Your letters, your choices

Privacy and terms, written for humans.

These notes explain what Asembi keeps, how we use it, and the choices you have while you write and share.

Privacy policy

This notice explains what Asembi collects, why it is used, who receives it, and the choices available to you. It applies to the Asembi website, accounts, letters, public share links, and related support. It is effective September 1, 2026.

Who is responsible

Asembi, operated from Ghana, is responsible for the product data described here. For privacy requests or questions, email support@asembi.page.

Information collected

  • Account data: email address, display name, authentication identifiers, verification state, recent account activity, and account-deletion status.
  • Letter data: titles, content, templates, design choices, opening dates, private sharing tokens, expiration choices, and protection settings.
  • Recipient activity: when a shared letter is opened, reading duration, an anonymous view identifier, source, and browser user-agent string. The letter writer can see opening and reading-time insights.
  • Security data: user agent, email-link activity, authentication events, automated abuse-check results, and blocked-request reasons.
  • Analytics data: page path, page title, device/browser information, approximate location, session identifiers, and selected product events, but only after analytics consent.
  • Connection security: Asembi immediately converts a connection address into a one-way, short-lived rate-limit key. The raw address is not saved in Asembi product or security records or explicitly included in automated challenge checks. Hosting, authentication, and security providers still receive normal connection information when delivering their services.

Why we use it

  • Provide accounts, save and render letters, protect private links, and show writers whether shared letters were opened.
  • Authenticate users, deliver verification or recovery messages, prevent fraud and abuse, and investigate failures.
  • Measure and improve the product after optional analytics consent.
  • Comply with legal obligations and protect users, Asembi, and the public.

Legal reasons for processing

Depending on where you live, Asembi relies on performing the service you request, legitimate interests in security and reliable operation, your consent for optional analytics, and compliance with law. You can withdraw consent without affecting earlier lawful processing.

Letter privacy and sharing

Unprotected letter content is stored so Asembi can display it. When you add a passcode, the letter body is encrypted in your browser before it is saved. Asembi stores the encrypted body and an encrypted owner-unlock record, while the owner's browser can retain the passcode locally. Anyone with a valid private link, and any required passcode, may be able to open the letter. Do not share a private link more widely than intended.

Service providers and disclosures

Asembi does not sell personal data or use letter content for advertising. Data is disclosed only as needed to:

  • Account and data-service providers: authentication, database storage, server processing, and transactional account messages.
  • Hosting providers: website delivery, server routes, and operational logs.
  • Security providers: automated abuse detection during protected authentication requests.
  • Analytics providers: optional usage measurement after consent. Advertising features and ad personalization remain disabled.
  • Authorities or other parties when required by law, necessary to protect rights and safety, or involved in a legitimate business transfer.

These providers may process data outside your country. Their locations and legal protections can differ from those where you live. Contact Asembi for current transfer details relevant to your request.

How long data is kept

  • Account, profile, letter, and encrypted unlock data remain while the account or letter is kept.
  • Letters moved to the recycle bin remain until the writer permanently erases them, restores them, or deletes the account.
  • An account-deletion request disables the account immediately and starts a 30-day recovery period. Account, profile, nested user data, and letters are then scheduled for deletion.
  • Public-letter view records currently have no fixed automatic expiry. A writer or recipient may request their deletion.
  • Blocked authentication logs are limited to the latest 250 records. Email-link security records can remain after their short-lived links expire and may be overwritten by later requests or removed during maintenance.
  • Optional analytics user-level and event-level data is kept for no more than 14 months. Aggregated reports may remain longer. Hosting records follow the provider's operational retention schedule.
  • Security, transaction, dispute, and legally required records may be kept longer where necessary.

Your choices and rights

You can edit your profile and letters, revoke a sharing link, change cookie consent, move letters to the recycle bin, permanently erase individual letters, or schedule account deletion from the product. Depending on local law, you may also request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Email support@asembi.page; Asembi may need to verify your identity. You may also complain to the data-protection authority where you live. In Ghana, this is the Data Protection Commission.

Children and policy changes

Asembi is not intended for children under 16, and they should not create an account or submit personal data. If you believe a child has done so, contact Asembi. Material changes to this notice will be posted here with a new effective date and, where required, a more direct notice or renewed consent.

Terms of service

These terms are effective September 1, 2026. By using Asembi, you agree to them. If you do not agree, do not use the service.

Eligibility and accounts

You must be at least 16 and legally able to agree to these terms where you live. Use a valid email address, provide accurate information, protect your account and private links, and notify Asembi if you suspect unauthorized access.

Your letters

You keep ownership of the content you create. You give Asembi a limited permission to host, process, render, back up, and transmit that content only as needed to operate the service and honour your sharing choices. You are responsible for having the right to use the content you upload and for deciding who receives a link or passcode.

Acceptable use

Do not use Asembi to break the law, threaten or exploit people, infringe intellectual-property or privacy rights, distribute malware, evade security controls, scrape the service, overload it, impersonate another person, or send unlawful spam. Asembi may restrict access or remove content when reasonably necessary to stop abuse, meet legal duties, or protect the service and its users.

Service changes and availability

Asembi may repair, update, suspend, or discontinue parts of the service. Reasonable notice will be given for material changes when practical. The service is provided on an "as available" basis, and uninterrupted or error-free operation is not guaranteed.

Responsibility and liability

To the extent allowed by law, Asembi is not responsible for indirect, incidental, or consequential loss caused by use of the service, a recipient's handling of a shared letter, third-party services, or events outside reasonable control. Nothing here excludes liability or consumer rights that cannot legally be excluded.

Ending use, law, and contact

You may stop using Asembi or schedule account deletion at any time. Ghanaian law governs these terms to the extent permitted, while mandatory protections in your home country continue to apply. Before starting a formal claim, contact support@asembi.page so there is a chance to resolve the issue. Changes to these terms will appear here with a revised effective date.

Cookies and device storage

Asembi uses cookies and similar browser storage to sign users in, protect the service, save work on a device, remember privacy choices, and, with consent, measure usage.

Cookies in use

NamePurposeExpiration
authEssential signed authentication token used by protected server routes.About 1 hour; refreshed while the signed-in session continues
asembi_cookie_consentRemembers whether analytics cookies were accepted or rejected.180 days
_ga, _ga_E3D5JPTYGDOptional analytics identifiers used to distinguish visitors and maintain session information. Set only after consent.Up to 2 years, subject to browser limits

Other storage and security technology

  • Authentication services can use browser storage to maintain the signed-in session.
  • Email-link sign-in temporarily stores the email address in local storage until sign-in finishes or the request is cleared.
  • Asembi uses local storage for in-progress drafts, the owner's local encryption vault, and locally remembered owner passcodes. This stays on that device until the product or browser clears it.
  • An automated security challenge processes technical signals and may use essential storage when a challenge is required.
  • Hosting, data-service, and security providers can create short-lived operational or security logs when requests reach the service.

Analytics choice and browser signals

Optional analytics remains off until you choose it. Rejecting it does not affect sign-in, letter creation, private sharing, or security checks. Asembi does not allow third parties to track people across unrelated services for advertising. It does not currently respond automatically to browser Do Not Track or Global Privacy Control signals; the cookie panel is the controlling choice for optional analytics.

Manage your cookie choice

You can reopen cookie settings at any time and change your analytics preference without affecting essential sign-in or security cookies.

Clearing cookies in your browser resets your choices and asks for a fresh selection on your next visit.