> Lettrove docs 1.x · https://docs.lettrove.com/docs/data/what-we-store

# What Lettrove stores

You are the **controller** of your users' data; Lettrove is the **processor**. This page lists
everything Lettrove keeps for an embed project, so you can answer your own security and privacy
reviews. Questions it does not answer: support@lettrove.com.

## Never

- **Personal details of your users.** A person is your own opaque id for them (`user.id`). A token
  request carrying a name, an email or any other field is refused.
- **What people type into forms** on your pages and popups. It goes to your page's code or your URL.
- **Who you send emails to**, or the emails as sent. The embed never sends; you do.
- **Your secret keys.** Lettrove keeps a keyed fingerprint (HMAC) of each, and its last four
  characters. A lost key cannot be shown again; you make a new one.

## What is kept, and for how long

| What | Why | Kept until |
|---|---|---|
| **Your project**: its name, mode, settings, branding, allowed sites, keys (fingerprints), webhooks | To run your integration | You delete the project, then 30 days (you can restore it), then erased |
| **Each end user**: your id for them, when they were first and last seen | To keep their designs theirs | You erase them, or the project is erased |
| **Designs** and their restore points (up to 50 per design) — unless you [keep designs yourself](/docs/data/own-design-storage), then none | Your users' work | Deleted by your user: hidden at once, erased 30 days later. Otherwise until the person or project is erased |
| **Images** your users upload or generate — unless you [keep uploads yourself](/docs/data/own-upload-handler), then none | Shown in their designs | Deleted by your user, or erased with the person or project. **An image an email went out with keeps its file** (see below) |
| **Brands and brand parts** (yours and your users') | Reused in designs | Deleted, or erased with the person or project |
| **Exports**: a record of each (when, which design, which format), and files you asked for (PDF, PNG, ZIP) | So you can fetch the file, and see what went out | Files: erased with the person or project (`expiresAt` on each file tells you if one will go sooner). Records: kept without the person's id, so the count of what went out stays right |
| **Webhook deliveries**: which event, when, your server's answer | The delivery log in the dashboard | 30 days |
| **AI usage**: counts and costs, no content | Credits and billing | Kept; the person's id is removed when they are erased |
| **Audit trail**: who changed what in your project (keys, sites, settings) | Security and support | Kept with your workspace |

## Images an email went out with are never deleted

An email shows its images from their addresses every time someone opens it — next week or in five
years. Deleting the file would break every copy already sent. So when a design is exported, the
images it shows are marked as sent. Deleting such an image (by your user, or by erasure) removes it
from their library and from every list, and **keeps the file** at its address. The audit trail
records that it was kept.

## Where it is kept

On Lettrove's servers and storage providers. For which providers and regions hold your project's
data, write to support@lettrove.com.

## Deleting

| You want to delete | How |
|---|---|
| One design | Your user deletes it in the editor (erased 30 days later) |
| One person and everything they made | `lettrove.users.erase(userId)` — at once, no grace period ([Erasure and privacy](/docs/data/erasure)) |
| A whole project | Settings → Embed → your project → **Delete**. It stops at once, can be restored for 30 days, then everything in it is erased |

## Keeping your own copy

You can keep every design in your own database as well, or instead: see
[Keeping your own copy](/docs/data/own-copy).
