About this policy
GoMatrix Tech Internet Co., Limited operates Lettura and is responsible for the personal information it processes to provide the service. This notice covers the Lettura application, these website pages, and requests you send to us. Contact support@lettureapp.com for privacy questions.
Personal information means information that identifies you or can reasonably be linked to you, including your account identifier. This notice describes the current service, including its local mood feature and server-based correspondence. It does not govern independent services you visit through someone else's links. Our Service Agreement describes use of Lettura, and our Child Safety Policy describes our standards for protecting children.
Reading this notice is not blanket consent to processing. We will seek a separate choice where required by law. You can request account deletion even if you no longer have the app installed.
Information we use and where it comes from
We receive information you enter, information supplied through supported sign-in providers, technical information generated when you use the service, and information other people submit in correspondence or reports involving you.
| Category | Examples and source | Purpose |
|---|---|---|
| Account and sign-in | Account identifier, provider identifiers, sign-in email and profile information supplied by Google or Apple, authentication records. | Create, authenticate, secure, and administer your account. We do not receive your provider password. |
| Profile and eligibility | Display name, pigeon avatar configuration, birthday, account status, and creation or update dates. | Show your chosen identity, apply the 18+ rule, and operate your account. |
| Approximate location and time | IP address used for country estimation; returned country, region, and city; UTC offset supplied by the app. | Set country information and apply local-day or time-based service rules. IP-based location is not device GPS tracking. |
| Letters and relationships | Letters, prompts, replies, stamps used, participants, sending times, delivery and read state, invitations, and friendship status. | Distribute letters, maintain correspondence, and show your personal inbox and relationships. |
| Flowers and stamp collections | Grants, appreciation events, earned and seen stamps, balances, and redemption records. | Operate collecting and appreciation features and prevent duplicate rewards. |
| Notifications and technical information | Push token, installation identifier, platform, app version, preferences, timestamps, request and security information, and error records. | Deliver requested notifications, operate infrastructure, investigate faults, and protect access. |
| Reports and support | Reporter and reported account references, reason, description, relevant correspondence or profile evidence, blocking records, and information you email us. | Assess concerns, respond to requests, prevent abuse, and meet legal duties. |
| Local mood records | Mood selections, dates, history, and reminder choices stored under your account on your device. | Provide mood check-ins and history. The current feature does not upload these records to our servers. |
Account sign-in, birthday, and the information needed to send a letter are required for their respective features. If you do not provide them, those features may be unavailable. Mood check-ins, support messages, and notification permissions are optional.
Letters, reports, and support messages may contain personal or sensitive information about you supplied by you or another person, such as health, religious, political, or relationship details. We process this content when delivering correspondence or addressing a report or request. Avoid unnecessary sensitive details about yourself or anyone else, and do not include passwords, payment credentials, or identity-document copies in letters.
Who can see your information
Other users: your display name, pigeon avatar, country, and account status can be available through relevant profile and correspondence views. A Discover original may reach multiple assigned readers. Replies are intended for the two participants. A stamp attached to a letter is visible to its readers.
Information kept private from other users: birthday, detailed location, stamp album and balances, notification settings, and personal read markers are not part of the public profile. Your read state is not shown to a correspondent as a read receipt. Mood history is not added to your letters or public profile.
Service operation: private account records and letters remain accessible to the infrastructure that operates Lettura and may be accessed for necessary support, security, safety, or legal work. Letters are not end-to-end encrypted. We cannot prevent recipients from separately copying what they can read, and we cannot guarantee that information voluntarily shared with them remains confidential.
Purposes and legal bases
We process information to provide and secure the service, deliver correspondence, support account and collection features, resolve requests, apply community standards, and comply with law. We do not treat your acceptance of the Service Agreement as consent to every optional use.
Where European or UK data-protection rules apply, the relevant bases include:
- Providing the service: processing necessary account and correspondence information to perform our agreement with you.
- Legitimate interests: proportionate security, abuse prevention, troubleshooting, support, and protection of correspondence history, where those interests are not overridden by your rights. This does not remove your right to object.
- Legal obligations: records and disclosures needed to comply with applicable requirements or valid legal process.
- Consent: optional processing for which the law requires your agreement. You may withdraw it without changing the lawfulness of earlier processing.
- Vital interests: necessary processing to protect someone's life or physical safety where the applicable legal conditions are met.
Different or additional conditions may apply under your local law, particularly to sensitive information. Sending a letter is not a waiver of those protections.
Discover allocation, sending limits, and reward eligibility use automated service rules. These organize app activity and do not guarantee a particular connection. Contact us if you believe a restriction or result is wrong.
Local storage, cookies, and device choices
On your device
Mood entries and history are stored locally, separated by account, and do not synchronize between devices through Lettura. You can change or remove today's entry and manage the reminder in the app. Local records may be lost when app data is removed or a device is lost; any operating-system backup or restoration depends on your separate settings.
The app also stores preferences, sign-in-related state, and caches of correspondence and stamp information. A cache is a local copy of information that can also exist on our servers. Deleting an account does not remotely wipe every device. Unsent original-letter and reply text is discarded when the editor closes; there are no saved drafts.
Website and service requests
These policy pages use local fonts and do not set advertising or analytics cookies or run analytics scripts. The website host can receive your IP address, requested page, browser information, and request time to serve and secure the site. Service infrastructure also processes request and error records for operation, troubleshooting, and security. These records are separate from your local mood history.
Independent sign-in providers and websites you follow through links have their own privacy practices.
Notifications and permissions
Manage notification categories in Lettura and system notification permission in your device settings. Push messages use general activity notices rather than letter bodies, but previews may still appear on a locked device. On iOS the app may request App Tracking Transparency permission; declining does not disable core correspondence. The current app has no advertising integration and does not use an advertising identifier for advertising or cross-app tracking.
Providers and the information they handle
The following providers support the current application. Their notices explain their own processing, including service or security information they handle under their terms.
- Google and Firebase: supported sign-in and authentication, database storage, server processing, push delivery, and App Check security checks. Relevant information includes account and authentication records, stored app data, push identifiers, network requests, and device or app attestation information. See Firebase Privacy and Security and Google's Privacy Policy.
- Apple: Sign in with Apple, Apple push delivery, and device or app attestation on supported devices. Your provider choices can affect the email or profile information supplied to us. See Apple's Privacy Policy.
- Cloudflare: R2 and related delivery infrastructure serve stamp images and other assets, receiving network and request information needed to deliver them. This asset delivery does not itself require sending your letter body to Cloudflare. See Cloudflare's Privacy Policy.
- ipwho.is / IPWHOIS: our server sends your IP address for an approximate location lookup and may receive a country, region, and city. It does not send your letter body for that lookup. See IPWHOIS's Privacy Policy.
Only the country is used as your public profile location. A country inferred from an IP address can be inaccurate; contact us if it needs correction. The current registration lookup does not request device GPS location.
Request account or data deletion
You can request deletion without reinstalling or signing in to Lettura. Email support@lettureapp.com. Suggested subject: “Lettura account deletion request”.
How to submit your request
- In the app: open Me → Settings → Delete account, enter the requested confirmation, and complete any sign-in verification.
- By email: identify the account and what you want deleted. Provide the account email or sign-in provider if known. If you cannot access the original email, or use an Apple private relay address, explain this in the message.
Opening the email link does not send a request or delete the account; send the message to submit it. If no email app opens, write to the address above using your usual email service. A suggested subject is optional. Never send passwords, verification codes, or identity documents with an initial request.
Scope and verification
An account deletion request covers the account and its associated personal information. You do not need to list every record or apply twice. We may request only the information needed to verify the account or an authorized representative. You can also ask to delete particular information while keeping the account, although a feature may stop working if it needs that information.
What happens next
Deletion removes sign-in access and starts cleanup of birthday, detailed private location, and push-device registrations. The app also attempts to clear mood history and relevant caches on the device used for deletion. Some server cleanup continues in the background.
Other records can remain after automatic cleanup. The next section explains what can remain and why retention needs a lawful basis. We must arrange any additional deletion required or explain an applicable exception. See Your privacy rights for response periods and complaints.
Signing out, disabling notifications, or uninstalling alone does not delete your server account.
How long information is kept
Retention depends on the purpose, whether an account is active, what is needed for correspondence, and any specific safety, dispute, or legal requirement. The following information can remain after account deletion:
- Other account records: stamp albums, flower balances and activity, read state, notifications, and delivery or allocation history are not all erased by the current automatic process. They remain within the scope of an account deletion request.
- Sent correspondence and historical identity: letters, replies, historical display names, avatars and countries, and an identity marked as deleted can remain in existing history. This does not automatically exempt them from a personal-data deletion or restriction request.
- Safety and security records: reports, blocking evidence, and security records may need to be kept for a specific abuse-prevention, protection, dispute, or legal purpose.
For information we retain, we must assess whether the purpose requires identifiable information, explain the applicable reason and period or criteria on request, and delete or make information anonymous when the basis ends. Replacing a name with an account identifier alone does not make information anonymous. Incomplete automatic cleanup is not a retention reason.
Temporary notification delivery jobs and other operational records have their own purposes and lifecycles. A notification expiring does not delete its underlying letter, and a local cache being removed does not erase the server copy.
Account deletion does not recall delivered letters. We cannot remotely erase screenshots, independent recipient copies, or device backups outside our control. Where applicable law requires us to notify providers or other recipients of an erasure or restriction, we must do so, subject to any lawful exception. For local data on another device, use that device's app-data controls.
Security and sensitive correspondence
We use authenticated access, separation of public and private records, and infrastructure security controls to reduce unauthorized access. Access needed for support, safety, or legal handling should be limited to the relevant purpose. No storage or transmission system can guarantee absolute security.
Letters are stored on service infrastructure and may be cached on devices; they are not end-to-end encrypted. Protect your device and sign-in account. If you believe your account or information has been compromised, contact support@lettureapp.com. Where a security incident requires notification to affected people or an authority, we must follow the applicable legal requirements.
Your privacy rights and how to use them
Available rights
Depending on applicable law, you may request access, correction, a copy or portable version of your information, deletion, restriction, or an explanation of disclosures. You may be able to object to processing based on legitimate interests, withdraw consent for optional processing, or authorize a representative to act for you. Withdrawal does not affect earlier lawful processing.
Make a request
Email support@lettureapp.com with what you want us to do and the account email or sign-in provider, if known. No special wording or subject line is required. If you cannot access the original email, explain this. Opening the link only opens your email app; you still need to send the message.
We may ask for the information needed to verify the account or your representative's authority. Do not send passwords, verification codes, or identity documents with your initial request. If another person supplied inaccurate information about you, you can raise that here. We will protect other people's information when supplying correspondence or report records.
Responses and complaints
We will respond within the period required by applicable law. Where EU or UK rules apply, the ordinary response period is one month; any permitted extension and its reasons must be communicated as the law requires. This is a response period, not a promise that every retained record will be erased within one month. We will explain a refusal or limitation and available complaint options.
Requests are generally free; an exceptional charge or refusal must have a lawful basis. We will not retaliate against you for exercising a right. You may complain to the appropriate privacy authority or seek an available legal remedy without first contacting us where the law permits.
If local law gives you a sale, sharing, targeted-advertising, or sensitive-data choice relevant to our processing, you can use the same contact route. The current app has no targeted-advertising feature.
Children
Lettura is intended only for people aged 18 or older. The account age check uses a submitted birthday, not independent identity verification. Anyone may read these policies or contact us for privacy or safety help; parental permission does not make an underage account eligible.
If we learn that a user is under 18, our policy is to restrict access and arrange deletion of their personal information, except information that must be kept for lawful safety or legal purposes. A parent, guardian, or other concerned person can contact support@lettureapp.com without creating an account. Do not send identity documents or abusive material with an initial report. See the Child Safety Policy reporting instructions.
Updates and contact
We will update this notice when practices change and identify revisions by their date. Material changes will receive appropriate notice, and additional consent will be obtained where required. A new notice does not retroactively authorize an unrelated use of previously collected information.
Data controller and operator: GoMatrix Tech Internet Co., Limited.
Privacy, deletion, and support contact: support@lettureapp.com.