La Lettre LittéraireThree mornings a week

Privacy

Your data, in plain terms.

What we process, why, with whom, for how long — and how to take back control at any time. Said simply, with no catch.

Who is responsible

the data controller

La Lettre Littéraire is published by Romain Detroyat, sole trader (micro-entreprise), 401 A avenue Jacques Cartier, 83000 Toulon, France — SIREN 502 558 125. He is the controller of your data. For any question or request: reponse@lettrelitteraire.fr.

What we process, and why

data, purposes, legal bases

We apply data minimisation: we only collect what is necessary.

  • Your email address and first name, to send you the letter and recognise you in your account — on the basis of your consent (sign-up confirmed by double opt-in).
  • Your subscription and payments(where applicable), to perform the contract and meet our accounting obligations. No card data passes through or is stored by us: payment happens on our provider’s secure page.
  • Reading signals (sends, opens and clicks of the letter, answers to the short quizzes, audio listens, use of the recommender), to gauge interest and improve the ritual — on the basis of our legitimate interest. These measures are kept to the strict minimum (for instance, the recommender keeps neither the text you type nor your email).
  • Referrals (if you take part): the link between referrer and referee, to attribute rewards.

With whom

our processors

We never sell or share your data. To run the service, we rely on technical providers, who act only on our instructions:

  • Supabase — database (hosted in the European Union, Europe region).
  • Vercel — website hosting.
  • Resend — email delivery.
  • Stripe — subscription payments.
  • Anthropic, OpenAI, Google — content generation and verification, and the reading assistant.
  • ElevenLabs — synthetic audio narration (receives only the text to read, no data about you).

Transfers outside the European Union

safeguarded

Some of these providers are established in the United States. Transfers are covered by the safeguards provided for by the GDPR — adherence to the EU–US Data Privacy Frameworkor the European Commission’s standard contractual clauses.

For how long

retention periods

  • Subscribers: as long as your subscription is active, then your details are deleted or anonymised at the latest 3 years after your last contact with us.
  • Proof of consent: kept for as long as needed to evidence it.
  • Reading signals: deleted when your account is deleted; used in aggregate form beyond that.
  • Billing: kept for 10 years, as required by accounting law.

Your rights

and how to exercise them

You have the right of access, rectification, erasure, objection, restriction and portability. The simplest way: unsubscribe in one click from any letter or from your account. For any other request, write to us at reponse@lettrelitteraire.fr — we reply within one month. You may also lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

Cookies

strictly necessary only

We use no advertising trackers and build no profiles. For audience measurement alone — how many people read us, and by which paths they arrive — we count visits ourselves, on our own servers: no cookie, anonymously (no IP address kept, no fingerprint, no cross-site tracking) and strictly aggregated. Nothing is shared with a third party, and it can never identify you.

As for cookies, only a few technical cookies are set: a session cookie (to keep you signed in, 30 days), a language preference cookie (to serve you the site in your chosen language, 1 year) and a reading-measurement cookie (so the same quiz isn’t counted twice, 2 years). All are strictly necessary for the site to work: no prior consent is required.

Artificial intelligence

transparency

Our content is written with the assistance of AI, then verified and proofread before publication — we explain this in our standard. The reading assistant is clearly identified as an AI, and the audio narration is produced by a synthetic voice (flagged beneath each player).

Security

how we protect your data

Data is encrypted in transit and at rest, access is strictly server-side, passwords are hashed, and secrets never appear in the code. We apply the principle of least access.

Updates

this document lives

This policy may change; we will inform you of any significant update. See also our terms & ownership and our legal notice.

This English text is a translation provided for convenience. In case of any discrepancy, the French version prevails.