Privacy Policy
Last updated: 24 August 2026
The short version: Letterlock reads your mail to draft replies to it. Identifiers are stripped out before any text reaches an AI model, your Google token is encrypted under two keys held by two different machines, and we do not sell, share, or train on anything. What we cannot honestly claim is that we are technically incapable of seeing your mail — that claim depends on a deployment step that is described precisely in “What we can and cannot see” below.
1. Who is responsible
The controller for the processing described here is the provider named in the Imprint. Contact details are there; data-protection questions can go to the same address or through the contact form.
2. What we process, and why
| Category | What it is | Why | Legal basis |
|---|---|---|---|
| Account identity | Your Google email address, name, and the opaque handle we index you by. | To have an account at all, and to know whose mailbox is whose. | Art. 6(1)(b) — performance of the contract |
| Google access | An OAuth refresh token for Gmail and Calendar, stored only in encrypted form. | Reading the mail we draft replies to, and writing those drafts back. | Art. 6(1)(b) |
| Mail and calendar content | Message bodies, headers, threads, and calendar events, fetched as needed. | Drafting a reply requires reading what it replies to. | Art. 6(1)(b) |
| Your settings | Timezone, chosen AI provider, whether auto-scheduling is on, whether the PII analyzer is on, notification target. | Doing what you asked in the way you asked for it. | Art. 6(1)(b) |
| Voice profile and personal context | Text you write or generate describing how you write and what the assistant should know about you. | Making a draft sound like you rather than like a chatbot. | Art. 6(1)(b) |
| Telegram chat id | The chat you linked, if you linked one. | Sending the notifications you asked for. | Art. 6(1)(a) — consent, withdrawable by unlinking |
| Billing state | Whether a subscription is active, and the customer id Polar gave us. | Knowing whether to run. We never see your card. | Art. 6(1)(b) |
| Audit log | Timestamp, account, which setting changed, the source IP and browser user-agent of the change. Field names only, never field values. | So that a change to your account can be reconstructed, by you or by us, if something goes wrong. | Art. 6(1)(f) — our and your interest in an account that has a history |
| Contact form | The message, and a name and email if you give them. | Answering you. Delivered to the operator over Telegram. | Art. 6(1)(f) — responding to an enquiry you started |
3. What leaves this server, and in what shape
Before any text reaches an AI model, a masking step replaces identifiers — your
name, email addresses, phone numbers, contact names — with placeholder tokens such as
[PERSON1]. The mapping back is held here and the draft is restored before it is
written to your Gmail. The AI provider sees the masked text and nothing else.
Two honest limits on that. First, masking is not perfect: it is measured against a public test corpus whose recall we publish, and recall is not 100%. Your own name and addresses are matched literally rather than only by a statistical model, so those are always caught, but a detail in the body of a message may not be. Second, masked text is pseudonymised, not anonymised. Under the GDPR it is still personal data, and we treat it as such. We do not claim otherwise.
Which provider receives that masked text is your choice in Settings, and the choices differ in kind, not just in name — one of them runs the model inside a hardware enclave and one does not. The table in section 6 says which is which.
4. What we can and cannot see
Your Google token is encrypted twice: an inner layer keyed inside the service, and an outer layer held by a separate co-signer machine that has never seen the token and cannot read what it unwraps. Neither key is on the host filesystem, and reading your mail requires compromising both machines at once. Everything in your account directory is ciphertext; the only plaintext file is the list of which accounts exist.
What that does not yet amount to: the strongest version of this claim — that the operator is technically incapable of reading your mail, provable by an attestation report you can check yourself — depends on the service running inside the hardware enclave it is built for. Until the page you are reading is served from that enclave and its attestation report is published, treat the guarantee as “two keys on two machines, and an operator who does not look” rather than as “an operator who cannot look”. We would rather say this plainly here than have you infer it later.
5. How long we keep things
| What | How long |
|---|---|
| Your account, token, settings, voice profile, personal context | Until you delete the account. See section 8 for what deletion does. |
| Mail and calendar content | Not stored. It is fetched, used to produce a draft, and dropped. What persists is a cursor saying how far through your mailbox we have read. |
| Audit log | 180 days, then pruned automatically. |
| Co-signer log of granted unwrap requests | 30 days. |
| Co-signer log of refused requests | 365 days — a refusal is a security event and outlives a routine grant. |
| Contact-form messages | They live in a Telegram chat, and are kept for as long as that conversation is useful. Ask and we will delete yours. |
6. Who else is involved
These are our processors and sub-processors. The hostnames are exhaustive: the service runs behind an egress allowlist, so these are the only places anything here can connect to, and that list is generated from the code rather than written by hand.
| Who | What they do | Where / transfer basis |
|---|---|---|
Google Ireland Ltd. / Google LLCgmail.googleapis.comcalendar.google.comaccounts.google.comoauth2.googleapis.comwww.googleapis.com |
The mailbox and calendar the service acts on: sign-in, the messages it reads, the drafts it writes back, the events it creates, and the push notification that says new mail arrived. | [location to confirm] [transfer basis to confirm] |
DeepSeekapi.deepseek.com |
Writes the draft, when it is the provider you selected. It is the current default. It receives masked text and is not an enclave provider: it can read whatever the masking did not catch. Settings lets you change this. | [location to confirm] [transfer basis to confirm] |
NEAR AIglm-5-2.completions.near.aigpt-oss-120b.completions.near.ai |
Writes the draft, when you select one of the two enclave models. It receives masked text, inside a hardware enclave whose attestation report this server checks before each session. | [location to confirm] [transfer basis to confirm] |
Polar Softwareapi.polar.shsandbox-api.polar.sh |
Takes the payment, as Merchant of Record, and tells this server whether a subscription is live. It holds the billing relationship and the payment details; this server never sees a card number. | [location to confirm] [transfer basis to confirm] |
Telegramapi.telegram.org |
Carries notifications to you, if and only if you linked a chat, and carries contact-form messages to the operator. Message text and your chat id pass through Telegram in the ordinary way, so do not put anything in a notification you would not put in a Telegram message. | [location to confirm] [transfer basis to confirm] |
Phala Networkpccs.phala.network |
Runs the confidential-compute host the service is being moved onto, and serves the certificates used to check an attestation quote. Phala operates the machine and, by construction, cannot read what runs inside the enclave. | [location to confirm] [transfer basis to confirm] |
Hetzner Online GmbHcosigner.morganrivers.com |
Runs the servers: the co-signer that holds the outer half of your token's encryption, and the current deployment of the service itself. Hetzner holds ciphertext and neither key. | Germany No transfer: processing is in the EU. |
We do not sell personal data, we do not share it for advertising, and nothing from your mailbox is used to train any model, ours or anyone else's.
7. Transfers outside the EU
Where a processor above is established outside the EU or EEA, the transfer rests on the mechanism named in that row — an adequacy decision, or Standard Contractual Clauses in the processor's data-processing agreement. Rows still showing a marked blank are ones we have not yet finished confirming, and this policy is not final until they are filled in.
8. Deleting your account
The Account page has a delete button, and it does the following, in this order: it withdraws our access at Google so the grant no longer exists on their side, stops the mailbox watch, destroys the encryption key for your account directory, and then deletes the directory. Because the key goes first, a backup taken this morning does not become readable by being restored — what is left is ciphertext nobody holds a key for.
One thing deliberately survives: the audit rows, including the row saying the account was deleted. A log a user can empty by asking is not a log. Those rows carry your address and are pruned on the 180-day schedule above.
Deleting the account does not cancel a subscription held at Polar. Cancel that through the billing portal, or ask us.
9. Your rights
Under the GDPR you have the right to access your data (Art. 15), to correct it (Art. 16), to have it erased (Art. 17), to restrict processing (Art. 18), to receive it in a portable form (Art. 20), and to object to processing based on our legitimate interests (Art. 21). Where processing rests on consent, you can withdraw it at any time without affecting what was done before.
Most of these you can exercise yourself: Settings and the Voice DNA and Personal information pages show and edit what we hold, and Account deletes it. For anything else, use the address in the Imprint. You also have the right to complain to a supervisory authority — ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
10. Cookies
Three, all of them necessary for the site to work, none of them analytics or advertising. That is why there is no consent banner: § 25 Abs. 2 TTDSG does not require consent for cookies strictly necessary to provide a service you asked for. There are no third-party scripts, fonts, or trackers on any page — everything the browser loads comes from this server.
| Name | Lifetime | What it does |
|---|---|---|
letterlock_session | 30 days | Keeps you signed in. Signed, HttpOnly, SameSite=Lax, Secure. |
letterlock_oauth_state | 30 minutes | Ties a Google sign-in you started to the answer that comes back, so somebody else's callback cannot land in your session. |
letterlock_checkout | 1 hour | Ties a checkout you started to the subscription that comes back from Polar, so a checkout id from a browser cannot claim another account. |
The web server keeps no request log of its own. Your IP address is recorded in one place, the audit row for a change you made, and used in one other, the rate limit on the contact form. Signing in and signing out are not changes and are not recorded at all, so there is nowhere that says when you were here.
11. Security
How this is built, and what each part does and does not protect against, is described on the About page and in the public source. If you find a security problem, the contact form reaches a human.
12. Children
This is not a service for children. Do not use it if you are under 16.
13. Changes
If this policy changes in a way that affects what happens to your data, we will say so by email or notification before it takes effect, not only by editing this page. The date at the top is the date of the last substantive change.
See also the Terms of Service and the Imprint.