shoutouts
Sign in

Privacy Policy

Last updated October 8, 2026

The short version: organizers give us an email address so they can sign in. Contributors give us a name and a message — no account, no email, no tracking. Team workspaces upload a roster of colleagues, which is the one place we hold details about people who never used the site themselves; it's the workspace's job to have the right to share them. We don't sell anything to anyone, and we don't run ads or advertising trackers.

1. Who's responsible

GOSHOUTOUTS, a sole proprietorship of Keith Falcon is responsible for the personal information described here. Write to goshoutouts@proton.me about anything on this page.

2. What we collect, by who you are

If you organize a card, we store your email address — it’s how you sign in and how we reach you about your cards. We also store the cards themselves: the recipient’s name, the occasion, the design, any cover photo or background photos you upload, any delivery date and time zone you set, and the recipient’s email address if you give us one.

If you sign a card, we store the name you type and your message, plus any photo, GIF, doodle, video, or voice recording you attach. If you add a YouTube link, we keep which video it is and nothing else about it. We do not ask for your email address, we do not create an account for you, and we do not track you across the web. The name you type is whatever you choose to type. (One exception, on some team cards, is described just below.)

If you receive a card, we store the email address the organizer gave us, so we can send you the link. If you write back with a thank-you note, we keep it and email it to the organizer (or to the team address a workspace has set up for its updates).

If you pay, Stripe handles the payment and holds your card details. We never see or store them. We keep a record that a card was upgraded and which plan was bought.

If your team runs a workspace, an admin there gives us a roster: each person’s name and, if the admin adds them, email address, birthday (month and day), start date, and a photo. We use those to open a card ahead of each birthday and work anniversary, to email the finished card to the address on the roster, and to put the photo on the card’s cover. Everyone who is an admin of that workspace can see its roster and every card and message in it. We also keep the workspace’s own details — its team and company names, the sender name it puts on email, and the address it may set up to receive its updates — and the email addresses of people invited to become admins. You never need an account to be on a roster, and being on one never sends you anything except a card.

If you sign a workspace card, the same rules apply as to any card: a name and a message, no account. A workspace can choose to limit signing to its own people; if it has, the page asks for your work email and checks it against the workspace’s roster. That email is checked and not kept — it is never stored, never shown to anyone, and never attached to your message. A workspace’s admins can see what you wrote, as any organizer can; they cannot see who you are beyond the name you typed.

If you contact support, we keep what you send: your email address, your message, the card link if you give one, and — only if you leave “include my browser and device details” ticked — your browser and device type and the page on this site you came from. To stop the form being abused we also keep a scrambled, one-way code made from your internet connection’s address; the address itself is never stored. We use all of it only to answer you and fix what went wrong.

If you visit our public pages — the home page, pricing, designs, about, support, the legal pages, sign-in and the page where a card is made — HeyCatch counts the visit for us: which of those pages you looked at, what you clicked (the kind of thing, not its words), the site that sent you, your browser and device type, and the rough location your internet connection suggests, under a random id kept in your browser. It never runs on a card: not on a signing link, a reveal, a workspace digest, or anywhere you are signed in, and it is never given a card’s link, a message, a name or an email address. When a card is made we tell it that one was, with the plan and the occasion and your account’s internal number, nothing more. If your browser sends Do Not Track, it counts nothing.

3. What we don't do

  • We don’t sell or rent personal information.
  • We don’t run ads or third-party advertising trackers.
  • We don’t require contributors to identify themselves, and we don’t try to work out who they are.
  • We don’t use your card content to train AI models.
  • We don’t tell a workspace who did or didn’t sign a card. Signing a colleague’s card is as anonymous as signing any other.

4. How we use it

To run the product, and essentially nothing else: showing a card to the people it’s for, emailing the recipient the reveal link at the time the organizer chose, reminding an organizer their card is coming up, opening a workspace’s cards ahead of roster dates and sending its admins the weekly digest, taking payment, and answering support email. We also use it to keep the service working and secure — for example, spotting abuse.

5. Who else touches it

We use a small number of companies to run the service. They only process what they need for their part:

  • Supabase — Database, organizer sign-in, and photo storage
  • Google — Only if you choose to sign in with Google — they confirm your email address to us and nothing else
  • Vercel — Website hosting
  • Stripe — Payments — they receive card details, we never do
  • Resend — Sending our emails: card links, reveals, reminders, thank-you notes, workspace invites and digests, and support messages
  • Mux — Hosting video and voice messages on Plus cards
  • HeyCatch — Counting visits to our public pages (never a card, a signing page, or anywhere you are signed in), and a note that a card was made
  • GIPHY — GIF search. Searches are proxied through our server, so GIPHY sees the search term but not who searched
  • YouTube (Google) — Only on a card where someone added a YouTube link. The video's picture comes from YouTube when that message is shown, and YouTube's player loads, from its privacy-enhanced address, only when someone presses play; from then on Google's privacy policy applies to the player. When a link is pasted, our server asks YouTube whether the video exists

We may also disclose information if the law genuinely requires it, or to protect someone’s safety.

6. How long we keep it

Cards are kept for a period that depends on the plan:

  • Free — 60 days after delivery (or creation, if no delivery date was set)
  • Standard — 365 days
  • Plus — kept indefinitely, for as long as we run the service

After that a card is archived and its links stop working. Organizer accounts are kept until you ask us to delete them. Payment records are kept as long as tax and accounting rules require, which is longer than the card itself.

Workspace cards have every Plus feature and are kept indefinitely — unless the workspace sets a retention period, in which case delivered cards are permanently deleted once it passes, attachments included. A roster entry is kept until an admin removes it or the workspace is deleted; removing someone from the roster doesn’t delete cards that were already sent to them. Deleting a workspace permanently deletes its roster, cards, and messages together.

7. Cookies

A sign-in cookie keeps organizers and workspace admins signed in. When you sign a card, your browser keeps a private key to your own message in a cookie, so you can come back and fix it; it expires two weeks after the card is delivered, and never lasts more than 90 days. A recipient’s browser remembers how far through their card they got, so they can pick up where they left off — that stays on their device and never reaches us. On our public pages only, the visit counter described in section 2 keeps a random id in your browser’s storage (not a cookie). No analytics or advertising cookies, nothing on a card, and nothing that tracks anyone across the web.

8. Your choices

  • Organizers can edit or delete a card at any time, and can turn reminder emails off per card in the card’s settings. Email us to delete your whole account.
  • Contributors can ask the card’s organizer to remove a message — they can do it themselves in a click. If you can’t reach them, write to us with the card link.
  • Recipients can ask us to delete a card sent to them.
  • People on a workspace roster can ask the workspace’s admins to remove them — it’s one click on their side — or write to us with the workspace’s name and we’ll see to it.
  • Workspace owners can delete the whole workspace from its settings, which removes everything in it at once.
  • Depending on where you live you may have rights to access, correct, export, or delete personal information. Email goshoutouts@proton.me and we’ll help — we won’t charge you or make it difficult.

9. Children

shoutouts isn’t directed at children, and organizer accounts aren’t for under-13s. Cards are often about children — a birthday, a graduation — and photos of them get uploaded by adults. If you believe a child’s photo or information is on a card without the right permission, email us and we’ll remove it promptly.

10. How it's protected

Cards are reached through long, unguessable links rather than being publicly listed. The database refuses direct access by default, so a card can only be read through the specific link it belongs to. Uploaded photos live in private storage and are served through short-lived signed links. Everything travels over HTTPS.

No system is perfect. Anyone holding a card’s link can open it, so treat those links like the card itself.

11. Where information is held

Our providers are based in the United States and information is processed there. If you’re elsewhere, using shoutouts means your information is transferred to the US.

12. Changes

If this policy changes, the date at the top changes with it, and we’ll tell organizers about anything significant. See also our Terms of Service.

Terms · Privacy · Home