Last updated: July 2026
Scope: This privacy policy applies to both the JustALetter mobile app and this website. Where a section is specific to only one of them, this is indicated.
Christopher Reinhardt
Potsdamerstraße 9
63322 Rödermark
Germany
E-Mail: support@justaletter.app
When using the main website (Homepage, Legal, Privacy):
Legal basis: GDPR Art. 6 (1) f) (legitimate interest for security and website stability)
Retention period: Automatically deleted server logs (typically 30 days)
When using authentication features (email verification, password reset), we process:
User accounts (email address, cryptographically hashed password) are managed via Firebase Authentication. Tokens and related account information are stored in the Cloud Firestore database (see Section 4).
Legal basis: GDPR Art. 6 (1) a) (consent) / Art. 6 (1) b) (contract)
Retention period: Tokens are automatically deleted after single use or expiration
Right to withdraw consent: Where processing is based on your consent (Art. 6 (1) a), you may withdraw it at any time with effect for the future by contacting support@justaletter.app.
The JustALetter app, this website, and their backend functions are operated via Firebase (a service of Google Ireland Ltd. / Google LLC). The following Firebase services are used:
How the app processes your data: JustALetter lets two connected people exchange one message per day. To provide this, we process the following in Cloud Firestore (and, for media, Firebase Storage), linked to your account:
Legal basis: GDPR Art. 6 (1) b) (performance of the service you requested); push notifications additionally rely on Art. 6 (1) a) (consent, granted via your device); Crashlytics relies on Art. 6 (1) f) (legitimate interest in maintaining app stability and security); Firebase Analytics relies on Art. 6 (1) f) (legitimate interest in analyzing and improving app usage); reviewing reported content relies on Art. 6 (1) f) (legitimate interest in platform safety and abuse prevention); product feedback requests rely on Art. 6 (1) f) (legitimate interest in improving our service), and you may object at any time (Art. 21 GDPR).
What happens when you delete your account: Deleting your account immediately removes your user profile (email, nickname, account document), your Firebase Auth account, and any open invitations you created. Active connections are automatically archived so that your connected person retains access to the shared letter history — letters you have already sent remain with the recipient, as they form part of the recipient's correspondence.
Deleting an archived history:Once a connection has been archived, you and your connected person can each individually hide the shared letter history from your app ("Delete history"). As long as only one person has hidden the history, the messages are retained, since they still form part of the other person's correspondence. Once both people have hidden the history, the associated messages and media are automatically and irreversibly deleted after a retention period of 2 years. During this period the data is no longer visible in the app and is retained solely for the purposes of preserving evidence and of establishing, exercising or defending legal claims — in particular in connection with unlawful content.
Legal basis: GDPR Art. 6 (1) f) (legitimate interest in preserving evidence and in combating abuse and unlawful content).
Legal hold: For content moderation purposes and to enable account restoration at your request, we retain a security record for up to 2 years after account deletion. This record contains your user ID, email address, sign-in methods used, basic account data (nickname, account level, creation date), and the IDs of your former connections. It is accessible only via the admin backend and is automatically deleted after the 2-year period.
Legal basis for the hold: GDPR Art. 6 (1) f) (legitimate interest in combating abuse and illegal content, and in the ability to restore an account at the user's request).
Data processing agreement: A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Google.
Third-country transfer: Firebase/Google may transfer data to the USA. The transfer is based on the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR).
More information: Google Privacy Policy
For sending transactional emails (email verification, password reset), we use Resend ( https://resend.com).
Legal basis: GDPR Art. 6 (1) a) (consent) / Art. 6 (1) b) (contract)
More information: Resend Privacy Policy
To provide and manage paid features (in-app purchases and subscriptions) in the app, we use RevenueCat ( https://www.revenuecat.com). RevenueCat validates purchase receipts and manages the status of your subscriptions.
Legal basis: GDPR Art. 6 (1) b) (performance of the purchase contract / provision of the features you purchased)
More information: RevenueCat Privacy Policy
In the free version of the app we occasionally show advertising flyers from advertising partners — after an ad-free introductory period, each time before you open a received letter. Users with an active Premium subscription do not see any ads.
No personalized advertising, no tracking. Which flyer is shown depends solely on your device's system language (read locally on the device, not transmitted to or stored by us) and a random, weighted rotation. No evaluation of personal characteristics, no profiling and no cross-device recognition takes place. We do not use an advertising identifier (e.g. IDFA) and therefore do not trigger an “App Tracking Transparency" prompt.
Anonymous reach measurement. To measure a campaign's performance we count only anonymous aggregate totals per flyer (number of impressions and clicks). These counters are not linked to any user, device or advertising identifier and do not allow any conclusions about individual persons.
Controlling the ad-free introductory period. To implement the ad-free introductory period, we maintain a simple server-side counter of the letters you have received. This value is used solely to decide when advertising starts to appear and is not shared with advertising partners.
External links. If you open the link offered within a flyer, an external website operated by the respective advertising partner opens. The advertising partner is responsible for its content and data processing; that partner's own privacy policy applies.
Legal basis: GDPR Art. 6(1)(f) (legitimate interest) in financing the free version of the app through a data-minimizing, non-tracking form of advertising.
We use Google Analytics 4 on this website, a web analytics service provided by Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Analytics uses cookies and similar technologies to analyse how visitors use our website.
Data processed:
Consent Mode v2: Google Analytics is configured so that by default it does not set cookies or transmit personal data. Tracking is only activated when you actively consent via our cookie banner. If you decline, Google Analytics only sends anonymous ping signals without setting any cookies.
Legal basis: GDPR Art. 6 (1) a) (consent); § 25 (1) TTDSG (consent for cookie placement)
Retention period: Analytics data is stored in Google Analytics for 14 months by default, after which it is automatically deleted.
Withdrawal: You can withdraw your consent at any time by clicking "Decline non-essential" in our cookie banner, or by clearing your browser's local storage (key cookie-consent). No new analytics data will be collected after withdrawal.
Data processing agreement: A DPA pursuant to Art. 28 GDPR is in place with Google.
Third-country transfer: Data may be transferred to the USA, safeguarded by the EU-US Data Privacy Framework and EU Standard Contractual Clauses (SCCs, Art. 46 (2) c GDPR).
More information: Google Privacy Policy | Google Analytics Opt-out Browser Add-on
If you contact us by email (e.g. at support@justaletter.app), we process the data you provide (email address, name if given, and the content of your message) in order to handle your request.
Legal basis: GDPR Art. 6 (1) b) (pre-contractual or contractual measures) or Art. 6 (1) f) (legitimate interest in responding to inquiries)
Retention period: We delete this data as soon as it is no longer required to process your request, unless statutory retention obligations apply.
This website uses strictly necessary local storage and — with your consent — analytics cookies (Google Analytics, see Section 8). We do not use third-party tracking or advertising cookies.
Strictly necessary storage (no opt-in required):
language, value de or encookie-consent, recording whether you accepted or declined non-essential storage, so we do not ask again on every visitThese entries are not transmitted to any server and contain no advertising identifiers.
Legal basis (strictly necessary): § 25 (2) TTDSG and GDPR Art. 6 (1) f) (legitimate interest for improving usability).
Legal basis (analytics cookies): § 25 (1) TTDSG / GDPR Art. 6 (1) a) (consent).
Withdrawal & deletion: You can change your choice at any time via the consent banner or by clearing your browser's local storage.
You have the following rights:
To exercise these rights, contact us at: support@justaletter.app
JustALetter is available internationally, including to residents of the United States. This section applies to residents of California (under the California Consumer Privacy Act as amended by the CPRA) and, where applicable, to residents of other U.S. states with comparable privacy laws, including Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA).
Personal information we collect. "Personal information" means information that identifies, relates to, or could reasonably be linked with you. In the past 12 months we have collected the following categories:
We do not collect Social Security numbers, government IDs, precise geolocation, biometric data, or other sensitive personal information through this website.
Purposes of collection. To create and secure your account, verify your email address, allow password resets, respond to inquiries, and maintain the security and stability of the service.
Sale or sharing of personal information. We do not sell your personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We disclose data only to the service providers (processors) described in this policy (Firebase/Google, Resend, RevenueCat, Google Analytics), who are contractually bound to use it solely to provide their service. Google Analytics only receives data if you have consented via our cookie banner. The flyer ads shown in the free app (see Section 7) are contextual (selected by device language only) and are measured on an anonymous, aggregate basis only; this constitutes neither a sale nor cross-context behavioral advertising.
Your U.S. privacy rights. Subject to applicable law, you have the right to:
Email opt-out. We only send transactional emails (verification and password reset), not marketing emails. You can stop receiving them by not requesting verification/reset and by deleting your account. If we ever introduce marketing emails, each will include an unsubscribe link.
To exercise any of these rights, contact us at support@justaletter.app. We will verify your request by reference to the email address associated with your account. You may use an authorized agent to submit a request on your behalf.
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR).
The competent supervisory authority for EU residents is:
Hessischer Beauftragter für Datenschutz und Informationsfreiheit (HBDI)
P.O. Box 3163, 65021 Wiesbaden, Germany
https://datenschutz.hessen.de
Residents of the United Kingdom may lodge a complaint with the Information Commissioner's Office (ICO), https://ico.org.uk.
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
We implement technical and organizational measures to protect your data, including encryption, secure token management, and regular security reviews.
We reserve the right to change this privacy policy at any time. The current version is always available on this page.