Skip to main content

Legal · Privacy

Privacy policy

The short version: OwnLetter collects almost nothing. If you just read the site, we set zero cookies and we cannot identify you. We only hold personal data if you choose to give it to us, through the quiz email opt-in, the newsletter signup, or a comment. We never sell data, run no ads, and do no cross-site tracking.

Effective date: June 10, 2026 · Last updated: June 10, 2026

1. Who is responsible for your data

The data controller is Arthur Brulard, individual entrepreneur (micro-entrepreneur) registered in france, publishing this site under the trade name OwnLetter. Full identification is on the legal notice. For anything privacy-related, write to contact@ownletter.com. No data protection officer is required for an operation of this size; the publisher answers directly.

2. What we collect, why, and for how long

Each row is one processing activity. Providing data is never required to read the site; the quiz result itself is shown without an email.

ActivityDataLegal basisRetention
Quiz result by email (optional)Email address, your quiz answers, the platforms we recommendedConsent (unticked checkbox you actively check)3 years from your last interaction with us, or deleted earlier on request
Newsletter (optional)Email address, where on the site you signed up (placement and page)Consent (unticked checkbox you actively check)3 years from your last interaction with us, or deleted earlier on request; every issue has an unsubscribe link
CommentsName (published next to your comment), email (converted to a one-way hash on arrival; the address itself is never stored and never published), comment text, your browser's user-agent string and the form submission timing (spam detection), and a salted one-way hash of your IP addressConsent for publishing your name; legitimate interest for spam preventionAs long as the comment stays published; deleted with the comment
Abuse prevention (AI analysis)A salted one-way hash of your IP address (never the raw IP)Legitimate interest (protecting the service from automated abuse)Used only to enforce an hourly request limit; never used to identify you
Web analyticsAggregated, cookieless page-view and usage statistics (see cookies page): scroll depth, clicked areas and anonymised session replays (form inputs are always masked), processed in the EU by PostHog. Nothing is stored on your device, stored statistics are not associated with your IP address, and identity does not persist across visitsLegitimate interest (audience measurement)Aggregated statistics only
Hosting logsStandard server logs operated by our host (Vercel)Legitimate interest (security, operations)Vercel's standard log retention

The 3-year prospect retention follows the French data protection authority's standard for commercial contact data. Every email we send includes a way to unsubscribe; unsubscribing stops emails immediately, and you can additionally ask us to erase your address entirely.

3. The AI-generated quiz analysis

If you use the quiz, your answers (multiple-choice identifiers like "q3b") and the names of the platforms we recommended to you are sent to OpenRouter, Inc. to generate your written analysis with a large language model. Nothing in that request identifies you: your email address is never part of it, so the AI provider cannot link the answers to you. OpenRouter states that by default it does not retain prompts after processing. The analysis is editorial output about newsletter platforms; it produces no legal or similarly significant automated decision about you.

4. Who processes data on our behalf

We use four processors. None of them may use your data for their own purposes.

ProviderRoleLocationTransfer safeguard
Vercel Inc.Site hosting, server logs and cookieless web analyticsUnited StatesEU-U.S. Data Privacy Framework (certified) + SCCs
Supabase (Supabase PTE. Ltd. / Supabase Inc.)Database hosting (quiz and newsletter leads, comments, rate-limit counters)United States (us-east-1)Standard Contractual Clauses (EU 2021/914)
Resend (Plus Five Five, Inc.)Email delivery and contact list hostingUnited StatesEU-U.S. Data Privacy Framework (certified) + SCCs
OpenRouter, Inc.AI generation of the quiz analysis (receives quiz answers only, never your email)United StatesStandard Contractual Clauses / adequacy decisions

The controller is established in France, so this data travels from the EU to the United States. Transfers rely on the EU-U.S. Data Privacy Framework where the provider is certified, and on the European Commission's Standard Contractual Clauses otherwise, as listed above (verified on each provider's legal pages, June 2026).

5. Your rights

Under the GDPR you can ask for access, rectification, erasure, restriction, portability, and you can object to processing based on legitimate interest. Where processing relies on your consent (the quiz email), you can withdraw it at any time; withdrawal does not affect what happened before. Email contact@ownletter.com and we will answer within one month.

You also have the right to lodge a complaint with the French supervisory authority, the CNIL: cnil.fr/fr/adresser-une-plainte.

6. For California and other US visitors

Most of our readers are in the United States. California's Online Privacy Protection Act (CalOPPA) asks us to state the following, and we extend the same answers to every visitor:

  • Categories collected: email address (quiz opt-in and newsletter signup), name (comments, published) and a one-way hash of the commenter's email, quiz answers, browser user-agent strings and submission timing (comment spam detection), and salted IP hashes for abuse prevention. Nothing else.
  • Third parties: only the four processors listed in section 4, acting on our instructions. We do not sell or share personal information with anyone for advertising. No third party collects behavioral data across other websites through this site.
  • Review and change your data: email contact@ownletter.com to review, correct, or delete anything we hold about you. We honor these requests for all visitors, wherever you live.
  • Do Not Track: we do not respond to browser Do Not Track signals, because there is nothing to turn off: this site does not track users over time or across third-party websites in the first place.
  • Change notifications: material changes to this policy are posted on this page with an updated date at the top.

For completeness: the CCPA/CPRA applies to businesses above certain thresholds (annual gross revenue over $25M as adjusted for inflation under the CPRA, or data on 100,000+ consumers, or half of revenue from selling data). OwnLetter is far below all three and sells no data, so it is not a covered business. We apply the access and deletion rights above anyway.

7. Children

This site is written for adults choosing newsletter software. It is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has submitted personal information, contact us and we will delete it promptly.

8. Related pages

What the site stores in your browser: cookies. How we earn commissions: how we make money. Who publishes the site: legal notice. Rules for using the site: terms of use.

Last updated: June 10, 2026 · Questions: contact@ownletter.com