What Lettrove stores
You are the controller of your users' data; Lettrove is the processor. This page lists everything Lettrove keeps for an embed project, so you can answer your own security and privacy reviews. Questions it does not answer: support@lettrove.com.
Never
- Personal details of your users. A person is your own opaque id for them (
user.id). A token request carrying a name, an email or any other field is refused. - What people type into forms on your pages and popups. It goes to your page's code or your URL.
- Who you send emails to, or the emails as sent. The embed never sends; you do.
- Your secret keys. Lettrove keeps a keyed fingerprint (HMAC) of each, and its last four characters. A lost key cannot be shown again; you make a new one.
What is kept, and for how long
| What | Why | Kept until |
|---|---|---|
| Your project: its name, mode, settings, branding, allowed sites, keys (fingerprints), webhooks | To run your integration | You delete the project, then 30 days (you can restore it), then erased |
| Each end user: your id for them, when they were first and last seen | To keep their designs theirs | You erase them, or the project is erased |
| Designs and their restore points (up to 50 per design) — unless you keep designs yourself, then none | Your users' work | Deleted by your user: hidden at once, erased 30 days later. Otherwise until the person or project is erased |
| Images your users upload or generate — unless you keep uploads yourself, then none | Shown in their designs | Deleted by your user, or erased with the person or project. An image an email went out with keeps its file (see below) |
| Brands and brand parts (yours and your users') | Reused in designs | Deleted, or erased with the person or project |
| Exports: a record of each (when, which design, which format), and files you asked for (PDF, PNG, ZIP) | So you can fetch the file, and see what went out | Files: erased with the person or project (expiresAt on each file tells you if one will go sooner). Records: kept without the person's id, so the count of what went out stays right |
| Webhook deliveries: which event, when, your server's answer | The delivery log in the dashboard | 30 days |
| AI usage: counts and costs, no content | Credits and billing | Kept; the person's id is removed when they are erased |
| Audit trail: who changed what in your project (keys, sites, settings) | Security and support | Kept with your workspace |
Images an email went out with are never deleted
An email shows its images from their addresses every time someone opens it — next week or in five years. Deleting the file would break every copy already sent. So when a design is exported, the images it shows are marked as sent. Deleting such an image (by your user, or by erasure) removes it from their library and from every list, and keeps the file at its address. The audit trail records that it was kept.
Where it is kept
On Lettrove's servers and storage providers. For which providers and regions hold your project's data, write to support@lettrove.com.
Deleting
| You want to delete | How |
|---|---|
| One design | Your user deletes it in the editor (erased 30 days later) |
| One person and everything they made | lettrove.users.erase(userId) — at once, no grace period (Erasure and privacy) |
| A whole project | Settings → Embed → your project → Delete. It stops at once, can be restored for 30 days, then everything in it is erased |
Keeping your own copy
You can keep every design in your own database as well, or instead: see Keeping your own copy.