it does not collect the advertising identifier and does not collect your IP address. None of it is linked to a name, an email address or an account, because the app has none.
What we do not do
- No accounts, no sign-in, no email address collected.
- No advertising, no advertising identifier, no tracking across apps or websites.
- Your data is never sold, and never shared for anyone else’s marketing.
- No analytics on what you draw, write or photograph.
Children
The app is rated 4+ and needs no personal information to work. We do not knowingly collect personal data from anyone, at any age.
Your rights
Because there are no accounts, the data described here cannot be looked up by person — that is the point of the design. What you can do at any time: unsend a card, which deletes it; or delete the app, which removes everything held on the device. For anything else, including questions under the GDPR, write to support@dobreon.com and include the card link if your question is about a specific card.
Reporting a card
Every card page has a “Report this card” link. Reports go to support@dobreon.com and a card that breaks the Terms is taken down.
Changes
If this policy changes, the effective date above changes with it, and material changes will be noted in the app’s release notes.