Privacy Policy

Last updated July 27, 2026

Lettertrace is operated by The Letter Company. This policy explains what we collect when you use the hosted service at lettertrace.com, why we collect it, and who else sees it.

1.Information we collect

Account information. Your email address, and, if you sign in with Google or GitHub, the name and profile picture that provider returns. We never receive your Google or GitHub password.

Monitoring configuration. The brands, domains, aliases, competitors, topics, and prompts you set up, plus your model and schedule preferences.

Run results. For each monitoring run we store the full text of the answers the AI models returned, the web sources they cited, and the brand and competitor mentions detected in them, along with sentiment and position.

Provider API keys. If you bring your own Anthropic or OpenAI key, we store it encrypted (see §5) so scheduled runs can use it. We also store a short hint such as sk-…4a9c so you can tell your keys apart.

Lettertrace API keys. Stored only as SHA-256 hashes. The full key is shown once at creation and cannot be recovered by us or by you afterwards.

Usage counters. If you use trial runs on our shared provider keys, we count the runs and tokens consumed so we can apply the free-run limit.

We do not use advertising trackers, and we do not build behavioural profiles of you.

2.What we send to AI providers

This is the part most worth understanding, because it is the core of what Lettertrace does.

When a monitoring run executes, we send your prompts to Anthropic and/or OpenAI. If web search is enabled for a project, those providers also run search queries derived from your prompts. The answers come back to us and are stored against your account.

Under bring-your-own-key, those requests are made with your API key, under your own account with that provider. How they handle, retain, and train on that traffic is governed by your agreement with them, not by this policy. Review Anthropic's and OpenAI's privacy terms directly.

If you instead use trial runs on our shared keys, those requests are made under The Letter Company's provider accounts and are subject to our agreements with those providers.

Prompts are questions about a market or category. Do not put personal data, customer information, or confidential material into a prompt. It will be transmitted to a third-party model provider.

3.Website content we fetch

During onboarding you can give us a brand's domain, and we fetch that site's public homepage to suggest topics and prompts. We fetch only publicly reachable pages over HTTP(S), and we block requests to private and internal network addresses. We store the extracted text only long enough to generate suggestions.

4.How we use your information

  • To operate the service: run monitors, detect mentions, and show your results.
  • To authenticate you and keep your account secure.
  • To enforce free-trial limits, where you use our shared provider keys.
  • To respond to support requests you send us.
  • To diagnose faults and keep the service running.

We do not sell your personal information, and we do not share it for advertising.

5.Security

Provider API keys are encrypted at rest using AES-256-GCM with a unique initialization vector per key. They are decrypted only in memory, at the moment a run executes.

Lettertrace API keys are stored as SHA-256 hashes only, never in plaintext.

Your data is isolated per account by Postgres Row Level Security, enforced by the database rather than only by application code. Elevated database access is limited to the scheduled-run job and the API-key-authenticated surface, where every query is scoped to the key's owner.

Traffic to and from lettertrace.com is encrypted in transit over TLS. No system is perfectly secure, and we cannot guarantee absolute security.

6.Service providers

We rely on the following processors to run Lettertrace:

  • Supabase: database, authentication, and storage of everything described in §1.
  • Vercel: application hosting and request logs.
  • Anthropic and OpenAI: the AI models queried during runs, as described in §2.
  • Google and GitHub: optional sign-in. They tell us your email, name, and profile picture; we tell them nothing about your usage.

We may also disclose information where legally required, or to protect the rights and safety of our users or the service.

7.Data retention

Your configuration and run history are retained for as long as your account is active, because the product's value is the trend over time. Deleting old runs would erase the record of how your visibility changed.

When you delete a project, its topics, prompts, competitors, runs, responses, sources, and mentions are deleted with it. When your account is deleted, everything associated with it is deleted.

Deleting a provider API key removes the encrypted value immediately. Revoking a Lettertrace API key takes effect immediately.

8.Your rights

You can, at any time:

  • Access and correct your account and project information in the dashboard.
  • Delete individual projects, prompts, competitors, or provider keys.
  • Revoke Lettertrace API keys.
  • Request a copy of your data, or deletion of your account, by emailing us.

Depending on where you live, you may have additional rights under the GDPR, the UK GDPR, or the CCPA, including access, correction, deletion, portability, and objecting to certain processing. We honour these requests regardless of where you are. We do not sell personal information as defined by the CCPA.

9.Cookies

We use cookies only for authentication, keeping you signed in and refreshing your session. We do not use advertising or cross-site tracking cookies. Clearing them signs you out.

10.Children

Lettertrace is a business tool and is not directed at children under 16. We do not knowingly collect information from them. If you believe a child has given us information, email us and we will delete it.

11.International transfers

The Letter Company operates in the United States, and our service providers process data in the United States and other countries. Using Lettertrace means your information may be transferred to and processed in those countries.

12.Scope of this policy

This policy covers the hosted Lettertrace service that we operate at lettertrace.com. It does not cover any separately operated deployment of the software, where we would neither hold nor receive the data.

13.Changes to this policy

We may update this policy as the service changes. We will update the date at the top, and for material changes we will make a reasonable effort to notify you. Continuing to use Lettertrace after an update means you accept the revised policy.

14.Contact

Questions about this policy, or requests about your data: privacy@letterbrace.com

Lettertrace is operated by The Letter Company. Privacy Policy · Terms of Service