anonymous postcard exchange
The correspondence feature is optional and is only activated after you choose to participate.
identity
The system does not use the IP address as a persistent identifier. The browser receives a random identifier and bearer token stored locally. The backend may use approximate network-derived location to calculate the journey of a postcard, but the included example does not store the raw IP address.
location
Only country and rounded coordinates are stored for approximate distance calculations. The other person only sees a broad area and estimated arrival time, never coordinates.
messages
Messages are limited to 500 characters. A person can maintain up to three correspondence lines at once. Deleting a line makes the example backend delete that conversation for both participants.
before publishing
Define your retention policy, controller contact details and a process for access or deletion requests before making this feature public.