Legal
Privacy policy.
You are trusting us with photographs of weddings and of people you have lost. This page says exactly what happens to them, in the same plain words we would use if you asked in an email.
In effect August 9, 2026
The short version
We collect what is needed to print your cards, post them, and keep the page they open working. We do not sell your data, we do not run advertising trackers, and we do not use your photographs or video in our own marketing. There is no cookie banner on this site because there is nothing on it that would need one.
What we collect
When you order — your name, shipping address, email address, what you are making, and the date you need it by. Your card number is not among it: payment details go straight from your browser to Stripe and never touch our server.
When you make an account — your email address and a password, which is stored only as a hash. You can sign in with a one-time link instead and never set one.
What you put on the card — the photographs you upload, the words you choose, and the video or link the card opens. This is the material the whole product exists to handle, and it is treated accordingly.
What you type to the design assistant — see the section below, because it leaves our servers.
When somebody taps a card — the date, the country, and a broad device family such as "iPhone". That is the entire record. No IP address, no identifier, and nothing that can be traced to the person who tapped. It is what makes the owner's "tapped 47 times this month" box possible, and it cannot tell you or us who did the tapping.
Your IP address, briefly — used as a counter key to stop a script hammering the upload, design and payment endpoints. The counters expire on a timer measured in hours and are never joined to your account, your order, or anything else.
Optional feedback — if you tell us how you found Dote, we save your answer with your order to understand how customers discover us. This is separate from anonymous site analytics. If you leave a review, we link it to your purchase to verify it. Your rating, review, and chosen public name may be published; your email address and order details are not part of the public review. You can stop review-request emails using the link in those messages without stopping essential order emails.
The design assistant sends what you write to Anthropic
When you describe the card you want, that text is sent to Anthropic's API to generate the designs you are shown. If you write "for my father's funeral in March", that sentence goes to Anthropic. We are telling you because you would reasonably want to know.
Anthropic processes it to return the designs and, under its commercial terms, does not use it to train its models. Your uploaded photographs are not sent — the assistant works from your words and lays out the design; the picture is placed by our own code, on our own servers.
Photographs and videos your guests upload
If you switch on guest uploads for an occasion page, we store the photographs and videos your guests submit so you, the card owner, can approve them before anyone else sees them. You can instead choose to let uploads appear on the page as they arrive, without waiting for you — if you do, know that a video cannot be automatically screened before it is shown, only after, the way a photograph can. Guests are not asked for a name, an email address or an account, and we do not collect one.
You can reject or delete any of it, and deleting removes it from storage. If you are a guest who wants something taken down, write to [email protected] and we will remove it without asking you to prove anything.
Who else touches it
Five companies, each doing one job, none of them permitted to use your data for their own purposes:
- Stripe — takes the payment. Card details go to Stripe directly, not through us.
- Supabase — the database holding accounts, orders and designs.
- Cloudflare — serves the site and stores the uploaded photographs and video.
- Anthropic — generates card designs from what you type, as described above.
- Resend — sends your receipt and your shipping notice.
Beyond those, we share personal information only where the law requires it. We have never sold personal information and we do not share it for cross-context behavioural advertising — the two things California law asks a business to state plainly.
Cookies, and why there is no banner
Signing in does not set a cookie; your session is kept in your own browser's local storage. The site sets exactly two cookies and neither one follows you:
- A session cookie for the operator console, which only we can log into.
- On a password-protected card page, a cookie remembering that the correct password was entered, so a re-tap within twelve hours does not ask again.
Both are strictly necessary, which is why you are not being asked to consent to them. There are no analytics cookies, no advertising pixels, and no third-party scripts on the page your card opens — that page runs no JavaScript at all.
What we count
We do count how the shop is used, because otherwise we are guessing. It is our own counting, on our own servers, and it is deliberately built so that it cannot identify you:
- Which page was opened, and which step you reached — the designer, the cart, checkout, an order.
- Which site sent you here, if any, and the campaign label on the link you clicked.
- A random number that lasts until you close the tab, so those steps can be counted as one visit rather than six unrelated ones. It is not a cookie, it is gone when the tab is, and it is not connected to you, your account, or any earlier visit.
We do not record your IP address, your device, your browser, what you typed, or anything that would let us pick you out. There is no third-party analytics script and nothing is shared with anybody. None of this happens on the page a card opens — that page still runs no JavaScript at all. Counts older than six months are deleted automatically.
How long we keep things
Your designs, video and card pages stay for as long as your account does — that is the point of the product. Order records are kept for as long as tax and accounting rules require, which is generally seven years. Rate-limit counters expire within hours. Tap records are anonymous from the moment they are written.
Deleting it
Do it yourself, at the bottom of your account, or under Account in the Dote app. You do not have to ask us and you do not have to explain.
It deletes your account, your designs, and every photograph, video and voice message on it. The cards stop working — a tap finds nothing — so if a card is in somebody else's hands, tell them first. The files themselves become unreferenced and are erased from storage by the nightly clean-up within thirty days.
Your order history stays, because we have to keep a record of what was paid. Your name and shipping address come off it. Stripe keeps its own record of the payment, which is theirs and not ours to delete.
One thing it cannot reach: a card bought before you had an account and never claimed onto it is not attached to you as far as our database is concerned, so it keeps working. The deletion screen counts those and says so — claim them first if you want them gone too.
If an order is still on its way, deletion waits until it arrives. We need the address to post it.
Deletion is permanent and we cannot undo it, so save anything you want to keep first. You are welcome to write to [email protected] instead if you would rather a person did it.
Your rights
If you are in California, you may ask what personal information we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. You may not be treated differently for asking, and we will not make you create an account to do it.
The same requests are honored for everyone, wherever you are, because running two standards would be more work than running the better one. Write to [email protected] — we answer within 45 days and usually the same week. If you want to appeal a decision we made, say so in the same email and a person will look at it again.
Security
Everything moves over HTTPS. Passwords are hashed, never stored in a readable form. Access to a design or an order is decided by the database against your signed-in identity, not by the page asking nicely. Nobody can browse to someone else's card page and edit it.
No system is perfect. If you find a way in, write to [email protected] — we would rather hear it from you than from a customer.
Children
Dote is sold to adults. We do not knowingly collect personal information from anyone under 13. Children obviously appear in the photographs customers upload — a birthday card is usually a child's — and those images belong to the adult who uploaded them, under that adult's account.
Changes
If this policy changes, the date at the top changes with it, and we will email account holders when the change is significant. We will not quietly widen what we do with your photographs.
Reaching us
ArcSmiths LLC, San Diego, California — [email protected]. By mail: 13910 Lyons Valley Rd, Ste R5, Jamul, CA 91935.
Your photographs, handled the way you would want.
Make a card tonight. Nothing you upload is used for anything but the card you asked for.
See the cards — from $30Ships in 24 hours · Free tracked shipping · Change the video any time