Privacy statement
Last updated 7 September 2026
This is a translation, provided for convenience. The Dutch version is legally binding; where they differ, the Dutch text applies.
This statement covers the Letrin app and this website.
In short
- The photo of your letter never leaves your phone; the text is read on the device itself.
- Only the text you approve on the redaction screen is sent, and no copy of it is kept.
- No account, no sign-in, no profile.
- This website sets no cookies and does not follow you.
Controller
Swendoz Studio, a sole proprietorship under Dutch law.
Postal address: TDPB 72922169, c/o Immobilien Jürgen Hoddenkamp, Asselner Hellweg 116, 44319 Dortmund, Germany. Privacy and data requests: [email protected]. Everything else: [email protected].
What we process
The text of your letter. The photo is read on your phone and is not uploaded. Only the redacted text you approve goes to our function and on to the AI provider, solely to write the explanation. Basis: consent (art. 6(1)(a) GDPR), which you can withdraw in the settings. Retention: we do not keep this text.
A device value. To count per device how many letters have been explained and how many requests are made in a day, we receive a value derived from the device. We keep only a hash of it, next to those counts: free letters used, letters used in the current subscription period, bought letters used, and today's requests. That record cannot be traced to a person and is used for nothing else.
There is a limit on requests per device per day. Above it, further requests are refused for the rest of that day, automatically; that is a limit that resets by itself, not a block. In the event of misuse we may also attach a block to the same record, after which the device can no longer use the service. By misuse we mean, for example, working around the limits, automated use, or use that puts a disproportionate load on the service. A block hangs on the device, not on a person: we do not know who uses the device and record no name, e-mail address or other contact detail for it. A block is set by hand, after our own assessment. If you disagree, write to [email protected]. Basis: legitimate interest in preventing misuse of the service and in protecting its availability and its cost (art. 6(1)(f) GDPR). Retention: for as long as the app is offered.
Your message to us. If you write to us, we keep your message and e-mail address in order to reply.
The app settings hold a support code: the anonymous number the store gave that installation. If you send it along, we can check what was actually bought when something goes wrong with a payment; without that code we cannot. The code is then part of your message and is kept with it. Sending it is up to you. Basis: legitimate interest in answering enquiries (art. 6(1)(f) GDPR), or performance of the contract for questions about a purchase (sub b). Retention: no longer than is needed to deal with your question and to be able to look back at earlier contact about the same matter.
Your purchases. Apple and Google collect the payment; we do not see your payment details. RevenueCat records that an anonymous installation has a running subscription or has bought a pack. When you ask for a letter you have paid for, the anonymous customer number RevenueCat created for this installation travels with the request, so that we can check with RevenueCat what was actually bought. Of that number we keep only a hash, next to the count of paid letters already used, so that the same purchase cannot be spent a second time from another phone. RevenueCat's answer (whether a subscription is running, which period, how many letters were bought) is kept for at most two days next to those hashes, so the app keeps working if RevenueCat is briefly unreachable. Basis: performance of the contract (art. 6(1)(b) GDPR). Retention: the hashes and counts for as long as the app is offered; RevenueCat's answer at most two days. What Apple, Google and RevenueCat keep about the purchase itself is governed by their own terms.
This website. There are no cookies on this site. Page views are counted twice, by ourselves and by a measurement service, DataFast. Neither stores anything lasting on your device. Our own count records which page it was, in which language, what kind of device you use (phone or computer) and which website you came from; of that last one we keep only the domain name, never the full address. Distinct visitors are told apart by a hash that changes daily and is deleted within a day and a half. DataFast runs in its cookieless mode: it receives the address of the page, the website you came from and the type of browser and device, and it tells visitors apart by a hash of, among other things, your IP address and browser, made with a key that changes every day, so that DataFast too cannot recognise you from one day to the next. Only while the tab is open does it keep a session number in the browser. If your browser sends "Do Not Track", neither count includes you. The network the traffic passes through and the server itself also record standard traffic data, including your IP address. Which parties those are is listed below under Processors and transfers. Basis: legitimate interest in an available, secure site and in understanding how it is used (art. 6(1)(f) GDPR). Retention: traffic data, no longer than thirty days; the counts at DataFast, for as long as we use that service.
Creator links. A link beginning with /r/ is a creator link recommending Letrin. Such a page forwards you to the App Store or Google Play, passing the creator's name as a campaign token, so that Apple and Google can count on their side how many installations follow from that link.
On our side we count three things per day and per creator: how often the page was opened, whether that happened on a phone or on a computer, and how often the App Store or Google Play was tapped afterwards. The device is among them because you do not install an app from a computer; without that distinction the number of taps says nothing.
It goes no further than those three counts. Nothing is stored on your device, on these pages we do not even build the visitor hash we use elsewhere, and we do not record here which language you read or which website you came from. Opening the same page twice is therefore indistinguishable to us from two different people. What remains is a daily count per creator in which nobody can be recognised. Basis: legitimate interest in being able to see whether a recommendation works (art. 6(1)(f) GDPR).
What does not happen
- We do not sell or rent personal data.
- Submitted text is not used to train AI models.
- No advertising, no cross-app tracking, no profiles.
- No automated decisions are taken about you; article 22 GDPR does not apply.
Processors and transfers
- Anthropic PBC (United States): the AI model that writes the explanation. Receives only the redacted text and the language you chose.
- Google Ireland Limited (Firebase, Google Cloud): the app's function and database, in region
europe-west4in the Netherlands. - OVH Hosting Limited (Ireland): the server this website runs on. That server stands in Frankfurt, Germany.
- Cloudflare, Inc. (United States): the network this website's traffic passes through before it reaches our server. It sees your IP address and the address of the page you request.
- Supabase, Inc. (United States): the database behind this website's counts and creator links, and also where a message from the contact form arrives. The project itself runs in the European Union.
- JustShipIt Pte. Ltd. (DataFast, Singapore): the measurement service for this website. Receives the address of the page, the website you came from, the type of browser and device, and your IP address. Its infrastructure is largely in the United States.
- RevenueCat, Inc. (United States): subscription management.
A data processing agreement is in place with each party. Transfers outside the European Economic Area, to the United States and to Singapore, rest on the European Commission's standard contractual clauses, supplemented where applicable by certification under the EU-US Data Privacy Framework. A copy is available on request via [email protected].
What stays on your phone
Your letters, their explanations, your replies and your settings are held only on your device, in an encrypted database whose key sits in the device keystore. We have no access to it. Deadline reminders are likewise scheduled on the device only. On Android the app is excluded from the system backup, so that database does not leave the phone that way either.
Your rights
You have the right of access, rectification, erasure, restriction and portability, and the right to object to processing based on legitimate interest. Consent can be withdrawn at any time.
Most of it is on your own device and you delete it yourself in the settings. For the rest, write to [email protected]; we respond within one month. A hash cannot be linked to you, so these rights cannot be exercised over it.
You may lodge a complaint with the Dutch Data Protection Authority or with the supervisory authority of your country of residence.
Security
The database on your device is encrypted and the key is managed by the operating system. Traffic to our function runs over TLS and is verified with Firebase App Check. Our own records hold hashes rather than the underlying values.
Children
Letrin is intended for users aged 16 and over. We do not knowingly collect data from younger persons.
Changes
If this statement changes, the date above this page changes. The app does not show the new version; where a change affects you, we say so in the release notes of the update that brings it.
Contact
Privacy: [email protected] · Everything else: [email protected]
