A nightly letter to tomorrow.
Effective date: June 4, 2026
Selfletter is a journal you keep with yourself. We built it so that the things you write are yours, full stop. This policy explains what we do — and more importantly what we don’t do — with your information.
If you sign in with Apple, Apple gives us:
We do not collect your Apple email address, even when Apple offers to share it.
If you sign in with email and password, we collect:
We do not store your password. Supabase stores only a salted hash of it.
Where your letters are stored depends on how you signed in:
iCloud.com.selfletter.app). The sync is end-to-end between Apple’s servers and your devices. We have no servers in this path and cannot access your iCloud data — only you and Apple can. Apple’s handling is governed by Apple’s Privacy Policy.All communication between the app and our authentication provider (Supabase) is encrypted in transit using TLS 1.2 or higher. Letters synced via CloudKit are encrypted in transit and at rest by Apple. Letter rows stored on Supabase reside in an encrypted Postgres database; your password is stored as a salted hash, never in plaintext. We do not have a mechanism that allows a human at our end to read your letter text in normal operation.
That said, no system is perfectly secure. If we ever discover a security breach affecting your account, we will notify you by email (for email-auth users) and post a notice in the next app update.
Letters stay until you delete them. We do not auto-delete inactive accounts. If you sign out and never sign back in, your account on Supabase remains until you explicitly delete it via the in-app Delete Account flow, or until you email us to request deletion. Deleting the app removes all on-device letters. If you used Sign in with Apple, your iCloud copies remain in your iCloud until you remove them through iOS Settings → [Your name] → iCloud → Manage Storage → Selfletter.
We share data only with the following third-party services, and only as needed to provide the app:
We do not send your letter text to any other third party.
Subscriptions and the lifetime upgrade are processed by Apple through StoreKit. We receive only the entitlement state from Apple (whether you have an active subscription, yes or no). We do not receive your name, billing address, payment method, or transaction history. Apple’s handling of payment information is governed by Apple’s privacy and payments policies.
If you enable the evening reminder, the notification is scheduled and delivered locally on your device by iOS. We do not run a push notification server, do not send remote push notifications, and have no way to see whether a notification was delivered, dismissed, or tapped. You can turn the reminder off at any time in Settings.
If you have Settings → Privacy & Security → Analytics & Improvements → Share With App Developers enabled in iOS, Apple may share aggregated crash and performance reports with us. These reports contain no letter content and no information that personally identifies you. You can opt out at any time in iOS Settings. We do not embed any independent crash-reporting or analytics SDK.
Selfletter is not directed at children under 13, and we do not knowingly collect any information from children under 13. Users in the EU, UK, and other jurisdictions with higher minimum ages should be 16 or older, or have parental consent in line with applicable law. If you believe a child under 13 has used Selfletter, please write to us and we will delete any data associated with that account.
Because we collect so little, there isn’t much for us to give you, correct, or delete on our end. To exercise your rights:
If you are a California resident, you have the right to know what categories of personal information we collect about you, to delete it, to correct it, to opt out of any “sale” or “sharing” (we do neither), and to be free from discrimination for exercising your rights. The only categories we collect are identifiers (an opaque Apple user ID or your email address) and, for email-auth users, the rows containing your own letters. We do not sell or share your personal information for cross-context behavioral advertising. You can exercise these rights using the methods described above.
If you are in a region with GDPR-equivalent law, you have the rights of access, rectification, erasure, restriction, portability, and objection. The legal basis for our processing is the performance of our agreement with you and, where required, your consent (which you give by signing in). You also have the right to lodge a complaint with your local data-protection authority. International transfers of your data may occur to Apple (United States) and Supabase (United States); both rely on appropriate safeguards including standard contractual clauses where applicable.
If we change anything material, we will update the effective date at the top and surface the change in an app update. For email-auth users, we may also notify you by email when changes are material. Continued use after a change means you accept the updated policy.
Questions or concerns: selfletterapp@gmail.com
Selfletter is built and operated by Gurshan Mann, based in California, United States.