A little privacy.
LittleSurprise stores the names, messages and photos you choose to include in a gift, organizer account identifiers, payment records and reports. We do not ask for the recipient’s email or phone number.
Who can see a gift?
The organizer can review contributions. Other contributors cannot read them. Anyone with the recipient link can view a finalized gift. Anyone with a contributor’s private edit link can manage that note before finalization. Keep private links out of public posts. This is link-based privacy, not end-to-end encryption.
Services we use
Clerk handles organizer sign-in, Neon stores gift records and private photos, and Stripe handles checkout. Card details go directly to Stripe. Our hosting provider processes requests and may retain operational logs. We don’t sell messages or photos, and private gift pages do not load advertising or analytics scripts.
Photos and local storage
Photos are resized and re-encoded before storage, removing embedded location metadata. Draft text is stored in this browser tab until you clear it or close the session. Recipient opening progress is kept on the device, along with your sound on/off preference. Clearing browser data or using another device may reset that progress; it doesn’t delete the gift.
Retention and deletion
Completed gifts remain accessible while the service operates, unless the organizer deletes them or they are removed for abuse. There is no lifetime hosting promise. Deleting a gift immediately disables its links and removes message text from the active application database. Photo deletion is processed separately, targeted within 7 days. Database backups may retain earlier versions for the provider’s configured backup window, currently 6 hours on the pilot database. Payment records may need to be retained for accounting and dispute handling.
We may remove unfinished, inactive free gifts after 90 days only after notifying the organizer. Automatic draft removal is not currently enabled. If the service closes, we intend to provide advance notice and a reasonable way to retrieve your messages.
Usage information
We record basic product events to understand whether gifts are created, purchased and completed. Event records do not include message text, display names, photo URLs or private link tokens. Abuse protection uses short-lived request counters and hashed network identifiers. Organizers can see when a recipient link was first opened and when all capsules or the message collection were opened. Anyone with the link can trigger these signals; they do not verify who read a gift. Downloaded copies are stored on the recipient’s device and cannot be revoked by deleting the online gift.
Your choices
Use your edit link to remove a contribution before finalization. Afterward, ask the organizer to remove it or use the gift’s report control. Organizers can delete individual gifts from the dashboard; contact support for account deletion. See support for help.