This policy explains what Bearletter collects, why, and what you can do about it. Bearletter is operated from Champion Tower, Three Garden Road, Central, Hong Kong. It applies to writers who use Bearletter and to readers of blogs hosted on it. See also our Terms of Service.
Writers
- Account: your email address, the name and profile details you add, and your settings.
- Content: drafts and their published versions, blog files, thoughts, uploaded media, and the settings of your blogs and mailing lists.
- Billing: if you buy Pro, Stripe collects your payment details; we never see or store your card number. We keep your Stripe customer ID and the status of your subscription.
- Sign-in: cookies that keep you logged in to the dashboard. They are the only cookies we set, and blogs set none.
The dashboard also keeps unsaved text and a few preferences, such as your theme, in your browser’s local storage. They stay on your device.
Readers
- Visit statistics (Pro blogs that keep them on): the page, the site you came from (its domain only), your country, and your device and browser type. To count a reader once per page per day we use a keyed hash of your IP address that changes every day. Your IP address itself is never stored, and no cookie is used.
- Likes: to allow one like per post, we store a keyed hash of your IP address that changes every year.
- Subscribing: if you join a writer’s mailing list, we store your email address, when you subscribed and confirmed, and when you unsubscribe. The writer decides what the list is for and can see and export it. Every email has a link to unsubscribe, which keeps working even if the writer’s plan changes.
How we use it
- to run the service: sign you in, save and publish your work, show blogs to readers, and send emails you asked for — sign-in codes, subscription confirmations, and notices about your account such as media retention dates;
- to handle billing and keep your plan in sync with Stripe;
- to keep Bearletter secure and prevent abuse.
We don’t sell personal data or show ads.
Who processes it
- Cloudflare hosts the service, its database and file storage, and delivers our email. Data may be processed in any country where Cloudflare operates; the main database is in North America.
- Stripe processes payments.
We share data with others only if the law requires it or to protect the service and its users from harm.
How long we keep it
- Account data and content are kept while your account exists. Things you delete are removed from the service; database backups that may still contain them expire within 30 days.
- After moving from Pro to Free, uploaded media is removed after 30 or 90 days, as described in the Terms.
- When a subscriber is deleted from a list, we keep their email address only so they aren’t added back without confirming again.
Your choices and rights
- Export your blog, media and mailing lists at any time from the dashboard.
- Turn visit statistics off for your blog in its settings.
- Ask us to access, correct or delete your data, including closing your account, by writing to hello@bearletter.com from the address you sign in with.
Depending on where you live, you may also have the right to object to processing or to complain to a data protection authority.
Children
Bearletter isn’t meant for anyone under 16, and we don’t knowingly collect their data.
Changes
If we change this policy in a way that matters, we will tell you by email or in the app before it takes effect.
Contact
Questions or requests about privacy: hello@bearletter.com.