Q: Quick Check: GDPR, Encryption & Privacy Policy

Letterly Team,

Could you please clarify your underlying infrastructure and whether it aligns with GDPR principles?

For those of us handling sensitive info, it’d be helpful to know:

1. Are audio/transcripts encrypted in transit and at rest?
2. Is there an access control policy? Can staff or subprocessors access data?
3. Any plans to update the Privacy Policy to reflect GDPR and clarify data handling?
4. Do you offer a DPA or internal GDPR-aligned documentation?
5. Is there a data retention policy or auto-deletion feature?
6. Have any security standards or breach notification processes been implemented?

Totally understand it’s a big task for a startup — just keen to know where you're at and how you’re approaching data protection.

Thanks!

Ida55820PLUSJun 1, 2025
Founder Team
Anton_Letterly

Anton_Letterly

Jun 8, 2025

A: Hi Ida, thanks for your questions! Please find the answers:

1. All audio and text notes are encrypted both in transit (via HTTPS/TLS) and at rest. Encryption keys are stored separately in a secure environment and can only be accessed through a controlled, multi-step validation process.

2. We have strict access controls in place. Access to user content is highly limited and governed by internal policies. The only external subprocessor we use is OpenAI, which temporarily processes notes for rewriting or transcription. This data is not used to train their models.

3. We’re updating our Privacy Policy to better reflect our GDPR alignment. While our documentation may still be evolving, our internal data practices are already designed with strong privacy and security in mind.

4. We’re working on making a Data Processing Agreement (DPA) available and expect to publish it soon. Internally, we already follow GDPR-aligned practices.

5. We retain user data for up to 12 months to support core functionality. Upon request, all data can be deleted within 24 hours (usually faster). Automatic deletion is planned and will be available in one of the next releases.

6. We haven’t completed formal certifications yet, but we follow security best practices and are working on a clear breach response process.

Share
Helpful?
Log in to join the conversation
Verified Purchaser badge

Verified purchaser

Posted: Jun 8, 2025

In a previous answer you stated "The data is saved both on the server and locally. In the future, we’re planning to add a feature that lets you delete it locally and keep it only on the server." However answer to point 5, my understanding is that our voice notes are stored on your EU servers for 12 months after which it will be deleted (when the automatic deletion is implemented)? Please clarify.

Founder
Posted: Jun 8, 2025

Thanks for the follow-up — happy to clarify!

We don’t delete your data if you’re actively using the app. Notes will be automatically deleted after 12 months of account inactivity. Of course, you can still manually delete your notes at any time.