Privacy Policy
Last updated: August 26, 2026
This policy explains what SecureLetter collects when you read the site, subscribe to the newsletter, or create an account, and what we do with it. We collect the minimum we need to run the product, and nothing is sold to third parties.
Who this policy covers
SecureLetter is operated by Leadrogen LLC (Limited Liability Company (LLC)), registered in New Mexico, United States, at 1209 Mountain Road PL NE STE R, Albuquerque, NM 87110, USA. For any privacy question or request, contact contact@secureletter.info.
What we collect
Depending on how you use the site:
- Reading the site. No account or personal data is required. We don't currently run analytics or advertising trackers — see “Cookies” below.
- Newsletter subscription. Your email address, subscription status, which page you signed up from, and — if you were invited by a colleague — the inviter's email address. Confirmation and unsubscribe use single-use tokens, not your identity, so a link in an email can't be used to look you up elsewhere.
- Creating an account. Your name, email address, and a securely hashed password (we never store your password itself). Accounts are optional — you can read every article and get the newsletter without one.
- Editorial actions. If you're a team member with an editor or admin role, actions you take in the CMS (approving, publishing, rejecting content) are recorded in an audit log with your account and a timestamp, so every change to published content is traceable. This is an internal record, not shared publicly.
What we use it for
- Sending the newsletter issue you subscribed to, and honoring an unsubscribe instantly and permanently.
- Letting you log in and access whatever your account role permits.
- Keeping an audit trail of who published or changed editorial content.
- Responding if you email us.
We do not use your data to build an advertising profile, and we do not sell it.
Cookies
The only cookie set today is the session cookie that keeps you logged in after you register or sign in — strictly necessary for the site to function, not used for tracking or advertising, and cleared when you log out or it expires. This site does not currently run analytics, advertising, or third-party tracking cookies. If that changes — for example, if we turn on the analytics integration referenced in our codebase — this section will be updated first and you'll be asked for consent where required.
Who we share data with
A short, honest list — including services that are built into the product but not yet switched on, so this stays accurate as they go live rather than needing a rewrite:
- Database hosting (active). Account and subscriber data is stored in MongoDB, hosted by our database provider, encrypted in transit.
- Email delivery (not yet active). Newsletter and confirmation emails are designed to send through Resend; until that integration is switched on, no third-party email provider receives your address from this system.
- Payments (not yet active). Paid plans are not available yet. When they launch, payment details will be handled directly by Stripe — we never see or store your card number.
- AI assistance (not yet active). Article drafting assistance via Anthropic's API is scaffolded but not in use; it would only ever process editorial content, never subscriber or account data.
We don't share your data with anyone for their own marketing purposes, and we don't sell it.
How long we keep it
Newsletter data is kept until you unsubscribe (instant) or ask us to delete it. Account data is kept while your account is active. Editorial audit-log entries are kept indefinitely for accountability — they record what an editor did, not personal data about readers.
Your rights
You can ask us to access, correct, export, or delete the personal data we hold about you at any time, and unsubscribing from the newsletter is always one click, no account needed. There's no self-service “delete my account” button in the product yet — until there is, email contact@secureletter.info and we'll handle it by hand. If you're in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
Children
SecureLetter is written for business owners and is not directed at children.
Changes to this policy
If this policy changes materially — most likely because one of the “not yet active” integrations above goes live — we'll update the date at the top of this page.