Ask Uncle Tuck — Letter Privacy Policy

Version 1.0
Effective date: July 19, 2026

A Letter Is an Act of Trust

When the platform accepts your Letter, you are trusting Uncle Tuck with part of your story. We take that responsibility seriously.

This policy explains what the Ask Uncle Tuck Letter Platform collects when it accepts a Letter, why we collect it, how we use and protect it, when a Letter may be considered for public content, and how you can contact us about your information.

What We Collect

When you use the Letter form, the platform processes:

  • The first name or nickname you provide
  • Your question or story
  • Your email address only if you choose to provide it
  • Your optional private follow-up choice when you provide an email address
  • Your required acknowledgment, the active policy version, and the time your consent is recorded
  • The Conversation you responded to, when you arrived from one
  • Limited technical and security information used to validate your request and help prevent abuse, including form timing, duplicate and abuse indicators, and short-lived protected rate-limit keys

When the platform accepts your Letter, it creates a private Letter record with a permanent Letter ID, received time, initial lifecycle and review states, consent history, and audit history.

The platform briefly processes the request’s network address to create a protected, short-lived rate-limit key. It does not attach the raw network address to your Letter record.

Today, the Letter Platform does not ask for your location, create a returning Writer profile, accept file attachments, or send your Letter to an AI provider for summaries or recommendations.

Why We Use It

We use accepted Letter information to:

  • Create a private Letter record, assign a permanent Letter ID, and confirm that your accepted Letter was received
  • Support human review and moderation by authorized reviewers
  • Use your optional email to send a delivery confirmation if email delivery is enabled
  • Contact you privately about your Letter only if you provided an email and allowed follow-up
  • Preserve the Conversation you responded to, when applicable
  • Detect and help prevent spam, abuse, and duplicate submissions
  • Maintain accountable consent, lifecycle, and audit histories

If we later wish to consider material from your Letter for public content, we must first resolve the required separate permission and human approvals. Sending a Letter alone never gives permission for public use.

We do not sell Letter information or use private Letters for behavioral advertising. We do not currently use private Letters for community-theme analytics or aggregate reporting.

What Happens After Your Letter Is Accepted

When the platform accepts your Letter, it assigns a permanent Letter ID, creates a private Letter record, and places it in an ordinary or restricted review state. A restricted state means the Letter requires closer human review by an authorized reviewer.

Security controls may help determine the initial review state. An automated assessment does not make a final editorial decision or permanently delete your accepted Letter.

Acceptance does not guarantee a personal response, selection, production, or publication. A Letter does not need to become public content to receive a respectful outcome.

Privacy and Public-Use Choices

We keep three decisions separate:

  • Your required acknowledgment allowing the platform to receive and review your Letter
  • Your optional permission for private follow-up when you provide an email address
  • Any later permission for a specific proposed public use

The Letter form does not ask for public-use permission. Sending a Letter never authorizes publication or any other public use.

The public-use process is not currently available. Unless and until that process is implemented and approved, private Letters are not eligible for public use.

If this process is implemented and enabled in the future, each proposed public use must resolve the applicable permission, privacy treatment, sensitivity concerns, and human editorial approval. Approved treatments may include:

  • Attributed: Using the approved name or attribution
  • Anonymized: Removing or changing identifying details
  • Paraphrased: Expressing the idea without quoting the Letter directly
  • Context-only: Allowing the Letter to inform broader content without presenting it as your story

We do not automatically copy a private Letter into an article, podcast, video, Short, or other public content.

Can I Submit Anonymously?

Not completely. The Letter form requires a first name or nickname, but it does not require your full legal name or an email address. You may use a nickname and leave the email field blank.

If the platform accepts your Letter without an email address, it still shows an on-screen confirmation with your permanent Letter ID. Without an email address, we cannot send an email confirmation, contact you privately, or request permission concerning a proposed public use.

When you provide an email address, only authorized personnel with an approved need may access it.

“Anonymous in public” is a possible treatment under the future public-use process, not a choice offered by the Letter form. That process is not currently available, and private Letters are not currently eligible for public use.

Editing for Clarity, Safety, and Privacy

The public-use process is not currently available, so we do not currently edit private Letters for public content.

If this process is implemented, enabled, and a specific public use is separately approved in the future, authorized personnel may edit, excerpt, paraphrase, or remove identifying details only for clarity, safety, length, and privacy.

Any editing must remain within the applicable permission, the approved privacy treatment, and the recorded human editorial approval. We will not intentionally sensationalize your story or change its essential meaning.

Who Can Access Letter Information

Letter information is private by default. Access requires an explicitly assigned platform role, the specific permission required for the information or action involved, and an approved operational need. WordPress administrator status alone does not grant access to private Letter content.

Depending on the operational responsibility, access may be granted to authorized personnel performing editorial review, moderation, privacy administration, or technical operations. Assignment to one function does not automatically grant access to all Letter information.

Security signals, internal notes, assignments, and moderation decisions are private operational records. The platform does not show them publicly or automatically include them in communications to Writers.

Service Providers

We use service providers only for specifically approved operational functions. Before Letter-related information may be sent to a service provider, its purpose and data access must be approved. The provider may receive only the minimum information necessary for that function.

The production hosting environment currently provides the database, storage, security, and maintenance capabilities needed to operate the Letter Platform. When the platform accepts a Letter, the hosting environment processes its private Letter record.

Approved backup systems may process access-controlled or encrypted copies needed for recovery. Provider-specific backup and restore handling remains subject to operational verification before public launch.

Brevo is configured as the site’s email provider, but Letter email delivery is currently disabled. The Letter Platform does not currently send Letter information to Brevo.

Letter analytics are not currently implemented or enabled. The platform does not send private Letter information to public analytics or send Letter content to an AI provider.

How We Protect Letter Information

The platform currently protects Letter information through HTTPS, private-by-default storage, explicitly assigned roles and permissions, server-side validation and abuse controls, accountable consent and audit histories, and privacy-minimized logging.

The production environment currently has backup and restore capability, but a successful Letter restore has not yet been verified. Backup access, restore integrity, and the reapplication of approved privacy changes must successfully complete operational validation before public launch.

Approved incident and recovery procedures define how authorized personnel must contain failures, preserve evidence, and restore trustworthy service. Those procedures do not, by themselves, prove that recovery has been successfully exercised.

No online service can promise absolute security. If a material privacy or security incident occurs, we will investigate and contain it, preserve appropriate evidence, and follow applicable notification and response obligations.

How Long We Keep Letter Information

Our governing rule is to keep Letter information only while an approved editorial, operational, security, consent, legal, or accountability purpose exists.

The platform does not currently run an automated retention-review or deletion workflow. It does not automatically permanently delete an accepted Letter merely because the Letter reaches a certain age.

Before public launch, the retention workflow must be implemented and must successfully complete operational validation against this approved schedule:

  • Active Letter information may remain while review, response, follow-up, or another approved purpose remains active
  • Completed Letter narratives and contact identity must receive a retention review at three years
  • Completed private follow-up and response content must receive a retention review at two years
  • Moderation signals may remain for up to twelve months unless needed for an active incident, investigation, or legal hold
  • Minimum consent, public-use permission, and audit evidence may remain for up to seven years when needed for accountability
  • Approved backup copies must expire through a bounded rotation, and approved privacy deletions or anonymization must be reapplied if a backup is restored

A scheduled review is not automatic deletion. Authorized personnel must determine whether the information still has a documented purpose, should be irreversibly anonymized, or should be securely deleted, subject to applicable legal and operational requirements.

Information may remain longer when an unresolved request, security incident, legal obligation, legal hold, or approved continuing relationship requires it. The retention workflow, its exceptions, provider backup rotation, and restored-backup privacy handling must successfully complete operational validation before public launch.

Your Privacy Choices and Requests

You may contact us to ask us to:

  • Confirm whether we hold information about your Letter
  • Provide an appropriate copy or export
  • Correct inaccurate identity or submission information
  • Stop private follow-up
  • Delete or irreversibly anonymize information when appropriate
  • Review an applicable public-use decision if a public-use process is implemented and enabled in the future

The complete privacy-request workflow is not currently implemented or operationally validated. The platform does not currently provide automated or self-service access, correction, export, deletion, or anonymization.

Before public launch, the privacy-request workflow must be implemented and must successfully complete operational validation for identity verification, request scope, authorization, legal holds, execution, provider and backup effects, audit evidence, and a plain-language outcome.

A Letter ID may help us locate a Letter, but it does not prove identity or authorize access. We will request only the information reasonably necessary to verify the request.

The approved operating targets are to acknowledge a privacy request within five business days and resolve it within thirty calendar days, unless a shorter applicable requirement controls. These targets are not current performance guarantees and must successfully complete operational validation before public launch.

Some minimum evidence may remain when required for security, a legal hold, consent history, or audit integrity. We must explain the outcome and any practical limitation.

If we cannot fulfill a request, you may ask for the decision to be reviewed through the same contact route. When applicable law provides an appeal or regulator-complaint right, the response must explain how to use it.

If You Change Your Mind After Future Public Use

The public-use process is not currently available, and private Letters are not currently eligible for publication through the Letter Platform. The post-publication process described below would apply only if public use is implemented, enabled, and separately approved in the future.

If public use is implemented in the future and you later become uncomfortable with an approved public use, you may contact us to request that the decision be reviewed.

Authorized personnel must review whether content under our direct control can appropriately and feasibly be corrected, further anonymized, unpublished, or removed. The public-use withdrawal and privacy-request workflows must be implemented and must successfully complete operational validation before any Letter-based public use is enabled.

Changing or removing content under our control cannot guarantee that search caches, syndication, quotations, downloads, or third-party copies will disappear. We must explain what we can change, what remains outside our control, and any practical limitation.

A public-use change or withdrawal must preserve the minimum restricted consent, provenance, decision, and audit evidence required for accountability. It does not automatically delete the underlying private Letter; deletion or anonymization requires a separate approved privacy decision.

Children and Minors

Ask Uncle Tuck is a general-audience service and is not directed to children under 13. The Letter form displays a notice that it is not intended for children under 13 and asks anyone under 13 to have a parent or guardian contact us.

The Letter form does not ask for a date of birth, precise age, or age range. The platform therefore does not determine a visitor’s age during ordinary submission.

If you are under 13, please do not submit personal information through the Letter form. Ask a parent or guardian to contact us.

The child-privacy response workflow is not currently implemented or operationally validated. Before public launch, the procedure for handling actual knowledge of personal information submitted by a child under 13 must receive documented Project Owner review under the applicable Review Authority Standard, be implemented, and successfully complete operational validation.

If we learn that personal information was submitted by a child under 13, authorized personnel must restrict access, stop ordinary processing, notify the accountable Privacy Owner, and follow the review-authority-approved deletion or verifiable parental consent process before further use.

A Letter involving a person under 18 must receive heightened privacy and sensitivity review before private follow-up or any future public use. Those actions must remain unavailable for an identified minor until the required workflow is implemented and successfully validated.

The public-use process is not currently available. If it is implemented in the future, we must not publicly identify a minor from a Letter without explicit, legally sufficient authorization and heightened human editorial review.

Sensitive Information and Urgent Safety

Please do not submit passwords, Social Security numbers, bank or payment details, medical records, precise home addresses, or information that could endanger you or another person.

Ask Uncle Tuck is not an emergency service, and the Letter form is not monitored continuously. If you or someone else is in immediate danger, contact local emergency services or an appropriate crisis resource instead of relying on the Letter form.

The Letter form currently displays this safety notice. The urgent-safety and sensitive-information response workflows are not currently implemented or operationally validated.

Before public launch, procedures for credible threats of violence, immediate risk of self-harm, abuse involving a minor, exploitation, and comparable urgent concerns must receive documented Project Owner review under the applicable Review Authority Standard, be implemented, and successfully complete operational validation.

If an accepted Letter appears to present an urgent safety concern, the approved future workflow must restrict ordinary access, notify the accountable safety role using the minimum information reasonably necessary for review, and require prompt human review. Automation must not diagnose a person or make a final external-reporting decision.

We do not ask you to provide sensitive personal information. If an accepted Letter nevertheless contains it, the approved future workflow must limit its use, restrict access when appropriate, avoid unnecessary repetition in notes, email, logs, or analytics, and support an authorized decision to redact, delete, or obtain separate authorization when required.

Exact intervention, external-reporting, and legally required disclosure duties must be established through documented Project Owner review under the applicable Review Authority Standard before public launch.

How We Change This Policy

We may update this policy as the Letter Platform and its approved governance evolve.

A material change must receive documented approval, a new policy version, and an effective date. The approved policy must then be published, verified, and activated through the authorized policy activation process before it becomes effective for new Letters.

Editing or approving policy language does not itself implement, configure, enable, or authorize a platform capability. Any related operational change must follow its own engineering, configuration, validation, and approval requirements.

When the platform accepts a Letter, it records the active policy version and the time your acknowledgment is recorded. A later policy version does not replace, rewrite, or retroactively alter the recorded policy history associated with your Letter.

Changes apply prospectively unless a different treatment is legally required and separately authorized through the applicable governance process.

How to Contact Us About Letter Privacy

For questions about this policy or to submit a privacy request, the currently designated contact address is:

Ask Uncle Tuck Privacy Email: askuncletuck@gmail.com

The dedicated privacy-request workflow, monitored ownership, response handling procedures, and alternate verification path have not yet successfully completed operational validation. They must do so before public launch.

Include your Letter ID when available because it may help us locate your Letter. A Letter ID does not prove your identity or authorize access to Letter information.

Do not send passwords, identity documents, medical records, financial information, or other unnecessary sensitive information by ordinary email. We will request only the information reasonably necessary to verify identity, establish authorization where applicable, and handle the request.

If safer verification is required, we must not ask you to send sensitive identity material by ordinary email. A safer verification path must be implemented and successfully validated before it is offered or relied upon.