What we know about you
Last updated 18 August 2026
The short version: there are no accounts, no cookies set by us, no advertising trackers and nothing that follows you between visits. Every card is stored for as long as it is readable and then deleted automatically. We do count how many people reach each step of making a card, as plain anonymous totals with nothing attached to them — described in full further down.
This page explains exactly what ChitthiBhejo collects, where it goes, and how long it stays. It is specific on purpose. If anything here is unclear, write to vedika.app04@gmail.com and we'll explain.
We don't collect the recipient's phone number, email address, or any other way of reaching them — because we never contact them. You share the link yourself, through WhatsApp or however you like. The only thing we know about your recipient is the name you typed on the card, which is usually a first name.
This is the most important thing on this page, so it comes before the lists. It also changed recently, and in the direction of us holding more — so it is spelled out rather than quietly amended.
What changed. The ₹49 card used to be packed into its own link and never reached our server at all. That made for a very long link, and it meant anything the link touched could read the card out of the URL. Both cards are now saved on our server and addressed by a short link instead. The trade is deliberate but it is a real one: we now hold a copy of a ₹49 card, where before we held nothing. In exchange the card's contents are no longer sitting in the URL itself, and the card can be deleted on request — which was previously impossible.
Both prices store the same fields. The difference between them is what you are allowed to attach: only the ₹99 card can carry a photo or a voice note, or be sealed until a chosen moment. What gets saved is exactly this and nothing else:
That's the whole record. There is no IP address in it, no device information, no browser fingerprint, and no identifier that links one card to another card by the same person. Two cards you send a week apart are, to us, unrelated.
Every stored card is given a deletion time when it is created: 90 days after the moment it unlocks. For a card that isn't sealed, that clock starts immediately, so it is gone about 90 days after you send it. For a card sealed for two weeks, it is gone about 104 days after you send it. The deletion is done by the storage system itself rather than by a cleanup job we have to remember to run — the card is written with an expiry and it stops existing at that time whether or not anyone is watching.
While a card is sealed, the countdown page the recipient sees is not hiding the message with CSS. The server does not send the message, the photo or the voice note at all — only the envelope's colours, the two names and the unlock time. There is nothing in the page to dig out with developer tools. The contents are handed over on the first request made after the unlock time has passed.
Payments are handled entirely by Razorpay, a licensed Indian payment gateway. Your card number, UPI ID, bank details and CVV are entered in Razorpay's own checkout and are never sent to us, seen by us, or stored by us — we could not access them if we wanted to.
What comes back to us from a successful payment is a payment reference, an order reference, and a signature we verify to confirm the payment really happened. We use those to make sure a card is only stored for someone who actually paid, and to look up a payment if you ask us for a refund. Whatever else Razorpay collects to do its job — including billing details and its own fraud checks — is held by Razorpay under its own privacy policy.
We do not send Razorpay your card's contents. The only thing attached to the order on their side is which of the two options you bought.
While you're writing, your draft is saved in your browser's own storage so a refresh or a misplaced back button doesn't lose your words. This stays on your device — it is not sent anywhere — and it is cleared when you finish the card.
You can clear both at any time through your browser's "clear site data" setting. Neither is a cookie, and we set no cookies of our own — not for analytics, not for preferences, not for anything.
There is no Google Analytics on this site, no Meta pixel, no advertising tag, no heatmap recorder and no A/B testing tool. No third party receives anything about your visit.
We do keep our own count of how many people reach each step of
making a card — landing on the site, starting to write, reaching
the preview, paying, and the recipient opening it. It is how we
find out which screen is losing people. Each step sends one
message that says nothing but the name of the step, like
preview, and we add one to a daily total.
Because that is genuinely all it is, there is:
Your browser does remember which steps it has already counted,
so that reloading a page doesn't count you twice. That is kept
in session storage under ln_seen_steps, it holds
only step names, and the browser discards it when you close the
tab.
This is a change from what this page said before, which was that we didn't know how many people visited a page. We now do, as a plain total. We chose the weakest form of it we could build — aggregate counts, no identifiers — because a profile of someone who came here to write to a person they love is not a thing we want to hold.
The only third parties involved in loading a page are:
Nobody, unless you share the link. We don't sell data — there is nothing to sell — we don't share cards with advertisers or partners, and we don't read cards for interest. We would only disclose a stored card if we were legally required to by a valid order under Indian law, or if we had to look at one to answer a specific support request you sent us.
ChitthiBhejo isn't intended for children under 13, and we don't knowingly store cards created by them. If you believe a child has sent a card and you'd like it removed, write to us and we will delete it.
Because we hold so little, most privacy requests have short answers:
Cards are served only over HTTPS. Stored cards sit behind a 16-character random address — around 95 bits of randomness, which is not guessable in any practical sense. Everything a sender or recipient types is put into the page as text rather than as markup, and photos and voice notes are checked to be genuinely images and audio before they are shown, so a tampered link can't turn a card into a script. No system is perfectly safe, though, and the honest limit of what we can promise is in the Terms.
If this policy changes we'll update the date at the top. If a change materially affects what we store, we'll say so plainly here rather than quietly editing a sentence.
Privacy questions, deletion requests, or anything that reads wrong on this page: vedika.app04@gmail.com.