Dear Babbo

Security

Dear Babbo is designed around private links. The link is the key, so keeping each link private matters.

Private links are the credential

Each list has two independent random links: a child link for choosing a gift and an owner link for managing the list.

Knowing the child link does not reveal the owner link. The child page is intentionally limited to the information needed to view gifts and choose one.

No accounts or recovery

Dear Babbo does not use logins, passwords, or account recovery in the MVP. If the owner link is lost, there is no automatic way back to the list.

Treat the owner link like a private document. Do not send it to the child, post it publicly, or store it somewhere shared.

Indexing and referrers

Private child and owner routes are marked noindex so search engines are told not to index them.

Gift and image links use no-referrer protections where possible so private list URLs are not sent to retailers when someone opens an outbound product link.

What Dear Babbo does not do

Dear Babbo does not process payments, store payment cards, order products, manage shipping, or send emails.

The app is a small private selection tool. Security depends partly on keeping the private links private.