Privacy, in plain words
Your plan is built and saved in your browser. BanMyself does not receive the personal details you enter into the plan builder. Here is what stays on your device and what you choose to share.
Your personal information
The name, date of birth, address, phone number, destination choices, checkmarks and program progress you enter are saved together in your browser's local storage. Program records may include the term, dates, operator reply method and reference you choose to enter. They are your own records; BanMyself does not independently verify enrollment. Drafts and printed documents are generated on your device. No BanMyself account is required. Someone with access to that browser profile may be able to open your saved plan. Use the plan's clear-and-start-new control or clear this site's browser data to remove it from that device. A visible message tells you if browser saving fails.
Optional ID photos stay in the current page's memory and are not uploaded or saved in local storage. Closing or reloading the page clears them. Printed pages and files you save through your browser remain under your control.
Prefill links
Links made on the Help someone you love page and the plan's cross-device link carry personal details after a # symbol. The cross-device link also carries destination choices, checkmarks and program records, including any dates or references you entered. It never carries ID photos. The browser does not include that fragment in its request for the web page. The page validates the link, asks before replacing an existing plan, saves the accepted plan when browser storage is available, and removes the fragment from the visible address bar. Imported progress remains self-reported.
The link is not encrypted. Anyone who receives the full link can read its contents, and the app you use to send it may retain it. Share it only with the person it is for. ID photos are not included.
Cookies and analytics
The site code does not add cookies, analytics, advertising pixels or fingerprinting. Hosting and font services still receive the connection information needed to serve a page, such as an IP address. Your entered plan details are not part of those requests.
Third parties
Fonts load from Google Fonts. Donations are processed by Stripe on its own pages. External links take you to organizations with their own privacy policies. Opening an email draft, sharing a plan link or sending a document gives information to the app or recipient you choose. Review the content before sharing it.
Donations
Stripe makes donation transaction details and contact information supplied at checkout available to the account owner for receipts and administration. Those records are separate from your locally saved plan. We are not yet a nonprofit; donations are not tax-deductible.
Assisted delivery preview
The separate assisted-delivery preview is restricted to invited testers using synthetic documents. Production sending is disabled. It does not read your saved plan or ID photos. Before approving anything, you see the exact selected file, form revision, program recipient, actual test destination, provider, zero-dollar test ceiling, attempt limit and expiry. The approval boxes start unchecked. Creating an authorization does not send the file; sending is a separate action.
When you send an approved test, the PDF passes through a Vercel function to the selected provider: Lob for a mail proof, Sinch for its test fax number, or Resend for its test email inbox, when that provider is configured. BanMyself does not save the PDF in its database or rewrite its bytes. The file stays in browser and request memory during processing. The application does not log document content or raw provider/callback messages.
Neon stores encrypted authorization scope, a protected hash of the private access credential, document fingerprint, job status and limited provider receipt information. Sending authority expires after 24 hours; status access expires after seven days. While access is active, you can cancel unsent attempts or delete the active BanMyself record from the preview. Daily cleanup aims to delete expired BanMyself records within the following 26 hours. Outages can delay deletion. A separate monitor checks for missed cleanup twice daily; delays or outages can also delay detection. A private access credential is saved in this tab's session storage. A copied access link puts that credential after the # symbol. Anyone with it can view the record, cancel work or use remaining authorized attempts. No PDF is saved in session storage or included in that link.
Deleting our record cannot recall an accepted provider job or delete that provider's records or backups. Each provider's retention terms apply separately. No notary service is connected in this preview, and it does not perform identity verification or notarization. Any future notary service must explain its own required record retention before you choose it. Provider delivery evidence does not establish enrollment.
Changes
The DIY plan remains browser-only. Real assisted delivery requires a separate release with verified receiving routes, provider readiness and retention terms. We will update this page before that path opens.
Questions: support line (385) 204-5149 · Last updated September 10, 2026