Plain-language policy

Privacy at Make a Hug

You do not need an account to create or open a package. This page explains what stays in your browser, what Make a Hug stores after link creation, and what third-party services process.

Drafts stay on your device

Before you create a share link, your draft—including selected photos, audio and drawings—stays in this browser and is not uploaded to Make a Hug. Some browsers may keep only the text if they cannot save media locally. During Waffo checkout, this browser stores a checkout proof and recovery code in session and local browser storage so it can verify the same payment after a return or reopen without asking you to pay again; the hosted checkout URL is kept only for the browser session. The proof and code are removed after the private link is safely saved here, after a checked checkout reaches a terminal unpaid or refunded state, after a recovered package is deleted, or when you clear this site’s browser data. They may remain after the hosted checkout expires so a delayed successful payment can still be recovered.

What is stored after you create a link

After Waffo confirms payment, Make a Hug automatically creates your private link and securely stores the recipient and sender names you entered, the cover message, your goodie text and links, and any uploaded photo, drawing or audio file. This lets the recipient open the package from another device.

The package is not listed in a directory and package pages are marked not to appear in search engines. Anyone who obtains the long random URL can still open it. A private link is not end-to-end encryption, so do not include passwords, financial records, medical records or anything that would be dangerous if the link were forwarded.

Deletion, recovery and retention

When a package is created, the deletion control and recovery code are saved in the creator’s browser. Make a Hug stores protected verification values rather than the usable deletion control or plain recovery code. Using “Delete forever” removes the package, its uploaded files and its recovery mapping. Clearing this browser’s site data may remove the creator’s ability to delete the package, so the private link and recovery code should also be saved somewhere safe.

Created packages are intended to remain available for at least 12 months from creation. A package may be removed earlier when the creator deletes it, a related payment is refunded, the package violates the Terms of Use, removal is required for safety or law, or continued storage is no longer reasonably possible as part of operating the service.

Service and security data

Cloudflare processes network information needed to deliver and protect the site, which can include IP address, request time, browser details and security signals. Make a Hug keeps a limited sample of technical logs to maintain reliability, prevent abuse and investigate errors. These logs do not include care-package message content.

Analytics

The public site uses Plausible Analytics, Microsoft Clarity and Google Analytics 4 to understand visits, performance and whether the creation flow works. These providers may process device, interaction, approximate location and network information under their own privacy terms. The private package page opened by a recipient does not load these analytics scripts. On the maker, areas that can show draft content, previews or saved private links are masked from Clarity session recordings. Custom analytics events contain only coarse details such as goodie type or item count—not names, messages, package URLs, private package IDs or deletion keys.

Waffo payment

A one-time Waffo payment at the price shown before checkout is required to generate each private package link. Waffo acts as the payment provider and merchant of record, and processes payment, billing, tax and receipt information under its own privacy terms. Make a Hug does not receive or store full payment-card details or copy the buyer email into the package record. It stores checkout, order and payment references, status, amount and currency so each completed payment can create only one link. Recipients do not pay to open a finished package.

Your choices

Children and sensitive content

Make a Hug is not directed to children under 13 and should not be used to store sensitive personal records. Only upload content you have permission to share.

Questions

Questions about this policy can be sent to support@fingerframeai.com.

Back to Make a Hug