Privacy
Privacy Policy
Effective September 7, 2026. Piloxa exists to mail a document and keep the proof. That job decides what we collect: your letter, where it goes, and what happened to it. We do not sell any of it, we do not use it for advertising, and we do not train models on it.
Who we are
Piloxa is a service of Decentralized Publishing LLC, 92 Corporate Park, Ste C #1083, Irvine, California 92606, United States. Questions about this policy go to support@piloxa.com.
What we collect
- Your account. The email address you sign in with, and a one-way hash of your password. We never store the password itself.
- Your documents. The file you upload or the letter text you approve, stored as a locked version with its SHA-256 fingerprint and page count. The fingerprint is what lets anyone confirm later that the file mailed is the file you saw.
- Recipient details. The name, company and postal address the letter goes to, and the result of checking that address against postal records.
- Execution records. The service chosen, the price you authorized, the vendor's job number, the USPS tracking number, every tracking event, and the return receipt when it arrives.
- Payment records. The amount, the currency, the payment status and the Stripe identifier for the charge. Card numbers never reach our servers: the card form is Stripe's, and the card details travel from your browser to Stripe.
- How you arrived. If an AI assistant prepared the letter, we record which assistant, how we identified it, and how confident that identification is. This tells us which assistants people actually use. It is not tied to any profile of you.
- Ordinary server records. Request times, page addresses and error records, kept briefly so the service can be operated and defended against abuse.
Cookies
Two, both first-party, neither for advertising. A sign-in cookie that keeps you signed in to your workspace, and an arrival cookie that remembers which assistant or link sent you, so the record of your letter shows where it came from. We run no advertising trackers and no third-party analytics scripts.
Who else sees your letter
Only the parties that have to, and only what they need:
- The print-and-mail vendor receives your document, the recipient address and the return address, because it prints the letter and hands it to the Postal Service. We tell you which vendor is in use for your letter before you pay, and it appears on the record afterwards.
- The United States Postal Service receives the envelope, the addresses and the certified-mail service request, and returns the tracking events and the electronic return receipt.
- Stripe receives the payment. Stripe is the card processor and holds the card details under its own privacy policy.
- Our hosting provider stores the encrypted server on our behalf and does not use the contents.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we hand it to a government or a court only when a subpoena, warrant or equivalent order requires it — in which case we tell you unless the order forbids it.
How long we keep it
Evidence is only useful if it survives, so the record of a mailing — the locked document, the fingerprint, the addresses, the tracking history and the receipt — is kept for as long as your account is open, and for six years after a mailing unless you ask us to delete it sooner. Payment records are kept as long as tax and accounting rules require. Server records are kept for 90 days.
Your choices
Write to support@piloxa.com and we act within 30 days. You can ask for a copy of everything we hold about you, ask us to correct it, ask us to delete your account and its documents, or ask us to stop using your email for anything other than service messages. California residents have these rights under the California Consumer Privacy Act, and we do not charge you or degrade the service for using them. Deleting a mailing record removes your copy of the evidence: the Postal Service and the vendor keep their own records under their own rules, and we cannot delete those.
Security
Traffic runs over HTTPS. Documents are stored outside the web root and are served only to the signed-in account that owns them. Passwords are hashed. Payment card details are never in our possession. No system is perfect, and if a breach affects your data we tell you and the authorities that require it.
Children
Piloxa is for adults and is not directed at anyone under 18. We do not knowingly collect information from children.
Changes
If this policy changes in a way that affects what we collect or who sees it, we post the new version here with a new effective date and email account holders before it takes effect.