Privacy Policy

Last updated: June 26, 2026

snailmail.eco LLC ("Just Get Crafty," "we," "us," or "our") operates the Just Get Crafty web application at justgetcrafty.com (the "Service"), which lets you turn your own handwriting into custom fonts and prepare vector artwork for pen plotters and cutters.

This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over your data. We've tried to write it in plain English.

By using the Service, you agree to the practices described here.


1. Who We Are and Scope

The data controller responsible for your personal information is snailmail.eco LLC, operating the Just Get Crafty brand at justgetcrafty.com.

This policy applies to personal information we process when you visit justgetcrafty.com, create an account, draw or upload content, generate fonts, subscribe to a paid plan, or otherwise interact with the Service. It does not apply to third-party websites or services we link to, which have their own privacy policies.

If you have any questions or want to exercise your rights, contact us at snailmail.eco@gmail.com.


2. What Data We Collect and How

We collect information in two ways: information you provide to us, and information collected automatically when you use the Service.

Information you provide

  • Account data. When you sign up, we collect your email address and a password. Passwords are hashed and managed by our authentication provider (Supabase Auth); we never see or store your plaintext password. You may also set an optional display name.
  • Google sign-in data. If you choose to sign in with Google, we receive basic Google profile information (your email address and name) from Google to create and identify your account. We only receive this if you select Google login.
  • User-created content. This is the heart of the Service and includes:
  • Handwriting drawings and glyph stroke data: the coordinates of the strokes you draw, including pen pressure and timing information.
  • Uploaded images you provide for tracing/conversion.
  • Uploaded font files (OTF/TTF) you provide for conversion.
  • Generated output files we create from your input, such as OTF/TTF font files and SVG vectors.
  • Payment-related data. When you subscribe to a paid ("Pro") plan, payment is handled by Stripe. We do not store your full card number. We store a customer/subscription reference and your plan status so we know what features you're entitled to.
  • Communications. If you email us (for support or to exercise a privacy right), we receive your email address and the contents of your message.

Information collected automatically

  • Technical and usage data. Like most websites, our hosting infrastructure generates standard server logs, which may include your IP address, browser/user-agent, request timestamps, and pages or endpoints accessed. We use these for security, debugging, and keeping the Service running.
  • First-party usage counters. To understand which features people actually use, the site records a small number of aggregate usage events (for example "a demo was used on this page" or "a font build finished"). Each event may also record:
  • the website you arrived from, as a bare domain name only (for example google.com), so we can tell which sources bring people who find the Service useful. We never store the full referring address, so this does not include the search terms you typed or the page you came from;
  • a random visit id held in your browser's sessionStorage, so we can see how far people get through a multi-step task (for example, how much of the alphabet gets drawn before someone stops). This id is not a cookie, is not tied to you or your device, is never shared with anyone, and disappears when you close the tab, it cannot connect one visit to another, or to you;
  • your account id, but only when you are signed in.

These events are sent to our own server only, use no cookies, and contain no fingerprinting. We do not use any third-party analytics service.

Opting out: if your browser sends a Global Privacy Control (GPC) or Do Not Track signal, we honour it automatically, we still count that something happened, but we record no visit id and no referring domain, so nothing about your visit can be linked together. You do not need to do anything else, and the Service works exactly the same either way.

  • Cookies and local storage. We use:
  • An authentication session (managed by Supabase) to keep you logged in.
  • A local draft autosave stored in your browser's localStorage, which holds your in-progress drawing so you don't lose work. This stays on your device.
  • Ad conversion measurement (only while we are running ad campaigns). When we advertise the Service (for example on Google), Google's conversion tag (gtag.js) may set a cookie so that, if you arrived from one of our ads and then create an account, we can tell which ad brought you here. It measures our own ads only; we do not use it to build profiles of you or to show you ads on other sites. When we are not running campaigns, this tag does not load at all.

We do not use any third-party analytics service, and we show no third-party ads on the Service. See our Cookie Policy for details.


3. Why We Process Your Data and Our Legal Bases

For users in the EU, UK, and other regions covered by the GDPR, we rely on the following legal bases:

PurposeData usedLegal basis (GDPR)
Create and manage your account; authenticate youAccount data, Google profile (if used)Contract (to provide the Service you requested)
Store your drawings and build/convert your fontsUser-created contentContract
Process payments and manage subscriptionsPayment reference, plan statusContract
Keep the Service secure, debug problems, prevent abuseTechnical/usage dataLegitimate interests (running a safe, reliable service)
Remember your draft on your devicelocalStorage draftConsent / your own device storage
Respond to your support or rights requestsCommunicationsLegitimate interests / legal obligation
Optional features that rely on third parties (e.g. Google login)Relevant dataConsent (you choose to use them)
Measure which of our ads lead to sign-ups (only while we run ad campaigns)Google Ads conversion cookieConsent where required / legitimate interests (measuring our own advertising)

Where we rely on consent, you can withdraw it at any time (this won't affect processing already carried out). Where we rely on legitimate interests, you have the right to object (see Section 7).


4. Sharing and Sub-Processors

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We share data only with the service providers ("sub-processors") that help us run the Service. Each processes data on our behalf and for the purposes below:

  • Supabase: our database (Postgres, including the jobs and saved_fonts tables), authentication, and file storage.
  • Stripe: payment processing for Pro subscriptions. Stripe handles your card details directly under its own privacy policy.
  • Google: OAuth sign-in (only if you choose to log in with Google), and Google Ads conversion measurement (only while we are running ad campaigns), which tells us that a click on one of our ads led to a sign-up.
  • Render: application hosting and server infrastructure.

We may also disclose information if required by law, to comply with legal process, to enforce our terms, or to protect the rights, safety, and property of our users or others.

Important: public storage disclosure

Please be aware that generated font files and glyph thumbnails are stored in a public storage bucket and served via public URLs (these URLs include a content-version identifier and are not publicly listed/indexed by us). This means anyone who has the URL can access those files. Please keep this in mind for any content you would prefer to keep private. Your account credentials, saved-font records, and other database entries are not public.


5. International Data Transfers

We are based in the United States, and our sub-processors (including Supabase, Stripe, Google, and Render) may process and store your data in the US and other countries. If you access the Service from the EU, UK, or elsewhere, your personal information will be transferred to and processed in the United States, which may have different data-protection laws than your home country.

Where required, we rely on appropriate safeguards for these transfers (such as the European Commission's Standard Contractual Clauses or an equivalent mechanism offered by our sub-processors). You can contact us at snailmail.eco@gmail.com for more information.


6. Data Retention

We keep personal information only as long as we need it:

  • In-progress font "jobs" are automatically deleted after 24 hours (our cleanup runs hourly). These are temporary working files used while building a font.
  • Saved fonts are kept until you delete them (or delete your account). They are intended to remain available to you.
  • Browser localStorage drafts stay on your device until you clear them (e.g., by clearing your browser data). We don't have access to them on the server.
  • First-party usage events are deleted automatically after 180 days, so we keep only what is needed to compare a season against the one before it. The random visit id inside them expires much sooner than that, on its own, when you close the browser tab.
  • Account data is kept for as long as your account is active. When you delete your account, we delete or anonymize associated personal data, except where we must retain limited records to meet legal, tax, or accounting obligations.
  • Payment records (held by Stripe and the references we keep) are retained as required for financial and legal compliance.
  • Server logs are retained for a limited period for security and operational purposes.

7. Your Privacy Rights

Depending on where you live, you have rights over your personal information. To exercise any of them, email us at snailmail.eco@gmail.com. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising your rights.

If you are in the EU/UK (GDPR)

You have the right to:

  • Access: get a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data ("right to be forgotten").
  • Portability: receive your data in a structured, commonly used, machine-readable format and have it transferred where technically feasible.
  • Restriction: ask us to limit how we use your data in certain circumstances.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: where we rely on consent, withdraw it at any time.
  • Complain: lodge a complaint with your local data-protection supervisory authority. We'd appreciate the chance to address your concern first.

If you are in California (CCPA/CPRA)

You have the right to:

  • Know / access: request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the parties we share it with.
  • Delete: request deletion of personal information we collected from you (subject to legal exceptions).
  • Correct: request correction of inaccurate personal information.
  • Opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. If this ever changes, we will update this policy and provide an opt-out mechanism.
  • Non-discrimination: we will not deny you service, charge you a different price, or provide a different quality of service for exercising your rights.

You may use an authorized agent to submit a request on your behalf, subject to verification.


8. Security

We take reasonable technical and organizational measures to protect your information. These include encryption of data in transit (HTTPS), hashed passwords managed by our authentication provider, scoped access to our database and storage, and reliance on reputable infrastructure providers (Supabase, Stripe, Render).

However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. Please also remember the public storage disclosure in Section 4 when handling generated files.


9. Children's Privacy

The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13 (or under 16 where a higher age applies under local law, such as in parts of the EU/UK). If you believe a child has provided us with personal information, please contact us at snailmail.eco@gmail.com and we will take steps to delete it.


10. Cookies and Local Storage

We use a small number of strictly necessary technologies: an authentication session to keep you logged in, and a localStorage draft to save your in-progress work on your device. We do not use third-party analytics cookies. While we are running ad campaigns, Google's conversion tag may set an advertising cookie used only to tell which of our ads brought a visitor who then signed up; when we are not running campaigns it does not load. For full details, see our Cookie Policy.


11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, notify you (for example, by email or an in-app notice). We encourage you to review this page periodically. Your continued use of the Service after an update means you accept the revised policy.


12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

snailmail.eco LLC Email: snailmail.eco@gmail.com

We will respond to your request within the timeframes required by applicable law.