Privacy Policy

Privacy Policy

This policy explains how The Letter accesses, uses, protects, retains and deletes personal information, including Google user data.

Last updated: August 5, 2026.

Information we collect

We collect account information such as name, email address and a password hash, plus the journals, pages, moods, appointments, clinical relationship information and optional Spotify URLs you choose to add. If a therapist chooses to connect Google, we also process the limited Google user data described below.

How we use information

We use this information to create and secure accounts, store journals and appointments, support therapist-patient collaboration, provide sharing links, show mood summaries, send account-related emails and provide the optional Google Meet functionality described below.

Google user data and OAuth services

The Google integration is optional and available to authenticated therapist accounts. The Letter requests only these OAuth scopes:

  • openidReceives a stable Google account identifier so the Google connection can be associated with the therapist's The Letter account.
  • emailReads the Google account email address so the therapist can see which Google account is connected.
  • https://www.googleapis.com/auth/meetings.space.createdAllows The Letter to create, modify and read metadata for Google Meet spaces created by The Letter. We use it only when the therapist explicitly asks to add a Google Meet link to an appointment.

For a connected Google account, we store the Google account identifier, email address, granted scopes, connection status, token expiry and OAuth access and refresh tokens. The OAuth tokens are encrypted at rest. When a Meet space is created, the returned meeting link is stored with the appointment.

The Letter does not request or access Google Calendar, Gmail, Google Drive, contacts, existing meeting lists, meeting recordings, transcripts or meeting content.

A Google Meet link attached to an appointment is available only to the authenticated therapist and the patient assigned to that appointment so they can join the session. Google user data is not sold, used for advertising, credit decisions or training generalized AI or machine-learning models.

The Letter's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Data protection measures

We use technical and organizational safeguards appropriate to the sensitivity of the information we process, including:

  • HTTPS/TLS encryption for data transmitted between users, The Letter and Google in production.
  • AES-256-GCM authenticated encryption for stored Google OAuth access and refresh tokens.
  • Authentication and account-level authorization so Google integration endpoints are limited to the therapist who owns the connection.
  • OAuth tokens and client secrets are not returned in integration status responses and are restricted to server-side processing.

Data retention and deletion

Google connection data is retained while the integration and The Letter account remain active so the therapist can create Meet spaces without reconnecting for every appointment.

When the therapist disconnects Google in The Letter, stored OAuth access and refresh tokens, token expiry and the granted-scope list are deleted immediately. Minimal account identifier, email, connection status and audit timestamps may remain until the The Letter account is permanently deleted. The therapist may also revoke The Letter from the Google Account permissions page.

Meet links already added to appointments remain part of the appointment record while that record is retained, because the therapist and assigned patient need the link to join the scheduled session.

A user may request account deletion in Settings or through the account-deletion process. The account enters a 30-day deletion period; when deletion is finalized, the associated Google integration record and remaining Google connection data are deleted with the account.

Limited non-content information may be retained only where required for legal obligations, fraud prevention, security, accounting or regulatory compliance. Google OAuth access and refresh tokens are not retained after disconnection or completed account deletion.

Read the account-deletion instructions

Cookies and local storage

The Letter uses essential browser storage to keep you signed in, remember your language preference and save your theme preference. With your consent, we may use privacy-conscious product analytics to understand page views, CTA clicks and registration funnel drop-off. We do not use advertising cookies.

Sharing

Your journals are private unless you generate and share a read-only link or explicitly grant an authorized therapist access. Anyone with a share link may view the shared journal until the link is regenerated or access changes. Google Meet links are shared only as described in the Google user data section above.

Third-party services

The Letter uses Google API Services for the optional Google Meet integration and may use infrastructure providers for hosting, private database storage and transactional email. These providers process information only as needed to operate the service. Spotify embeds are loaded only when you add a Spotify URL to a page. We do not sell personal information or Google user data.

Contact

For privacy questions or requests concerning personal information or Google user data, contact The Letter at:

support@contact.theletter.eu