Letterpier · Privacy policy
Version 1.0 · Last updated 30 September 2026
https://app.letterpier.com/legal/privacy
Privacy policy
Datenschutzerklärung
How Letterpier handles personal data: what we collect, why, who helps us, how long we keep it, and your rights.
Contents (17)
Letterpier is operated by Michael Ketzer, Rotkehlchenweg 51, 40789 Monheim am Rhein, Germany (“we”, “us”). We are the controller (Verantwortlicher) for the processing described in this policy, except where § 2 says we act for a customer. Our full details are in the legal notice.
Contact for data protection: mail@michael-ketzer.com. You can write to us in German or English.
No data protection officer has been designated. We are not required to designate one (§ 38 BDSG): fewer than 20 people regularly process personal data for us.
Letterpier is an email service for businesses. Depending on the data, we play one of two roles under the GDPR.
We are the controller for
- delivering and securing our website and dashboard;
- sign-in and user accounts;
- access requests and email you send us;
- audit logs of actions in the dashboard;
- handling abuse and security reports, and the evidence they involve;
- billing, once it exists (there is none yet).
We are a processor for our customers
As a processor (Auftragsverarbeiter, Art. 28 GDPR) we handle the following on our customers’ behalf and on their instructions:
- outgoing and incoming messages: addresses, subjects, bodies, headers, attachments and the original .eml files;
- delivery events and webhook deliveries;
- suppression lists;
- domains and their DNS records;
- API usage.
For this data, the customer is the controller.
If you received an email sent through Letterpier, or sent an email to an address on a domain that uses Letterpier, the organisation behind that domain decides how your data is used. Please contact it first. We process that data on its behalf and will pass your request on.
Where we use customer data for our own narrow purposes, namely keeping the platform secure, preventing abuse and meeting legal obligations, we are the controller for that use (§ 10).
Letterpier currently serves its operator’s own products: Letterpier, Shinra Metrics and Reichweitenamt. Shinra Metrics is run by a separate legal entity; it is our customer, and we act as its processor. Reichweitenamt belongs to the same legal person as Letterpier, so there is no processor relationship with it.
Our website and dashboard run on a single server we rent from OVH, in an EU data centre (Limburg, Germany). The server is shared with other workloads of ours.
When you load a page, your browser sends us your IP address and the request (the address of the page, your browser’s user agent and similar technical details). We process them only to deliver the page and to protect the service. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is a secure website that works.
app.letterpier.com, which serves our website, dashboard and API, keeps no access log. Plain-HTTP requests (which we only redirect to HTTPS, or use for certificate checks) and requests to mail.letterpier.com and postal.letterpier.com are recorded in our web server’s access log: IP address, time, request line, status, response size, referring page and browser user agent. We keep them for up to 14 days (web server logs rotate daily; container logs are capped at 3 × 10 MB per service and overwritten as they fill).
Error logs of the web server, the application and our mail server can contain IP addresses or email addresses when something goes wrong; we keep them for up to 14 days (web server logs rotate daily; container logs are capped at 3 × 10 MB per service and overwritten as they fill).
We use no analytics, advertising, tracking pixels, third-party scripts, embedded content or remote fonts. Our fonts are served from our own server, and our pages load nothing from other websites.
You can read the public website without giving us any personal data.
What we collect. When you use the request-access form: your name, work email, company or organisation, product or website, what you plan to send, rough monthly volume, sending domains, your note, and your two confirmations (that you are a business and that you will send transactional email only).
To accept only one request per email address per day, we keep a one-way hash of your email address and the date for 24 hours. To limit abuse of the form, we also count requests per IP address, stored as a one-way hash of the address and the hour and deleted about 24 hours after that hour ends.
Why, and on what basis. To review and answer your request and to prepare a contract with your organisation (Art. 6(1)(b) GDPR, steps taken at your request before a contract). Where no contract is in view, our legitimate interest in answering enquiries and preventing abuse of the form (Art. 6(1)(f) GDPR).
How it’s processed. Your request is sent to us as an email through Letterpier itself. It is stored in our own Letterpier project, where your details are in the encrypted message body; only the subject (“Access request: <company>”) is stored unencrypted. Our mail server (Postal) keeps an unencrypted copy, as it does for every message (§ 9). The email then arrives in our mailbox at OVHcloud (OVH Mail).
We don’t send an automatic reply to the address you enter, and we don’t use it for marketing. We reply personally, by email, if Letterpier is a good fit.
How long. In our Letterpier project, for the message retention set for that project (1 to 90 days; 30 by default). In our mailbox: until we have decided on the request, then up to 6 months; if a business relationship follows, as long as commercial law requires (up to 6 years for business letters).
If you email us, we process what you send: your address, your message and anything in it. We use it to answer you and to handle your matter. Legal basis: Art. 6(1)(b) GDPR where your message concerns a contract or steps towards one, otherwise Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries).
Our mailbox is hosted by OVHcloud (OVH Mail). We keep emails until the matter is resolved, and longer where commercial law requires it: 6 years for business letters (§ 257 HGB, § 147 AO).
Sign-in codes. To sign in, you enter your email address and we send you a single-use six-letter code. Codes expire after 10 minutes and allow at most five attempts. We store only a keyed hash of the code, plus an encrypted copy until the email has been handed to our mail server, and we delete expired codes automatically. The application never logs codes in plain text. We send a code only if an account exists for the address, and we tell nobody whether it does.
The code email is a service message about your sign-in, sent through our own mail server (Postal). Postal keeps the message for 7 days, and a delivery record (your address, the subject with the code, and the delivery status) for 30 days. The code has long expired by then. The email contains no tracking.
Your session. After you sign in, your session is kept in a signed and encrypted cookie that expires 7 days after you sign in; after that you sign in again with a new code. On every request we check that your account still exists and is active.
Preventing abuse. Sign-in requests are rate-limited. For this we store an unkeyed one-way (SHA-256) hash of your email address combined with a time window of up to one hour, and a counter. We also limit requests per IP address, stored the same way as a hash of the address and the hour. A hash like this can’t be read back, but someone who already knows an address could recognise it, so we treat it as personal data. These entries are deleted about 24 hours after their window ends.
Legal basis. Art. 6(1)(b) GDPR where you are our contract partner; where your organisation is, Art. 6(1)(f) GDPR (our legitimate interest in giving the people our customers name access to their projects). Rate limits and session checks: Art. 6(1)(f) GDPR (our legitimate interest in protecting accounts against misuse).
What we store. Your name and email address; your organisation and project memberships and roles; metadata of the API keys you create (name, the first characters of the key, environment, permission, and when it was created, last used or revoked; the keys themselves are stored only as hashes and shown once); and audit log entries (who did what to which object, and when).
Where it comes from. From you, or from the organisation that asked us to create your account (for example your employer). There is no self-service sign-up.
Why, and on what basis. To provide the dashboard and the API. Where you are our contract partner, the basis is Art. 6(1)(b) GDPR. Where your organisation is, it is Art. 6(1)(f) GDPR: our legitimate interest in giving the people our customers name access to their projects. Audit logs keep a record of changes for security and accountability (Art. 6(1)(f) GDPR).
How long. For as long as the account exists. Audit logs: 12 months, then deleted automatically.
For customer projects we process the categories listed in § 2 as a processor. The customer decides why and for how long; our data processing agreement with the customer governs the details.
Message bodies, attachments, original messages, DKIM keys and webhook secrets are encrypted at rest with keys managed by our application (AES-256-GCM). This is encryption at rest with keys the application manages. It is not end-to-end encryption. Addresses, subjects and delivery events stay unencrypted so they can be searched and mail can be routed.
Our mail server software (Postal) keeps unencrypted copies of raw messages and DKIM private keys in its private database for its own processing. It keeps raw messages for 7 days and metadata for 30 days.
Customers choose how long message content is kept, from 1 to 90 days per project (30 by default). Deleting a message removes our copy and Postal’s. Encrypted backups keep seven daily recovery points, so deleted data disappears from backups as they expire. One exception: a copy of the backup repository made on is kept on the operator’s own computer; it doesn’t expire automatically and keeps the data of that day until it is deleted or replaced.
We don’t track opens or clicks, and we don’t offer newsletters, contact lists or campaigns.
We process data to keep Letterpier secure and to stop misuse: abuse and security reports and the evidence attached to them, which may name people who never contacted us; the messages, addresses and delivery events concerned; the integrity of suppression lists; and requests from authorities.
Legal basis: Art. 6(1)(c) GDPR where the law requires it, otherwise Art. 6(1)(f) GDPR (our legitimate interest in a secure service that is not used for spam, fraud or attacks). We keep this data as long as the purpose requires, and beyond that only for the applicable limitation periods.
If you are named in a report, the data comes from the person who reported. You can ask us what we hold (§ 14).
We share personal data only with the providers below, who process it for us under data processing agreements, and with recipients’ mail servers when a message is delivered. We may also have to disclose data to authorities or courts where the law requires it.
| Provider and role | Purpose | Location | Transfer basis |
|---|---|---|---|
| OVH (OVH GmbH (OVHcloud), Cologne, Germany)Processor | The server that runs our website, dashboard, background worker, mail server (Postal) and its database, the encrypted volume for received messages (.eml) and their attachments, and our encrypted backups. | Data centre: Limburg, Germany, EU. Headquarters: France. | No transfer (EU). Data processing agreement: www.ovhcloud.com/de/terms-and-conditions/contracts |
| Neon (Databricks, Inc., the parent company of Neon, LLC)Processor | Our application database (PostgreSQL), which holds accounts, projects and message records. | Amazon Web Services eu-central-1, Frankfurt, Germany. Headquarters: USA (Databricks, Inc.). Neon’s own processors include Amazon Web Services. | EU-US Data Privacy Framework and the Standard Contractual Clauses in Neon’s data processing agreement: www.databricks.com/legal/dpa |
| Vercel Inc.Processor for our registrant and account data | Registration and DNS for letterpier.com. Vercel answers DNS lookups for letterpier.com, so it sees the DNS resolver that asks (usually your provider’s), not the pages you read. It doesn’t host Letterpier and never sees message data. | USA | EU-US Data Privacy Framework; Standard Contractual Clauses in Vercel’s data processing agreement: vercel.com/legal/dpa |
| OVHcloud (OVH Mail)Processor | Our mailbox: access requests and email you send us. | OVHcloud data centres in the EU | No transfer (EU). Data processing agreement as part of OVHcloud’s contract terms. |
| Recipients’ mail serversIndependent recipients, not processors | Delivering the messages our customers send. | Worldwide, wherever the recipient’s mailbox is hosted | Necessary to carry out the customer’s instruction to deliver the message. |
Recipients of personal data
OVH (OVH GmbH (OVHcloud), Cologne, Germany)Processor
- Purpose
- The server that runs our website, dashboard, background worker, mail server (Postal) and its database, the encrypted volume for received messages (.eml) and their attachments, and our encrypted backups.
- Location
- Data centre: Limburg, Germany, EU. Headquarters: France.
- Transfer basis
- No transfer (EU). Data processing agreement: www.ovhcloud.com/de/terms-and-conditions/contracts
Neon (Databricks, Inc., the parent company of Neon, LLC)Processor
- Purpose
- Our application database (PostgreSQL), which holds accounts, projects and message records.
- Location
- Amazon Web Services eu-central-1, Frankfurt, Germany. Headquarters: USA (Databricks, Inc.). Neon’s own processors include Amazon Web Services.
- Transfer basis
- EU-US Data Privacy Framework and the Standard Contractual Clauses in Neon’s data processing agreement: www.databricks.com/legal/dpa
Vercel Inc.Processor for our registrant and account data
- Purpose
- Registration and DNS for letterpier.com. Vercel answers DNS lookups for letterpier.com, so it sees the DNS resolver that asks (usually your provider’s), not the pages you read. It doesn’t host Letterpier and never sees message data.
- Location
- USA
- Transfer basis
- EU-US Data Privacy Framework; Standard Contractual Clauses in Vercel’s data processing agreement: vercel.com/legal/dpa
OVHcloud (OVH Mail)Processor
- Purpose
- Our mailbox: access requests and email you send us.
- Location
- OVHcloud data centres in the EU
- Transfer basis
- No transfer (EU). Data processing agreement as part of OVHcloud’s contract terms.
Recipients’ mail serversIndependent recipients, not processors
- Purpose
- Delivering the messages our customers send.
- Location
- Worldwide, wherever the recipient’s mailbox is hosted
- Transfer basis
- Necessary to carry out the customer’s instruction to deliver the message.
Letterpier supports Cloudflare R2 for storing attachments, but doesn’t use it. If we ever do, it will be with EU jurisdiction, and we will update this list first.
Apart from these providers, a copy of our backup repository, made on , is kept on the operator’s own computer (§ 9).
Neon (part of Databricks, Inc., USA) and Vercel Inc. (USA) are headquartered in the United States. We rely on their certification under the EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023, Art. 45 GDPR) and on the Standard Contractual Clauses in their data processing terms (Art. 46(2)(c) GDPR).
US providers may be subject to US government requests for access.
When an email is delivered to a recipient whose mailbox provider is outside the EU, it necessarily goes there.
We delete personal data when it is no longer needed for its purpose, unless the law requires us to keep it.
| Data | How long |
|---|---|
| Web requests | app.letterpier.com: no access log. Plain-HTTP requests and requests to mail.letterpier.com and postal.letterpier.com: access log, up to 14 days (web server logs rotate daily; container logs are capped at 3 × 10 MB per service and overwritten as they fill). Error and application logs: up to 14 days (web server logs rotate daily; container logs are capped at 3 × 10 MB per service and overwritten as they fill) |
| Rate-limit entries (sign-in and request-access form) | About 25 hours (a window of up to 1 hour, plus 24 hours) |
| Duplicate-request check (request-access form) | 24 hours |
| Sign-in codes | Expire after 10 minutes; deleted automatically after that |
| Sign-in emails at our mail server | Message 7 days; delivery record 30 days |
| Session cookie | 7 days after you sign in |
| Accounts | As long as the account exists |
| Customer message content, attachments and events | 1 to 90 days per project (30 by default). Lowering the period also applies to existing data. Deleting a message also removes Postal’s copies. |
| Postal raw messages and metadata | Raw messages 7 days; metadata 30 days |
| Backups | 7 daily recovery points; deleted data disappears as they expire. One exception: a copy of the backup repository made on is kept on the operator’s own computer; it doesn’t expire automatically and keeps the data of that day until it is deleted or replaced. |
| Neon restore history | the restore window configured for our Neon project |
| Suppression lists | until the project allows the address again, or until the project is deleted |
| Content-free receipt fingerprints | Kept, so deleted mail can’t be replayed into the system. They contain no content or addresses. |
| Audit logs | 12 months, then deleted automatically |
| Access requests and business letters | until we have decided on the request, then up to 6 months; if a business relationship follows, as long as commercial law requires (up to 6 years for business letters) |
| Invoices (not yet issued) | 8 years (§ 147(3) AO, § 257(4) HGB, as amended from 1 January 2025) |
Retention periods
Web requests
- How long
- app.letterpier.com: no access log. Plain-HTTP requests and requests to mail.letterpier.com and postal.letterpier.com: access log, up to 14 days (web server logs rotate daily; container logs are capped at 3 × 10 MB per service and overwritten as they fill). Error and application logs: up to 14 days (web server logs rotate daily; container logs are capped at 3 × 10 MB per service and overwritten as they fill)
Rate-limit entries (sign-in and request-access form)
- How long
- About 25 hours (a window of up to 1 hour, plus 24 hours)
Duplicate-request check (request-access form)
- How long
- 24 hours
Sign-in codes
- How long
- Expire after 10 minutes; deleted automatically after that
Sign-in emails at our mail server
- How long
- Message 7 days; delivery record 30 days
Session cookie
- How long
- 7 days after you sign in
Accounts
- How long
- As long as the account exists
Customer message content, attachments and events
- How long
- 1 to 90 days per project (30 by default). Lowering the period also applies to existing data. Deleting a message also removes Postal’s copies.
Postal raw messages and metadata
- How long
- Raw messages 7 days; metadata 30 days
Backups
- How long
- 7 daily recovery points; deleted data disappears as they expire. One exception: a copy of the backup repository made on is kept on the operator’s own computer; it doesn’t expire automatically and keeps the data of that day until it is deleted or replaced.
Neon restore history
- How long
- the restore window configured for our Neon project
Suppression lists
- How long
- until the project allows the address again, or until the project is deleted
Content-free receipt fingerprints
- How long
- Kept, so deleted mail can’t be replayed into the system. They contain no content or addresses.
Audit logs
- How long
- 12 months, then deleted automatically
Access requests and business letters
- How long
- until we have decided on the request, then up to 6 months; if a business relationship follows, as long as commercial law requires (up to 6 years for business letters)
Invoices (not yet issued)
- How long
- 8 years (§ 147(3) AO, § 257(4) HGB, as amended from 1 January 2025)
You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), erased (Art. 17) or its processing restricted (Art. 18), and to receive data you gave us in a common, machine-readable format (Art. 20).
To use these rights, write to mail@michael-ketzer.com. We answer without undue delay and within one month. Where a request is complex, this can be extended by two further months; we will tell you within the first month (Art. 12(3) GDPR). For data we process for a customer (§ 2), we pass your request on to the customer.
Right to object (Art. 21 GDPR)
Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We will then stop, unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves legal claims.
To object, write to mail@michael-ketzer.com. We don’t use your data for direct marketing.
Complaints. You can complain to a supervisory authority. The authority responsible for us is Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de. You can also contact any other supervisory authority, in particular where you live or work.
We don’t ask for your consent for any processing, so there is no consent to withdraw.
No law requires you to give us data. You can read our website without providing personal data. To request access we need your name, work email, company, what you plan to send, and your two confirmations (that you are a business and will send transactional email only); the other fields are optional. To sign in we need your email address. Without them we can’t answer your request or give you an account.
We don’t make automated decisions with legal or similarly significant effects, and we don’t build profiles (Art. 22 GDPR). Rate limits, and the automatic suppression of addresses that fail permanently, are technical safeguards, not decisions about you.
We update this policy when our processing changes, before the change takes effect. The date and version at the top show the current version; the version history below lists earlier ones.
Version history
| Date | Version | Changes |
|---|---|---|
| Version 1.0 (this version) | First published version. |