Privacy Policy

Version: 5 October 2026

What Lettrium does

Lettrium is a consent-based email workspace. Users sign in, connect their own sender account separately, manage recipients and request email delivery. Signing in with Google does not authorize Gmail sending.

Information we access and store

Gmail access is send-only. Lettrium does not use this access to read inbox messages, replies, contacts or Google Drive files.

Purpose and limits on use

We use this information to authenticate users, connect authorized senders, process user-requested delivery, enforce recipient preferences and rate limits, troubleshoot faults, and prevent abuse. Google user data is not sold, used for advertising or used to train generalized AI models.

Google user data is handled according to the Google API Services User Data Policy, including its Limited Use requirements. Human access must be limited to user-authorized support, necessary security investigations, legal obligations or other uses allowed by that policy.

Sharing and service providers

Messages and recipient addresses are transmitted to the selected email delivery provider—Google, Microsoft or Amazon Simple Email Service (Amazon SES)—to perform the requested send, and then to the intended recipients. When Amazon SES is selected, sending uses a domain identity verified by the workspace and tenant-scoped SES resources. Our application hosting (Vercel), email delivery, job processing and key management (AWS, including Amazon SES), and database infrastructure (Neon) process service data to run Lettrium. Primary function, database and job-processing workloads are configured in Frankfurt, Germany. Access is limited to the service purpose; these providers are not recipients for advertising or resale.

Infrastructure providers may process operational or support information outside Türkiye, including through their control planes. We may disclose information where required by law or necessary to address security incidents, consistently with applicable policy.

Storage, retention and account closure

OAuth credentials are encrypted. Disconnecting a sender immediately removes its locally stored tokens and prevents new use through that connection; remaining connected-account metadata is redacted after 90 days. Expired OAuth transaction records are deleted one day after expiry. Expired or revoked application sessions are deleted after 30 days.

For completed or abandoned sends, message subject/body and sender snapshots are redacted after 90 days; provider identifiers, delivery attempts and queue details are also removed after 90 days while a minimal final status may remain. Security and application audit entries are deleted after 12 months. CloudWatch application logs are configured for 30 days, and the database restore-history window is configured for 6 hours.

Account closure immediately revokes local sessions and sender connections, removes locally stored sender tokens, pauses applicable active campaigns and pseudonymizes profile identifiers. Consent, unsubscribe and suppression evidence is retained while the workspace is active and for up to three years after workspace closure where needed to respect opt-outs, investigate abuse or meet legal obligations. A legal hold or binding legal requirement may extend a period. Backups and provider copies expire on their configured cycles; messages already submitted to a provider cannot be recalled.

Your controls

Use Settings → Sender accounts to disconnect. You can also remove Lettrium’s access in your Google Account connections. Settings → Account offers an account-data export and account closure. The export includes identity, connection metadata, memberships and recent campaign history, not OAuth/session secrets or a complete export of every workspace record. Privacy requests and applicable access, correction or deletion rights can be exercised through the contact below once published.

Cookies and changes

Lettrium uses first-party session cookies for sign-in. Where language selection is enabled, a first-party cookie remembers that preference. These are not advertising cookies. Policy changes will be published on this page with an updated version date; materially different access must be explained before requesting it.

Operator and contact

Lettrium is operated by Semih Arda Öngül in Türkiye.

For support, privacy requests, abuse reports and other concerns: support@lettrium.com.