← Home

Privacy Policy

Last updated: July 2026

⚠️ Important Notice: The German version "Datenschutzerklärung" is the legally binding version. This English translation is provided for information purposes only and may not be complete or accurate. In case of any discrepancies, the German version shall prevail.

Scope: This privacy policy applies to both the JustALetter mobile app and this website. Where a section is specific to only one of them, this is indicated.

1. Controller (GDPR Art. 4 No. 7)

Christopher Reinhardt
Potsdamerstraße 9
63322 Rödermark
Germany

E-Mail: support@justaletter.app

2. Data Collection and Processing

When using the main website (Homepage, Legal, Privacy):

  • IP address (automatically)
  • Browser type and version (automatically)
  • Access date and time (automatically)
  • Pages visited (automatically)

Legal basis: GDPR Art. 6 (1) f) (legitimate interest for security and website stability)
Retention period: Automatically deleted server logs (typically 30 days)

3. Authentication Pages (/auth/*)

When using authentication features (email verification, password reset), we process:

  • Email address: For email verification and password reset
  • Verification token: Randomly generated token, stored in Cloud Firestore (retention: max. 24 hours)
  • Reset token: Randomly generated token, stored in Cloud Firestore (retention: max. 1 hour)

User accounts (email address, cryptographically hashed password) are managed via Firebase Authentication. Tokens and related account information are stored in the Cloud Firestore database (see Section 4).

Legal basis: GDPR Art. 6 (1) a) (consent) / Art. 6 (1) b) (contract)
Retention period: Tokens are automatically deleted after single use or expiration
Right to withdraw consent: Where processing is based on your consent (Art. 6 (1) a), you may withdraw it at any time with effect for the future by contacting support@justaletter.app.

4. JustALetter App & Firebase (Google)

The JustALetter app, this website, and their backend functions are operated via Firebase (a service of Google Ireland Ltd. / Google LLC). The following Firebase services are used:

  • Firebase Hosting: Delivery of the website, including access logging (server logs), performance and security information
  • Firebase Authentication: Management of user accounts (email address, cryptographically hashed password) for email verification and password reset
  • Cloud Firestore (database): Storage of verification and reset tokens, related account documents (e.g. the time of the last password reset), and the content you create in the app (see below)

How the app processes your data: JustALetter lets two connected people exchange one message per day. To provide this, we process the following in Cloud Firestore (and, for media, Firebase Storage), linked to your account:

  • Account & sign-in: your email address and authentication data. You can sign in with email/password, Sign in with Google, or Sign in with Apple. These are third-party identity providers with their own privacy policies; Apple may forward an anonymized relay email instead of your real address. If you sign in with Apple, Apple may also share your name with us on the first authorization; if provided, we store it so it can be shown to a connection partner instead of an anonymized relay address.
  • Connection & invitations: to use the app you connect with one other person via a short invite code or shareable link. We store the invitation and the link between the two connected accounts.
  • Messages: the messages you write (and any media you attach) are, by design, transmitted to and visible by the person you are connected with — this is the core purpose of the service. Messages are stored so that you and your connection can read your shared history. For technical reasons, attached photos are uploaded to our storage (Firebase Storage) while you are still composing, so that sending completes faster; there they are accessible to your account only. If the letter is never sent — for example because you remove the photo or discard or delete the draft — the file is deleted, and in any case automatically after 7 days at the latest.
  • Reported content: if a message is reported, we may access its content to review the report. We review reported content manually; we do not currently take any automated moderation action.
  • Push notifications: if you allow notifications, we process a device token via Firebase Cloud Messaging for each device you're signed in on, to notify you of a new message. You can disable this at any time in your device settings.
  • Firebase Crashlytics: to detect and fix technical errors we use Firebase Crashlytics (Google Ireland Ltd. / Google LLC). In the event of a crash, Crashlytics automatically collects non-personal technical data: device model, operating system version, app version, time of the crash, and a stack trace (code location of the error). No user content, messages, or personally identifiable information is transmitted. The collected crash data is transferred to Google in the USA; the safeguards described at the end of this section apply (EU-US Data Privacy Framework, EU Standard Contractual Clauses).
  • Firebase Analytics (app):to analyze app usage we use Firebase Analytics (Google Ireland Ltd. / Google LLC). We collect automatic standard events (e.g. app opens, session length) as well as our own usage events in anonymised, aggregated form – such as that a letter was sent along with non-content metadata (e.g. character count, number of attached photos, whether a drawing was added), screens viewed, and interactions such as opening the premium screen or completing a purchase. We do not collect message content, photos, or any other identifying content. A device-side instance ID is also used. Analytics data is retained for 14 months and then deleted automatically. The data may be transferred to Google in the USA; the safeguards described at the end of this section apply (EU-US Data Privacy Framework, EU Standard Contractual Clauses).
  • Product feedback: we may occasionally contact you by email to ask for your feedback on the app (e.g. what you like or what we could improve). This is not advertising. You can object to such requests at any time by contacting us at support@justaletter.app.

Legal basis: GDPR Art. 6 (1) b) (performance of the service you requested); push notifications additionally rely on Art. 6 (1) a) (consent, granted via your device); Crashlytics relies on Art. 6 (1) f) (legitimate interest in maintaining app stability and security); Firebase Analytics relies on Art. 6 (1) f) (legitimate interest in analyzing and improving app usage); reviewing reported content relies on Art. 6 (1) f) (legitimate interest in platform safety and abuse prevention); product feedback requests rely on Art. 6 (1) f) (legitimate interest in improving our service), and you may object at any time (Art. 21 GDPR).

What happens when you delete your account: Deleting your account immediately removes your user profile (email, nickname, account document), your Firebase Auth account, and any open invitations you created. Active connections are automatically archived so that your connected person retains access to the shared letter history — letters you have already sent remain with the recipient, as they form part of the recipient's correspondence.

Deleting an archived history:Once a connection has been archived, you and your connected person can each individually hide the shared letter history from your app ("Delete history"). As long as only one person has hidden the history, the messages are retained, since they still form part of the other person's correspondence. Once both people have hidden the history, the associated messages and media are automatically and irreversibly deleted after a retention period of 2 years. During this period the data is no longer visible in the app and is retained solely for the purposes of preserving evidence and of establishing, exercising or defending legal claims — in particular in connection with unlawful content.
Legal basis: GDPR Art. 6 (1) f) (legitimate interest in preserving evidence and in combating abuse and unlawful content).

Legal hold: For content moderation purposes and to enable account restoration at your request, we retain a security record for up to 2 years after account deletion. This record contains your user ID, email address, sign-in methods used, basic account data (nickname, account level, creation date), and the IDs of your former connections. It is accessible only via the admin backend and is automatically deleted after the 2-year period.
Legal basis for the hold: GDPR Art. 6 (1) f) (legitimate interest in combating abuse and illegal content, and in the ability to restore an account at the user's request).

Data processing agreement: A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Google.
Third-country transfer: Firebase/Google may transfer data to the USA. The transfer is based on the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR).
More information: Google Privacy Policy

5. Resend – Transactional Email Service

For sending transactional emails (email verification, password reset), we use Resend ( https://resend.com).

  • Data processed: Email address, verification tokens
  • Purpose: Sending authentication-related emails (verification, password reset)
  • Provider: Resend, Inc., a company based in the United States
  • Data processing agreement: A DPA pursuant to Art. 28 GDPR is in place with Resend
  • Data location: We use Resend's EU data-residency region, so transactional email data is processed within the European Union. Insofar as access from the United States cannot be excluded, such transfers are covered by EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR) and, where applicable, the EU-US Data Privacy Framework.
  • Retention: Email delivery logs are retained for operational purposes; your email address is not stored beyond what is necessary to deliver the message

Legal basis: GDPR Art. 6 (1) a) (consent) / Art. 6 (1) b) (contract)
More information: Resend Privacy Policy

6. RevenueCat – In-App Purchases & Subscriptions

To provide and manage paid features (in-app purchases and subscriptions) in the app, we use RevenueCat ( https://www.revenuecat.com). RevenueCat validates purchase receipts and manages the status of your subscriptions.

  • Data processed: a pseudonymous app user ID, app store purchase receipts or transaction identifiers, purchase and subscription status (e.g. active, expired, renewal date), and technical device and platform data (operating system, app version, country/region)
  • No payment data: the actual payment is handled exclusively by the Apple App Store or Google Play. Neither we nor RevenueCat receive any credit card or bank account details.
  • Purpose: validating purchases, unlocking purchased features, and managing and restoring subscriptions
  • Provider: RevenueCat, Inc., a company based in the USA
  • Data processing agreement: a data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with RevenueCat
  • Third-country transfer: RevenueCat may transfer data to the USA; the transfer is safeguarded by EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR) and, where applicable, the EU-US Data Privacy Framework.

Legal basis: GDPR Art. 6 (1) b) (performance of the purchase contract / provision of the features you purchased)
More information: RevenueCat Privacy Policy

7. In-App Advertising (Flyers)

In the free version of the app we occasionally show advertising flyers from advertising partners — after an ad-free introductory period, each time before you open a received letter. Users with an active Premium subscription do not see any ads.

No personalized advertising, no tracking. Which flyer is shown depends solely on your device's system language (read locally on the device, not transmitted to or stored by us) and a random, weighted rotation. No evaluation of personal characteristics, no profiling and no cross-device recognition takes place. We do not use an advertising identifier (e.g. IDFA) and therefore do not trigger an “App Tracking Transparency" prompt.

Anonymous reach measurement. To measure a campaign's performance we count only anonymous aggregate totals per flyer (number of impressions and clicks). These counters are not linked to any user, device or advertising identifier and do not allow any conclusions about individual persons.

Controlling the ad-free introductory period. To implement the ad-free introductory period, we maintain a simple server-side counter of the letters you have received. This value is used solely to decide when advertising starts to appear and is not shared with advertising partners.

External links. If you open the link offered within a flyer, an external website operated by the respective advertising partner opens. The advertising partner is responsible for its content and data processing; that partner's own privacy policy applies.

Legal basis: GDPR Art. 6(1)(f) (legitimate interest) in financing the free version of the app through a data-minimizing, non-tracking form of advertising.

8. Google Analytics 4 (Web Analytics)

We use Google Analytics 4 on this website, a web analytics service provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Analytics uses cookies and similar technologies to analyse how visitors use our website.

Data processed:

  • Page views and time spent on pages
  • Device information (browser type, operating system, screen resolution)
  • Approximate location (based on anonymised IP address; the full IP is not stored)
  • Traffic source (e.g. search engine, direct visit, external links)
  • On-page interactions (e.g. scroll depth, clicks on external links)

Consent Mode v2: Google Analytics is configured so that by default it does not set cookies or transmit personal data. Tracking is only activated when you actively consent via our cookie banner. If you decline, Google Analytics only sends anonymous ping signals without setting any cookies.

Legal basis: GDPR Art. 6 (1) a) (consent); § 25 (1) TTDSG (consent for cookie placement)
Retention period: Analytics data is stored in Google Analytics for 14 months by default, after which it is automatically deleted.
Withdrawal: You can withdraw your consent at any time by clicking "Decline non-essential" in our cookie banner, or by clearing your browser's local storage (key cookie-consent). No new analytics data will be collected after withdrawal.
Data processing agreement: A DPA pursuant to Art. 28 GDPR is in place with Google.
Third-country transfer: Data may be transferred to the USA, safeguarded by the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR).
More information: Google Privacy Policy | Google Analytics Opt-out Browser Add-on

9. Contacting Us by Email

If you contact us by email (e.g. at support@justaletter.app), we process the data you provide (email address, name if given, and the content of your message) in order to handle your request.

Legal basis: GDPR Art. 6 (1) b) (pre-contractual or contractual measures) or Art. 6 (1) f) (legitimate interest in responding to inquiries)
Retention period: We delete this data as soon as it is no longer required to process your request, unless statutory retention obligations apply.

10. Cookies, Local Storage & Consent

This website uses strictly necessary local storage and — with your consent — analytics cookies (Google Analytics, see Section 8). We do not use third-party tracking or advertising cookies.

Strictly necessary storage (no opt-in required):

  • Language preference: Key language, value de or en
  • Consent choice: Key cookie-consent, recording whether you accepted or declined non-essential storage, so we do not ask again on every visit

These entries are not transmitted to any server and contain no advertising identifiers.
Legal basis (strictly necessary): § 25 (2) TTDSG and GDPR Art. 6 (1) f) (legitimate interest for improving usability).
Legal basis (analytics cookies): § 25 (1) TTDSG / GDPR Art. 6 (1) a) (consent).
Withdrawal & deletion: You can change your choice at any time via the consent banner or by clearing your browser's local storage.

11. Your Rights under the EU & UK GDPR (Chapter III)

You have the following rights:

  • Right of access (Art. 15): Request information about your data
  • Right to rectification (Art. 16): Correction of inaccurate data
  • Right to erasure (Art. 17): Deletion of your data (right to be forgotten)
  • Right to restrict (Art. 18): Restrict data processing
  • Right to object (Art. 21): Object to processing based on Art. 6 (1) f) (legitimate interest)
  • Data portability (Art. 20): Receive your data in machine-readable format

To exercise these rights, contact us at: support@justaletter.app

12. U.S. Privacy Rights (California CCPA/CPRA & Other States)

JustALetter is available internationally, including to residents of the United States. This section applies to residents of California (under the California Consumer Privacy Act as amended by the CPRA) and, where applicable, to residents of other U.S. states with comparable privacy laws, including Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA).

Personal information we collect. "Personal information" means information that identifies, relates to, or could reasonably be linked with you. In the past 12 months we have collected the following categories:

  • Identifiers: email address; name (only if provided by Apple on first Sign in with Apple authorization); randomly generated verification/reset tokens
  • Internet/network activity: IP address, browser type, access timestamps (server logs); if you consent, also usage statistics via Google Analytics 4 (page views, device information, traffic source)
  • User-generated content: the letters and related content you create in the app

We do not collect Social Security numbers, government IDs, precise geolocation, biometric data, or other sensitive personal information through this website.

Purposes of collection. To create and secure your account, verify your email address, allow password resets, respond to inquiries, and maintain the security and stability of the service.

Sale or sharing of personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We disclose data only to the service providers (processors) described in this policy (Firebase/Google, Resend, RevenueCat, Google Analytics), who are contractually bound to use it solely to provide their service. Google Analytics only receives data if you have consented via our cookie banner. The flyer ads shown in the free app (see Section 7) are contextual (selected by device language only) and are measured on an anonymous, aggregate basis only; this constitutes neither a sale nor cross-context behavioral advertising.

Your U.S. privacy rights. Subject to applicable law, you have the right to:

  • Right to Know / Access: request the categories and specific pieces of personal information we have collected about you
  • Right to Delete: request deletion of your personal information
  • Right to Correct: request correction of inaccurate personal information
  • Right to Opt-Out: opt out of the sale or sharing of personal information (note: we do not sell or share, so no action is required)
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights

Email opt-out. We only send transactional emails (verification and password reset), not marketing emails. You can stop receiving them by not requesting verification/reset and by deleting your account. If we ever introduce marketing emails, each will include an unsubscribe link.

To exercise any of these rights, contact us at support@justaletter.app. We will verify your request by reference to the email address associated with your account. You may use an authorized agent to submit a request on your behalf.

13. Right to Lodge a Complaint (Art. 77 GDPR / UK GDPR)

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR).

The competent supervisory authority for EU residents is:
Hessischer Beauftragter für Datenschutz und Informationsfreiheit (HBDI)
P.O. Box 3163, 65021 Wiesbaden, Germany
https://datenschutz.hessen.de

Residents of the United Kingdom may lodge a complaint with the Information Commissioner's Office (ICO), https://ico.org.uk.

14. Automated Decision-Making (Art. 22 GDPR)

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

15. Security

We implement technical and organizational measures to protect your data, including encryption, secure token management, and regular security reviews.

16. Changes to This Policy

We reserve the right to change this privacy policy at any time. The current version is always available on this page.