Privacy Policy

Last updated: 26 March 2026 · Lettly is operated by Lettly Ltd, United Kingdom

The short version: we collect only what we need to run Lettly, we store it securely in the UK/EU, we never sell it, and you can delete it any time.

Who we are

Lettly is a property portfolio management platform for UK landlords, operated by Lettly Ltd, United Kingdom. We are the data controller for personal data collected through lettly.co.

Contact us about privacy: hello@lettly.co

What data we collect

We collect the following categories of personal data:

  • Account data: your name and email address, collected when you sign up via Clerk (our authentication provider)
  • Portfolio data: property addresses, tenancy details, tenant names and contact information, financial figures, compliance certificate dates. All entered by you or extracted from documents you upload
  • Documents: PDFs and images you upload for AI extraction. These are processed and then the extracted data is stored. Raw document files are not stored on our servers.
  • Usage data: pages visited, features used, session information, collected anonymously via Vercel Analytics
  • Payment data: handled entirely by Stripe. We never see or store your card details.

How we use your data

We use your data solely to provide the Lettly service:

  • To create and manage your account
  • To store and display your property portfolio
  • To send compliance reminder emails you request
  • To provide AI-powered document extraction and chat features
  • To process your subscription payments via Stripe
  • To improve Lettly: we may analyse anonymised, aggregated usage patterns

We do not use your data for advertising. We do not sell your data to any third party. Ever.

Who we share data with

We use a small number of trusted third-party services to operate Lettly. Each acts as a data processor on our behalf:

  • Supabase (supabase.com): database storage, hosted in EU West (Ireland). Your portfolio data lives here.
  • Clerk (clerk.com): authentication and user accounts. Stores your name and email.
  • Anthropic (anthropic.com): AI processing for document extraction and chat. Documents are processed transiently and not retained by Anthropic.
  • Vercel (vercel.com): hosting and deployment. Based in the EU when possible.
  • Resend (resend.com): email delivery for compliance reminders.
  • Stripe (stripe.com): payment processing. We never see your card details.

We do not share your data with any other third parties, including letting agents, mortgage brokers, insurance providers, or advertisers.

Where your data is stored

Your portfolio data is stored in Supabase, hosted on AWS EU West (Ireland). This is within the UK GDPR adequacy framework.

Authentication data is stored with Clerk, which operates within EU data centres.

All data in transit is encrypted using TLS. All data at rest is encrypted using AES-256.

How long we keep your data

  • Account and portfolio data: for as long as your account is active, plus 30 days after deletion to allow recovery
  • After 30 days of account deletion: all personal data is permanently deleted from our systems
  • Anonymised usage analytics: retained indefinitely (no personal data)
  • Payment records: retained for 7 years as required by HMRC

Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Right to access: request a copy of all data we hold about you
  • Right to rectification: correct inaccurate data
  • Right to erasure: request deletion of your account and all associated data
  • Right to portability: receive your data in a machine-readable format
  • Right to object: object to processing of your data
  • Right to restrict processing: limit how we use your data

To exercise any of these rights, email hello@lettly.co. We will respond within 30 days.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been handled improperly.

Cookies

Lettly uses only essential cookies required for the service to function:

  • Authentication cookies: set by Clerk to keep you logged in during a session
  • Session cookies: set by Next.js for application state
  • Analytics cookies: anonymised, set by Vercel Analytics, no personal data collected

We do not use advertising cookies, tracking cookies, or third-party marketing cookies. You can disable cookies in your browser settings, but this will prevent you from logging in.

Children

Lettly is not intended for use by anyone under the age of 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us at hello@lettly.co and we will delete it immediately.

Changes to this policy

We will notify active users by email if we make material changes to this privacy policy. The date at the top of this page shows when it was last updated.

Contact

For any privacy questions or requests: hello@lettly.co

Lettly Ltd, United Kingdom