Legal
Privacy Policy
Last updated: 2026-06-15
Service: Adorvi (the "Service")
Controller: Rishi Venkat ("Adorvi," "we," "us," "our")
Effective date: June 15, 2026
Last updated: June 15, 2026
This Privacy Policy explains what personal information we collect when you use Adorvi at https://adorvi.com, how we use and share it, the legal bases on which we rely, and the rights you have. It covers both the person who creates a gift ("Sender") and the person who receives it ("Recipient"), as well as people whose images appear in uploaded photos. Capitalized terms not defined here have the meaning given in our Terms of Service.
For EU/UK residents, Rishi Venkat is the "controller" of your personal data under the GDPR/UK GDPR. We are a small US-based sole operator and do not target our Service at, or monitor individuals in, the EU/UK; on that basis we have not appointed a representative under GDPR Article 27. EU/UK residents may contact us directly at help@adorvi.com.
1. Summary (Plain Language)
- We collect the information needed to create, deliver, and manage your digital Letter: Sender name and email, Recipient name, your letter and biography text, captions, music selection, and up to five photos.
- Photos and your letter/biography text are sent to Google's AI services (Gemini / Vertex AI and Imagen) for styling and text generation. Photos are stored on Google Cloud / Firebase.
- Like any website, our servers and hosting provider log basic request data (including IP address) when a Letter is opened, to operate and secure the Service and prevent abuse. We do not notify the Sender when a Letter is opened.
- We use your email to send transactional messages (receipts, the verification link that saves your draft, and sign-in codes). If you enter your email, verify it, and then don't finish your gift, we may send you one reminder to pick your draft back up - with a one-click unsubscribe. We do not send discount codes or general marketing emails. You can opt out at any time.
- Payments are handled by Stripe; we do not store full card numbers.
- We do not knowingly collect biometric identifiers, and the Service is not directed to children under 18.
This summary does not replace the full policy below.
2. Information We Collect
2.1 Information you provide as a Sender
- Identity & contact: your name and your email address.
- Recipient information: the Recipient's name (and any other details you include about them).
- Content you create: the free-text letter, an optional short biography about the Recipient, photo captions, occasion, tone, theme/palette/style selections, and music selection (a curated background track or an audio file you upload).
- Photos: up to five (5) images you upload, which may depict you, the Recipient, family members, and other identifiable individuals (potentially including minors).
- Email captured during creation. You enter your email at the first step of the create flow (it's needed for your receipt and to save your draft). At that point we save a text-only draft and send you a one-time verification email (transactional). We retain the email and draft context so you can resume and receive your receipt. If - and only if - you verify your email and then leave without finishing, we may send you one reminder to resume your draft (see Section 4.3); that reminder carries a one-click unsubscribe link. There is no separate marketing opt-in checkbox: verifying your email is the affirmative opt-in for that single reminder, and unverified addresses are never sent it.
2.2 Payment information
- Payments are processed by Stripe. We receive limited transaction metadata (such as a Stripe session/identifier, payment status, and the fact and amount of a purchase). We do not receive or store your full payment-card number. Stripe processes your card data under its own privacy policy.
2.3 Information about the Recipient (a person who did not sign up)
- We receive the Recipient's name from the Sender.
- When the Recipient opens the Letter, our servers and hosting provider log basic request data (such as IP address and user-agent), as they do for any visitor, to help us detect abuse and protect the Service. We do not store an "opened" status or open timestamp on the Letter, and we do not notify the Sender when a Letter is opened.
- We do not expose the Recipient's IP address to the Sender. See Section 12 for how we handle Recipient data.
2.4 Information collected automatically
- Local storage / draft state. The creation flow may store draft data in your browser's local storage so you don't lose work. See the Cookie Notice.
- Device and browser information. When you access the Service, our servers and hosting provider log your IP address and information about your device, including device type, operating system, browser type and version, language settings, and related software configuration.
- Usage data. We may log information about your activity on the Service, such as the URL of the website you came from (referrer), pages or steps you viewed, how long you spent on each step, access times, and other details about how you interact with the Service.
- Logs & security data. Server logs, IP addresses, and rate-limiting counters (via Upstash) used to operate and secure the Service and prevent abuse.
- Cookies / similar technologies. See Section 11 and the Cookie Notice. We use only essential cookies and local storage; we do not embed third-party media players or load advertising cookies on the Letter page.
2.5 Inferences
We may derive or infer information from data we collect using automated means - for example, inferring your approximate geographic location from your IP address, or inferring preferences from your creation choices. Under laws such as the CCPA/CPRA, inferences are treated as personal information. We use inferences only to operate, improve, and protect the Service.
2.6 Sensitive information
- Photos can reveal sensitive characteristics (for example, of identifiable people, potentially including minors). We process photos only to provide the Service. We do not intentionally collect special-category data (such as racial/ethnic origin, health, religious, or biometric data) and we ask you not to upload content that depends on such data. See the biometric disclaimer in Section 6.
3. Where the Information Comes From
Most information comes directly from the Sender. Recipient request data (such as IP address) is logged automatically by our servers/hosting when the Letter is opened, as for any website visitor. Payment status comes from Stripe. We do not buy personal data from data brokers.
4. How We Use Information & Legal Bases (GDPR/UK GDPR)
We use personal information for the purposes below. For users in the EU/UK, the relevant legal basis under Article 6 GDPR is shown in brackets.
4.1 To provide the Service
Create, generate, style, host, and deliver your Letter; assemble the page; apply AI styling to photos and AI assistance to text; activate the unguessable URL; and host the Letter while it remains live. (Legal basis: performance of a contract - Art. 6(1)(b).)
4.2 Transactional communications
Send purchase receipts, the email-verification link used to save your draft, manage-dashboard sign-in codes, and other service-related messages, via Resend. (Legal basis: performance of a contract - Art. 6(1)(b); and our legitimate interests in operating the Service - Art. 6(1)(f).)
4.3 Abandoned-draft reminder
If you enter your email in the create flow, verify that email, and then leave without finishing your gift, we may send you a single reminder to come back and complete your draft. We do not send promotional discount codes, and we do not currently send general marketing or product-update emails. The reminder is sent only after you have verified your address - your verification is the affirmative opt-in - and it is sent at most once per draft. (Legal basis: where consent is required, your verification of the email address as a clear affirmative action - Art. 6(1)(a); and our legitimate interests in helping you finish what you started - Art. 6(1)(f), balanced against your rights.) You can opt out at any time via the one-click unsubscribe link in the reminder (also exposed to your mail client via standard List-Unsubscribe headers) or by contacting help@adorvi.com. Unverified addresses are never sent this reminder. We honor CAN-SPAM (US), CASL (Canada), and GDPR/ePrivacy (EU/UK) requirements. See Section 10.
4.4 Payments & fraud prevention
Process payments via Stripe, prevent and investigate fraud, handle chargebacks and refunds. (Legal basis: performance of a contract - Art. 6(1)(b); legal obligation - Art. 6(1)(c); legitimate interests in fraud prevention - Art. 6(1)(f).)
4.5 Security, abuse prevention & rate limiting
Operate logs, apply rate limits (Upstash), detect and prevent abuse, enforce our Terms and AUP, and protect users and third parties. This includes logging IP addresses and request metadata for visitors, including Recipients who open a Letter. (Legal basis: legitimate interests - Art. 6(1)(f); legal obligation - Art. 6(1)(c).)
4.6 Content safety / moderation
Apply automated safety filtering (including provider-side AI safety filters) and, where appropriate, human review of reported content, to prevent prohibited content (e.g. CSAM, non-consensual imagery, deepfakes). (Legal basis: legitimate interests and compliance with legal obligations - Art. 6(1)(f), (c).)
4.7 Service improvement
Understand aggregate usage and improve features and reliability. We avoid using private Letter content for this where reasonably possible. (Legal basis: legitimate interests - Art. 6(1)(f).)
4.8 Legal compliance
Comply with applicable law, respond to lawful requests, and establish, exercise, or defend legal claims. (Legal basis: legal obligation - Art. 6(1)(c); legitimate interests - Art. 6(1)(f).)
Where we rely on consent, you may withdraw it at any time without affecting prior processing. Where we rely on legitimate interests, you may object (Section 9).
5. AI Processing Disclosure (Google Gemini / Vertex AI & Imagen)
5.1. To provide AI styling and AI-assisted text, the Service sends the following to Google's AI services (Gemini / Vertex AI for text; Imagen on Vertex AI for image styling): your uploaded Photos and the letter/biography/occasion text used to generate or refine content. This processing occurs on Google Cloud infrastructure (see Sub-processors, Section 7) and involves transfer to and processing in the United States and potentially other locations (see International Transfers, Section 8).
5.2. Model training and data retention. Based on Google's Vertex AI Service Terms and data-governance documentation, Google does not use the data we submit to Vertex AI (including your Photos and the text we send for generation) to train or improve its foundation models, and does not make that data available to other customers. Inputs and generated outputs are processed only to return a result to us, are subject to Google's Vertex AI data-processing terms, and may be subject to automated abuse and safety filtering. We use the paid, enterprise Vertex AI tier rather than any free consumer tier, and we do not consent to the use of customer content for model training. This reflects Google's terms as of the effective date of this Policy; those terms are controlled by Google and may change.
5.3. No guarantee of AI output. As described in the Terms, AI output is variable and provided "as is." AI features may alter likenesses; do not rely on them for accuracy.
5.4. Your responsibility for inputs. You must have the rights and consents described in the Terms (Section 9) and AUP for every Photo and person you submit to AI processing, including minors and the Recipient.
6. Biometric Data Disclaimer
6.1. Adorvi applies artistic styling to photos for aesthetic purposes only. We do not knowingly collect, capture, extract, generate, convert, store, use, or sell "biometric identifiers" or "biometric information" as those terms are defined under the Illinois Biometric Information Privacy Act ("BIPA"), the Texas Capture or Use of Biometric Identifier Act ("CUBI"), the Washington biometric privacy law (RCW 19.375), or similar laws.
6.2. The Service does not perform facial recognition, faceprint/face-geometry extraction, identity matching, or biometric template creation. AI styling does not identify individuals or create a biometric template; it produces a stylized image.
6.3. If any underlying third-party AI service processes facial geometry as part of image transformation, we instruct that no biometric template is retained or used to identify a person. Our styling pipeline performs image-to-image artistic transformation only; it does not run facial recognition or build a face-geometry template.
6.4. Do not upload images for the purpose of biometric identification. That use is prohibited by the AUP.
7. Who We Share Information With - Sub-Processors & Third Parties
We do not sell your personal information for money. We share personal information with the service providers ("sub-processors") below, who process it on our behalf under contract and only as needed to provide the Service. (For the CCPA/CPRA meaning of "sell"/"share," see Section 9.)
| Sub-processor | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| Vercel | Website hosting and content delivery | Request/log data, IP address | https://vercel.com/legal/privacy-policy |
| Google Cloud / Firebase | Database (Firestore) and file storage (Storage) | All gift data, photos, Sender/Recipient info | https://firebase.google.com/support/privacy |
| Google Gemini / Vertex AI & Imagen | AI text generation and AI photo styling | Photos; letter/bio/occasion text | https://cloud.google.com/terms/cloud-privacy-notice |
| Stripe | Payment processing, fraud prevention | Payment/transaction data, email | https://stripe.com/privacy |
| Upstash | Rate-limiting infrastructure | IP addresses, request counters | https://upstash.com/trust/privacy |
| Resend | Transactional & abandoned-draft reminder email delivery | Email address, message content | https://resend.com/legal/privacy-policy |
We may also disclose information: (a) to comply with law, legal process, or lawful government requests; (b) to enforce our Terms/AUP or protect the rights, safety, and property of users, third parties, or us (including reporting CSAM or other illegal content to law enforcement or appropriate authorities); and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or will notify you as required.
We keep this sub-processor list current and will update it if we add analytics, error-monitoring, support, or other tools that process personal data.
8. International Data Transfers
8.1. We are based in the United States, and our sub-processors - notably Google Cloud / Vertex AI and Stripe - process data in the United States and potentially other countries. If you are in the EU, UK, Switzerland, or Canada, your personal data (including photos) will be transferred to and processed in countries that may not provide the same level of data protection as your home country.
8.2. For transfers out of the EEA/UK/Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and/or a recipient's certification under the EU-U.S. Data Privacy Framework where applicable. You may request a copy of the relevant safeguards by contacting help@adorvi.com.
9. Your Privacy Rights
Depending on where you live, you may have some or all of the rights below. We will not discriminate against you for exercising them.
9.1 EU/UK (GDPR/UK GDPR)
- Access a copy of your personal data.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten").
- Restriction of processing.
- Portability of data you provided, in a machine-readable format.
- Objection to processing based on legitimate interests, including objection to direct marketing at any time.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority (Section 14).
9.2 California (CCPA/CPRA) and similar US state laws
- Right to know / access the categories and specific pieces of personal information we collect, use, and disclose.
- Right to delete personal information, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing" of personal information and of targeted/cross-context behavioral advertising. We do not sell your personal information for money. We have not done so in the past 12 months. We do not use advertising cookies or third-party tracking embeds, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CPRA, so no "Do Not Sell or Share My Personal Information" mechanism is required.
- Right to limit use of sensitive personal information (note: we aim not to use sensitive data beyond providing the Service).
- Right to non-discrimination for exercising these rights.
- Authorized agent. You may designate an authorized agent to make CCPA/CPRA requests on your behalf. To use an agent, the agent must provide proof that you have authorized them to act on your behalf (such as a written authorization or power of attorney). We may also require you to verify your identity directly with us before we fulfill a request made by an agent. To provide or delete specific pieces of personal information, we will verify your identity to the degree of certainty required by law - typically by confirming control of the email address associated with your Letter or by requiring information sufficient to identify your account.
9.3 Canada (PIPEDA / provincial laws)
- Rights to access and correct your personal information and to withdraw consent, subject to legal/contractual limits.
9.4 How to exercise your rights
Email help@adorvi.com (or help@adorvi.com) with your request. Because we operate without accounts, we may need to verify your identity by confirming control of the email address associated with the Letter and/or details of the gift, before acting. We will respond within the timeframes required by applicable law. You may use an authorized agent where the law permits. Note that some content (such as a Letter's Recipient name) may relate to another person, which can affect what we can disclose or delete.
10. Email Marketing & Your Opt-Out Choices
10.1. Transactional vs. marketing. Transactional emails (receipts, the draft-verification link, and manage sign-in codes) are part of the Service. The only non-transactional email we currently send is the single abandoned-draft reminder described in Section 4.3. We do not send discount codes or general marketing/product emails.
10.2. How to opt out. The abandoned-draft reminder contains a one-click unsubscribe link (and standard List-Unsubscribe headers your mail client can use), and you may also email help@adorvi.com. We will process opt-outs promptly (and, for CAN-SPAM, within 10 business days). Unsubscribing does not stop transactional messages necessary to deliver a Letter you purchased.
10.3. Consent capture (CASL / GDPR / ePrivacy). The abandoned-draft reminder is sent only to addresses that have been verified by clicking the verification link - we treat that verification as the affirmative opt-in, and unverified addresses are never sent it.
10.4. CAN-SPAM (US) requirements we follow for the abandoned-draft reminder: accurate sender and subject lines, clear identification of who is sending the message, and a working one-click unsubscribe mechanism honored promptly. You can reach the sender at any time at help@adorvi.com.
11. Cookies & Local Storage
11.1. We use browser local storage to save your in-progress draft so you don't lose work. We and our providers may use cookies or similar technologies for essential functionality, security, and (via Stripe) payment processing.
11.2. Background music is served as ordinary audio files from our own infrastructure; the Letter page does not embed any third-party media player and does not set third-party or advertising cookies.
11.3. Because we use only strictly necessary cookies and local storage (and no non-essential or advertising cookies), no cookie-consent banner is required for EU/UK visitors. See the Cookie Notice.
12. Recipient Data (People Who Did Not Sign Up)
12.1. A Recipient does not register or accept the Terms. We process limited Recipient data: the name provided by the Sender, and, when the Letter is opened, basic request data logged by our servers/hosting (such as IP address and user-agent), as for any website visitor.
12.2. We use Recipient data only to deliver the Letter and for security/abuse prevention. We do not notify the Sender when a Letter is opened, we do not expose the Recipient's IP address to the Sender, and we do not use a Recipient's data to market to the Recipient.
12.3. If you are a Recipient (or a person depicted in a Photo) and wish to access, object to, or request deletion of data about you, contact help@adorvi.com. Because Letters are created by Senders, we may need to coordinate with, or identify the relevant Letter from, limited information you provide. We will act on valid requests as required by law.
12.4. People depicted in photos. The Sender is responsible for having the consent of every identifiable person in a Photo (including minors via a guardian). If you appear in a Photo and did not consent, contact us to request removal.
13. Data Retention
13.1. Paid Letters. Retained on an ongoing basis while we host the Letter, subject to the Terms - including our right to retire inactive or abandoned Letters and to discontinue the Service (Terms Section 6) - and to deletion on your request. We do not guarantee perpetual retention; please keep your own copies of anything you want to preserve.
13.2. Inactive or abandoned Letters. We may retire a Letter (making it inaccessible and deleting it and its associated photos) after an extended period of inactivity or abandonment, or on wind-down of the Service, with reasonable email notice where we have a valid address (see Terms Sections 6.2–6.3).
13.3. Pending/abandoned drafts. Unpaid draft gifts may be auto-deleted after a short period (currently about 24 hours) via an automated time-to-live mechanism. Note: an email address used for the abandoned-draft reminder (Section 4.3) may be retained separately from the deleted draft so we can send the single reminder and honor any unsubscribe or suppression request.
13.4. Payment and legal records. Transaction records may be retained as long as required for tax, accounting, fraud-prevention, and legal-compliance purposes.
13.5. Logs and security data. Retained for a limited period necessary for operations and security (generally up to 90 days for detailed request logs), then deleted or aggregated.
13.6. Backups. Deleted data may persist in routine backups for a limited period (generally up to 30 days) before being overwritten.
We review these retention periods from time to time and delete or anonymize data once it is no longer needed for the purposes described above.
14. Children's Privacy
14.1. The Service is not directed to children and is intended for users 18 and older. We do not knowingly collect personal information from children under 13 (US COPPA) or under the applicable age of digital consent in the EU/UK. If we learn we have collected personal information from a child in violation of law, we will delete it.
14.2. Minors appearing in photos. This is distinct from children using the Service. A Sender may upload Photos that depict minors. The Sender must be the minor's parent/guardian or have verifiable guardian consent for all uses described in the Terms (Section 9) and AUP. We do not knowingly host unlawful imagery of minors and enforce a zero-tolerance policy against CSAM (see the AUP).
15. Security
15.1. We use technical and organizational measures designed to protect personal information, including: access controls and deny-by-default storage rules; serving photos via unguessable download tokens rather than a public bucket; unguessable Letter URLs/identifiers; input validation and file-type verification on uploads; payload-size limits; and rate limiting against abuse.
15.2. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you share content at your own risk. Remember that anyone with a Letter's URL can open it.
16. Data Breach Notification
16.1. If we become aware of a personal-data breach that triggers notification obligations, we will notify the relevant supervisory authority and/or affected individuals as required by applicable law (for example, within 72 hours of becoming aware, where GDPR Art. 33 applies, and as required under applicable US state breach laws and Canadian PIPEDA).
17. Changes to This Policy
We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, take reasonable steps to notify you (for example, a notice on the Service or, where appropriate, by email). Your continued use after changes take effect constitutes acceptance where permitted by law.
18. Contact Us & How to Complain
Privacy questions / rights requests: help@adorvi.com General contact: help@adorvi.com Controller: Rishi Venkat, an individual based in Texas, United States (a mailing address is available on request for formal legal notices) Data Protection Officer: Not appointed - not required for an operation of this nature and scale. EU/UK Representative: Not appointed - see the note at the top of this Policy.
If you are in the EU/UK and believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office; in the EU, your national supervisory authority). Canadian users may complain to the Office of the Privacy Commissioner of Canada.
Adorvi is operated by Rishi Venkat. Questions about your privacy or your rights? Email help@adorvi.com.