Privacy
Privacy by product boundary
Private creations stay separate from the public site, with practical controls for recovery, revocation, and deletion.
Effective date: August 2, 2026. This is a site-specific launch draft. The controller’s legal identity, address, governing law, retention schedule, and consumer-refund terms must be approved and inserted before public launch.
What this notice covers
This notice explains how YoursToOpen handles personal data on the public site, in creator tools, and while delivering a private recipient experience. It applies to information you provide directly and technical or operational information created when the service is used.
A recipient reveal is not a public profile or gallery entry. The creator decides what to include, and the recipient opens it through a private link or QR code.
Information a creator provides
Depending on the experience and features selected, a creator may provide a recipient name, personal message, photos, audio, event details, response settings, scheduling choices, a recovery email, and an optional PIN. A creator who opens an account also provides account credentials and profile information needed for that account.
Please do not include payment card details, passwords, government identifiers, health information, or other information that is not needed for a personal reveal.
- Recipient and creator content
- Optional recovery or account details
- Support, safety, and removal requests
Information created when a reveal is used
We create the minimum operational records needed to publish, protect, recover, troubleshoot, and enforce the lifecycle of a private reveal. This includes high-entropy link capabilities, creation status, expiry, revoke or deletion events, security and abuse-prevention signals, and service logs.
Where a creator has an eligible analytics feature, reporting is held as daily aggregate counts such as opens, completions, and responses. It is not a named recipient activity trail and is not designed to provide precise location or browser fingerprinting.
- Private-link and lifecycle records
- Aggregate feature reporting when available
- Technical signals needed to secure and operate the service
Why we use information
We use information to provide the experience a creator asks us to make and deliver; let the recipient open it; operate accounts and recovery; process a purchase where one is offered; respond to support, safety, removal, and legal requests; prevent fraud, abuse, or harmful use; and improve reliability.
The exact legal basis and any consent requirements depend on the jurisdiction and processing involved. The published launch version must identify the applicable controller and legal bases for each regional audience.
Who may process information
Access is limited to people and service providers that need it to run YoursToOpen, such as hosting and storage, email delivery, payment, support, security, and infrastructure providers. They may process information only for the service and under appropriate contractual or legal safeguards.
YoursToOpen does not make private recipient content available as a public browsing catalogue or use it to build advertising audiences. A final launch notice must name or clearly categorize current material processors and explain any cross-border transfer safeguards.
Security, private links, and lifecycle
Private recipient and edit links are high-entropy capabilities. Sensitive values such as recovery contact details and link material are protected in storage, and optional PINs are stored as verification values rather than displayed back to us. These controls reduce risk; they do not replace careful sharing by the creator.
Creators can revoke or delete a reveal. A revoked, deleted, or expired reveal should no longer expose its private content. Deletion also triggers removal of associated media, while limited operational records may remain for the configured retention period needed for security, accounting, or legal obligations.
Retention and deletion
Published content is available only for its stated hosting period unless it is revoked or deleted earlier. Recovery links expire. Deletion and expiry jobs remove media and dependent service data according to the active operational retention configuration.
The production retention schedule, backup window, and any statutory accounting retention periods have not yet been approved for publication. They must be completed here before launch; a local development fixture is not a customer-data retention commitment.
Your choices and privacy requests
Creators can manage a creation through the available creator or account controls, including revocation and deletion. To ask about access, correction, deletion, objection, restriction, portability, or a privacy complaint where applicable, contact info@yourstoopen.com. We may need to verify the request before acting on it.
Recipients can use the safety route to report a reveal or request review without creating an account. If a request concerns a private link, do not post that link publicly; provide it only through the relevant support or safety path.
Launch details still required
This notice is written for the product that is implemented today, but it cannot be a final legal notice until the controller’s legal entity name, registered address, applicable jurisdiction, contact point or data-protection officer where required, regional legal bases, processor list, transfer safeguards, and retention schedule are approved and inserted.