← Home

Privacy Policy

Last updated: September 2026

⚠️ Important Notice: The German version "Datenschutzerklärung" is the legally binding version. This English translation is provided for information purposes only and may not be complete or accurate. In case of any discrepancies, the German version shall prevail.

Scope: This privacy policy applies to both the JustALetter mobile app and this website. Where a section is specific to only one of them, this is indicated.

1. Controller (GDPR Art. 4 No. 7)

Christopher Reinhardt
Potsdamerstraße 9
63322 Rödermark
Germany

E-Mail: support@justaletter.app

2. Data Collection and Processing

When using the main website (Homepage, Legal, Privacy):

  • IP address (automatically)
  • Browser type and version (automatically)
  • Access date and time (automatically)
  • Pages visited (automatically)

Legal basis: GDPR Art. 6 (1) f) (legitimate interest for security and website stability)
Retention period: Automatically deleted server logs (typically 30 days)

3. Authentication Pages (/auth/*)

When using authentication features (email verification, password reset), we process:

  • Email address: For email verification and password reset
  • Verification token: Randomly generated token, stored in Cloud Firestore (retention: max. 24 hours)
  • Reset token: Randomly generated token, stored in Cloud Firestore (retention: max. 1 hour)

User accounts (email address, cryptographically hashed password) are managed via Firebase Authentication. Tokens and related account information are stored in the Cloud Firestore database (see Section 4).

Legal basis: GDPR Art. 6 (1) a) (consent) / Art. 6 (1) b) (contract)
Retention period: Tokens are automatically deleted after single use or expiration
Right to withdraw consent: Where processing is based on your consent (Art. 6 (1) a), you may withdraw it at any time with effect for the future by contacting support@justaletter.app.

4. JustALetter App & Firebase (Google)

The JustALetter app, this website, and their backend functions are operated via Firebase (a service of Google Ireland Ltd. / Google LLC). The following Firebase services are used:

  • Firebase Hosting: Delivery of the website, including access logging (server logs), performance and security information
  • Firebase Authentication: Management of user accounts (email address, cryptographically hashed password) for email verification and password reset
  • Cloud Firestore (database): Storage of verification and reset tokens, related account documents (e.g. the time of the last password reset), and the content you create in the app (see below)
  • Firebase Storage: Storage of your encrypted attachments (see below) and delivery of the app’s design elements (envelopes, letter paper, seals) that we add after a release. When these design elements are fetched, your IP address is transmitted to Google and logged there. The files are cached on your device and are therefore downloaded only once. They contain no personal data and are identical for every user.

How the app processes your data: JustALetter lets two connected people exchange one message per day. To provide this, we process the following in Cloud Firestore (and, for media, Firebase Storage), linked to your account:

  • Account & sign-in: your email address and authentication data. You can sign in with email/password, Sign in with Google, or Sign in with Apple. These are third-party identity providers with their own privacy policies; Apple may forward an anonymized relay email instead of your real address. If you sign in with Apple, Apple may also share your name with us on the first authorization; if provided, we store it so it can be shown to a connection partner instead of an anonymized relay address.
  • Connection & invitations: to use the app you connect with one other person via a short invite code or shareable link. We store the invitation and the link between the two connected accounts. An invite code is valid for 72 hours; after that it expires and can no longer be redeemed.
  • A letter attached to an invitation: you can write a letter before the person it is meant for has an account. The letter is then tied to the invite code and is only delivered once someone redeems that code. Until then we store its content and any attached photos encrypted only (see section 15); the key used for it becomes the key of the connection that is created on redemption. If the code is never redeemed, we automatically delete the content, the attachments and the key once the invitation has expired or you withdraw it, and therefore at the latest 72 hours after it was created, plus the interval of our clean-up job. A copy of the letter stays in your drafts on your device, so nothing is lost to you in the meantime.
  • Messages: the messages you write (and any media you attach) are, by design, transmitted to and visible by the person you are connected with— this is the core purpose of the service. Messages are stored so that you and your connection can read your shared history. Content and attachments are encrypted on your device before they reach us and are stored by us only in encrypted form; see Section 15 for the details and the limits of that encryption. For technical reasons, attached photos are uploaded to our storage (Firebase Storage) – likewise encrypted – while you are still composing, so that sending completes faster; there they are accessible to your account only. If the letter is never sent — for example because you remove the photo or discard or delete the draft — the file is deleted, and in any case automatically after 7 days at the latest.
  • Reported content: if a message is reported, we may access its content to review the report – for encrypted letters we decrypt that specific letter for this purpose. This is only possible for letters a report exists for, is done manually by an authorised person, and is logged. We review reported content manually; we do not currently take any automated moderation action.
  • Push notifications: if you allow notifications, we process a device token via Firebase Cloud Messaging for each device you're signed in on, to notify you of a new message. You can disable this at any time in your device settings.
  • Letters from us (broadcasts):occasionally we write a letter to everyone who uses the app – about a new feature, after an outage, or to say thank you. Such a letter sits in your mailbox like any other and, if you allow notifications, arrives with a push notification. You can turn those off at any time under Settings → Notifications → “News from Just a Letter”, without losing notifications for letters from the people you write with. These are service messages about the app itself, not advertising. For them we store which of these letters were delivered to you and whether and when you opened one. This is only ever evaluated as a total (“how many of the recipients opened this letter”); we do not evaluate individual people, and our tools do not offer it. We use no tracking pixels or comparable techniques for this: the value is produced by the app itself when you open the letter. You may object to the counting at any time; we will then exclude you from it, with no change to the letter or to your mailbox.
  • Promotional messages (only with your consent):separately from the service messages above, we may send you letters with promotional content – for example about paid features or offers. You receive these only if you have first actively opted in under Settings → Notifications → “Offers from Just a Letter”; that switch is off by default. We store that and when you opted in, so that the consent can be demonstrated. You can withdraw it at any time in the same place with effect for the future; the time of withdrawal is stored as well. Without this consent you receive no promotional letters, neither as a push nor in your mailbox.
  • Firebase Crashlytics: to detect and fix technical errors we use Firebase Crashlytics (Google Ireland Ltd. / Google LLC). In the event of a crash, Crashlytics automatically collects non-personal technical data: device model, operating system version, app version, time of the crash, and a stack trace (code location of the error). No user content, messages, or personally identifiable information is transmitted. The collected crash data is transferred to Google in the USA; the safeguards described at the end of this section apply (EU-US Data Privacy Framework, EU Standard Contractual Clauses).
  • Firebase Analytics (app):to analyze app usage we use Firebase Analytics (Google Ireland Ltd. / Google LLC). We collect automatic standard events (e.g. app opens, session length) as well as our own usage events in anonymised, aggregated form – such as that a letter was sent along with non-content metadata (e.g. character count, number of attached photos, whether a drawing was added), screens viewed, and interactions such as opening the premium screen or completing a purchase. We do not collect message content, photos, or any other identifying content. A device-side instance ID is also used. Analytics data is retained for 14 months and then deleted automatically. The data may be transferred to Google in the USA; the safeguards described at the end of this section apply (EU-US Data Privacy Framework, EU Standard Contractual Clauses).
  • Product feedback: we may occasionally contact you by email to ask for your feedback on the app (e.g. what you like or what we could improve). This is not advertising. You can object to such requests at any time by contacting us at support@justaletter.app.

Legal basis: GDPR Art. 6 (1) b) (performance of the service you requested); push notifications additionally rely on Art. 6 (1) a) (consent, granted via your device); letters from us rely on Art. 6 (1) b) (delivering the letter and tracking whether it has been read are part of the service) and, as far as the total number of opens is concerned, on Art. 6 (1) f) (legitimate interest in knowing whether an announcement reached its recipients), and you may object at any time (Art. 21 GDPR); promotional messages rely solely on Art. 6 (1) a) (consent) together with applicable marketing law and are not sent without that consent; Crashlytics relies on Art. 6 (1) f) (legitimate interest in maintaining app stability and security); Firebase Analytics relies on Art. 6 (1) f) (legitimate interest in analyzing and improving app usage); reviewing reported content relies on Art. 6 (1) f) (legitimate interest in platform safety and abuse prevention); product feedback requests rely on Art. 6 (1) f) (legitimate interest in improving our service), and you may object at any time (Art. 21 GDPR).

What happens when you delete your account: Deleting your account immediately removes your user profile (email, nickname, account document), your Firebase Auth account, and any open invitations you created. Any running chapter of an active connection is automatically closed, so that your connected person retains access to the shared letter history: letters you have already sent remain with the recipient, as they form part of the recipient's correspondence.

Deleting a past chapter:Every stretch of time two people are connected forms its own chapter. Ending a connection closes the running chapter; connecting again later begins a new one, and earlier chapters stay separate from it. Once a chapter is closed, you and your connected person can each individually delete it from your app ("Delete chapter"). As long as only one person has deleted a chapter, the messages are retained, since they still form part of the other person's correspondence. Once both people have deleted the same chapter, the associated messages and media are automatically and irreversibly deleted after a retention period of 2 years; other chapters between the same two people are unaffected. During this period the data is no longer visible in the app and is retained solely for the purposes of preserving evidence and of establishing, exercising or defending legal claims, in particular in connection with unlawful content.
Legal basis: GDPR Art. 6 (1) f) (legitimate interest in preserving evidence and in combating abuse and unlawful content).

Legal hold: For content moderation purposes and to enable account restoration at your request, we retain a security record for up to 2 years after account deletion. This record contains your user ID, email address, sign-in methods used, basic account data (nickname, account level, creation date), and the IDs of your former connections. It is accessible only via the admin backend and is automatically deleted after the 2-year period.
Legal basis for the hold: GDPR Art. 6 (1) f) (legitimate interest in combating abuse and illegal content, and in the ability to restore an account at the user's request).

Inactive accounts: We may delete an account that has not been used for 24 months (the app was not opened while signed in to it). Before we do, we notify you at least 30 days in advance by e-mail to the address on file; opening the app once within that period is enough to keep the account. The deletion then takes place exactly like a deletion you request yourself (see above): letters you have sent remain with the recipient, and the security record is kept as described. To determine inactivity we store the time the app was last opened in your account.
Legal basis: GDPR Art. 5 (1) e) (storage limitation) and Art. 6 (1) f) (legitimate interest in not keeping data longer than it is used).

How attachments are stored: Photos and drawings are stored at a resolution sufficient for display in the app. To save storage space we may store attachments, in particular older ones, at a reduced resolution or with stronger compression. The content and visibility of the letters do not change as a result, and attachments continue to be stored exclusively in encrypted form.

Discontinuation of the service: Should we discontinue Just a Letter (see Terms of Use, Section 10), we will announce this at least 30 days in advance. After the announced date we irreversibly delete all personal data, including every letter, photo, and drawing, from our servers (Firebase). The security record described above and the two-year retention of deleted chapters then also lapse. The only exception is data we are required to keep under statutory retention obligations (for example tax or commercial law); such data is deleted once the respective period expires.
Legal basis for deletion: GDPR Art. 17 (1) a) (the purpose of processing no longer applies).

Data processing agreement: A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Google.
Third-country transfer: Firebase/Google may transfer data to the USA. The transfer is based on the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR).
More information: Google Privacy Policy

5. Resend – Transactional Email Service

For sending transactional emails (email verification, password reset), we use Resend ( https://resend.com).

  • Data processed: Email address, verification tokens
  • Purpose: Sending authentication-related emails (verification, password reset)
  • Provider: Resend, Inc., a company based in the United States
  • Data processing agreement: A DPA pursuant to Art. 28 GDPR is in place with Resend
  • Data location: We use Resend's EU data-residency region, so transactional email data is processed within the European Union. Insofar as access from the United States cannot be excluded, such transfers are covered by EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR) and, where applicable, the EU-US Data Privacy Framework.
  • Retention: Email delivery logs are retained for operational purposes; your email address is not stored beyond what is necessary to deliver the message

Legal basis: GDPR Art. 6 (1) a) (consent) / Art. 6 (1) b) (contract)
More information: Resend Privacy Policy

6. RevenueCat – In-App Purchases & Subscriptions

To provide and manage paid features (in-app purchases and subscriptions) in the app, we use RevenueCat ( https://www.revenuecat.com). RevenueCat validates purchase receipts and manages the status of your subscriptions.

  • Data processed: a pseudonymous app user ID, app store purchase receipts or transaction identifiers, purchase and subscription status (e.g. active, expired, renewal date), and technical device and platform data (operating system, app version, country/region)
  • Support requests from the Customer Center:if you contact support through the subscription management screen in the app, your email to us is routed through RevenueCat's servers and enriched with your pseudonymous app user ID, your current subscription status and your device and app version, so that we can identify your case without asking you for these details. RevenueCat thereby also processes your email address and the content of your message. Support requests sent to us directly by email are not affected by this.
  • No payment data: the actual payment is handled exclusively by the Apple App Store or Google Play. Neither we nor RevenueCat receive any credit card or bank account details.
  • Purpose: validating purchases, unlocking purchased features, and managing and restoring subscriptions
  • Provider: RevenueCat, Inc., a company based in the USA
  • Data processing agreement: a data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with RevenueCat
  • Third-country transfer: RevenueCat may transfer data to the USA; the transfer is safeguarded by EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR) and, where applicable, the EU-US Data Privacy Framework.

Legal basis: GDPR Art. 6 (1) b) (performance of the purchase contract / provision of the features you purchased)
More information: RevenueCat Privacy Policy

7. In-App Advertising (Flyers)

In the free version of the app we occasionally show advertising flyers from advertising partners — after an ad-free introductory period, each time before you open a received letter. Users with an active Premium subscription do not see any ads.

No personalized advertising, no tracking. Which flyer is shown is decided by your device alone. The inputs are the language set in the app, the device's region setting, the current date and local time, the operating system in use and the number of letters you have already received, plus a random, weighted rotation. All of these are read and evaluated locally on the device; none of them are transmitted to or stored by us. No evaluation of personal characteristics, no profiling and no cross-device recognition takes place. We do not use an advertising identifier (e.g. IDFA) and therefore do not trigger an “App Tracking Transparency" prompt. Your location is not processed: a device's region setting says nothing about where you actually are.

Anonymous reach measurement. To measure a campaign's performance we count only anonymous aggregate totals per flyer (number of impressions and clicks), both as a lifetime total and per calendar day. These counters are not linked to any user, device or advertising identifier and do not allow any conclusions about individual persons. The language, region and time of an impression are not recorded either.

Limiting how often an ad appears (storage on your device). So that the same flyer is not shown to you repeatedly on the same day, the app stores a simple counter locally on your device, consisting of the flyer's identifier, the current date and the number of times it has been shown. This counter contains no identifier of you or your device, is not transmitted to us or to advertising partners, and is overwritten when a new calendar day begins. Legal basis for the storage on your device: § 25(2) TTDSG, as the storage is necessary to provide you with the ad-financed free version in the data-minimizing form described here.

Controlling the ad-free introductory period. To implement the ad-free introductory period, we maintain a simple server-side counter of the letters you have received. This value is used solely to decide when advertising starts to appear and is not shared with advertising partners.

External links. If you open the link offered within a flyer, an external website operated by the respective advertising partner opens. The advertising partner is responsible for its content and data processing; that partner's own privacy policy applies.

Legal basis: GDPR Art. 6(1)(f) (legitimate interest) in financing the free version of the app through a data-minimizing, non-tracking form of advertising.

8. Google Analytics 4 (Web Analytics)

We use Google Analytics 4 on this website, a web analytics service provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Analytics uses cookies and similar technologies to analyse how visitors use our website.

Data processed:

  • Page views and time spent on pages
  • Device information (browser type, operating system, screen resolution)
  • Approximate location (based on anonymised IP address; the full IP is not stored)
  • Traffic source (e.g. search engine, direct visit, external links)
  • On-page interactions (e.g. scroll depth, clicks on external links)

Consent Mode v2: Google Analytics is configured so that by default it does not set cookies or transmit personal data. Tracking is only activated when you actively consent via our cookie banner. If you decline, Google Analytics only sends anonymous ping signals without setting any cookies.

Legal basis: GDPR Art. 6 (1) a) (consent); § 25 (1) TTDSG (consent for cookie placement)
Retention period: Analytics data is stored in Google Analytics for 14 months by default, after which it is automatically deleted.
Withdrawal: You can withdraw your consent at any time by clicking "Decline non-essential" in our cookie banner, or by clearing your browser's local storage (key cookie-consent). No new analytics data will be collected after withdrawal.
Data processing agreement: A DPA pursuant to Art. 28 GDPR is in place with Google.
Third-country transfer: Data may be transferred to the USA, safeguarded by the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR).
More information: Google Privacy Policy | Google Analytics Opt-out Browser Add-on

9. Contacting Us by Email

If you contact us by email (e.g. at support@justaletter.app), we process the data you provide (email address, name if given, and the content of your message) in order to handle your request.

Legal basis: GDPR Art. 6 (1) b) (pre-contractual or contractual measures) or Art. 6 (1) f) (legitimate interest in responding to inquiries)
Retention period: We delete this data as soon as it is no longer required to process your request, unless statutory retention obligations apply.

10. Cookies, Local Storage & Consent

This website uses strictly necessary local storage and — with your consent — analytics cookies (Google Analytics, see Section 8). We do not use third-party tracking or advertising cookies.

Strictly necessary storage (no opt-in required):

  • Language preference: Key language, value de or en
  • Consent choice: Key cookie-consent, recording whether you accepted or declined non-essential storage, so we do not ask again on every visit

These entries are not transmitted to any server and contain no advertising identifiers.
Legal basis (strictly necessary): § 25 (2) TTDSG and GDPR Art. 6 (1) f) (legitimate interest for improving usability).
Legal basis (analytics cookies): § 25 (1) TTDSG / GDPR Art. 6 (1) a) (consent).
Withdrawal & deletion: You can change your choice at any time via the consent banner or by clearing your browser's local storage.

11. Your Rights under the EU & UK GDPR (Chapter III)

You have the following rights:

  • Right of access (Art. 15): Request information about your data
  • Right to rectification (Art. 16): Correction of inaccurate data
  • Right to erasure (Art. 17): Deletion of your data (right to be forgotten)
  • Right to restrict (Art. 18): Restrict data processing
  • Right to object (Art. 21): Object to processing based on Art. 6 (1) f) (legitimate interest)
  • Data portability (Art. 20): Receive your data in machine-readable format

To exercise these rights, contact us at: support@justaletter.app

12. U.S. Privacy Rights (California CCPA/CPRA & Other States)

JustALetter is available internationally, including to residents of the United States. This section applies to residents of California (under the California Consumer Privacy Act as amended by the CPRA) and, where applicable, to residents of other U.S. states with comparable privacy laws, including Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA).

Personal information we collect. "Personal information" means information that identifies, relates to, or could reasonably be linked with you. In the past 12 months we have collected the following categories:

  • Identifiers: email address; name (only if provided by Apple on first Sign in with Apple authorization); randomly generated verification/reset tokens
  • Internet/network activity: IP address, browser type, access timestamps (server logs); if you consent, also usage statistics via Google Analytics 4 (page views, device information, traffic source)
  • User-generated content: the letters and related content you create in the app

We do not collect Social Security numbers, government IDs, precise geolocation, biometric data, or other sensitive personal information through this website.

Purposes of collection. To create and secure your account, verify your email address, allow password resets, respond to inquiries, and maintain the security and stability of the service.

Sale or sharing of personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We disclose data only to the service providers (processors) described in this policy (Firebase/Google, Resend, RevenueCat, Google Analytics), who are contractually bound to use it solely to provide their service. Google Analytics only receives data if you have consented via our cookie banner. The flyer ads shown in the free app (see Section 7) are contextual (selected on the device itself, with no personal data involved) and are measured on an anonymous, aggregate basis only; this constitutes neither a sale nor cross-context behavioral advertising.

Your U.S. privacy rights. Subject to applicable law, you have the right to:

  • Right to Know / Access: request the categories and specific pieces of personal information we have collected about you
  • Right to Delete: request deletion of your personal information
  • Right to Correct: request correction of inaccurate personal information
  • Right to Opt-Out: opt out of the sale or sharing of personal information (note: we do not sell or share, so no action is required)
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights

Email opt-out. We only send transactional emails (verification and password reset), not marketing emails. You can stop receiving them by not requesting verification/reset and by deleting your account. If we ever introduce marketing emails, each will include an unsubscribe link.

To exercise any of these rights, contact us at support@justaletter.app. We will verify your request by reference to the email address associated with your account. You may use an authorized agent to submit a request on your behalf.

13. Right to Lodge a Complaint (Art. 77 GDPR / UK GDPR)

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR).

The competent supervisory authority for EU residents is:
Hessischer Beauftragter für Datenschutz und Informationsfreiheit (HBDI)
P.O. Box 3163, 65021 Wiesbaden, Germany
https://datenschutz.hessen.de

Residents of the United Kingdom may lodge a complaint with the Information Commissioner's Office (ICO), https://ico.org.uk.

14. Automated Decision-Making (Art. 22 GDPR)

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

15. Security and Encryption

We implement technical and organizational measures under Art. 32 GDPR to protect your data, including encrypted transport throughout (TLS), secure token management, tightly scoped access rights, and regular security reviews.

Encryption of your letters: the content of your letters – text, P.S. and signature, as well as attached photos and drawings – is encrypted on your device (AES-256-GCM) and is transmitted to us and stored by us in encrypted form only. Each connection between two people has its own key, which is in turn protected by a non-exportable key in Google Cloud KMS. Access to our database or file storage alone is therefore not enough to read letters.

What this explicitly does not mean: this is not end-to-end encryption. The keys are held on our servers – so that you lose nothing when you change devices or reinstall, and need no recovery code. Technically, this means we are able to decrypt letters. We do so only to review a report (see Section 4) or where we are legally required to; every such access is logged.

The information surrounding a letter is not encrypted: who is connected with whom, when and how often letters were written, and whether a photo or drawing was attached. We need this information to operate the service and can see it.

On your device: drafts you have not sent yet are stored encrypted locally. Cached image data is likewise held on the device in encrypted form only. On Android, the operating system's automatic backup is disabled for the app; on iOS the device-local key stays in the device keychain and is not synchronised to iCloud.

16. Changes to This Policy

We reserve the right to change this privacy policy at any time. The current version is always available on this page.

Just a Letter
HomeLegalTermsSupportChangelogLicences