BlueLetter

Privacy Policy

Effective date: 21 August 2026 · Last updated: 21 August 2026

BlueLetter is a mobile application that scans Dutch government letters and returns a translation, a plain-language summary, and extracted deadlines. This privacy policy explains what data we collect, why we collect it, how we share it, and what rights you have over it under the EU General Data Protection Regulation (GDPR) and the EU AI Act.

It covers both the iOS app and the tryblueletter.com website, including the waitlist form. Where a section applies to only one of the two, it says so.

This document is written in plain English. If anything is unclear, please contact us at the address below — we'll explain in writing.

1. Who we are

BlueLetter ("we," "us," "our") is operated by Marco Santini, a sole proprietor based in the Netherlands. We are the data controller for the personal data described below.

Contact: privacy@tryblueletter.com

We are not legally required to appoint a Data Protection Officer because our core activities do not involve large-scale systematic monitoring or large-scale processing of special-category data. You can address any privacy question to the contact above and we will respond personally.

2. What data we collect

2.1 Letter photos and extracted content

When you scan a letter inside BlueLetter:

Important — Article 9 GDPR. Letters from Dutch government agencies (IND, UWV, Belastingdienst, DUO, CJIB, Gemeente, KvK) may contain special categories of data, including information about your immigration status, health (e.g. UWV illness allowances), or financial position. They also routinely carry your burgerservicenummer (BSN) — the Dutch citizen service number, a national identification number whose processing is separately restricted under Article 87 GDPR and Article 46 of the Dutch Uitvoeringswet AVG. When you scan such a letter, the BSN printed on it is sent to our backend and to the AI provider along with the rest of the page, and it may appear in the extracted text stored on your device and in our EU database.

By scanning a letter you give us your explicit consent to process this data for the limited purpose of translation, summarization, and deadline extraction. We do not use the BSN to identify you, index by it, or share it with anyone beyond the processors named in section 4. You can withdraw your consent at any time by deleting the letter, deleting your account, or uninstalling the app.

2.2 Onboarding answers

During onboarding we ask you for the following information, stored only on your device:

2.3 Account information

Creating an account is required to scan a letter. You can sign up in one of two ways:

Your account record (identifier, email, creation date) is stored in our EU database and is what links your synced letters to you. Deleting your account from inside the app erases that record along with your letters and deadlines.

2.4 Subscription information

If you purchase a subscription through the App Store, the purchase is processed entirely by Apple. We receive a confirmation that your subscription is active and at which tier; we do not receive your payment card details or any billing address. Apple's privacy policy governs that data: apple.com/legal/privacy.

2.5 Technical data

Our backend logs the minimum needed to operate: the timestamp of each scan request, the HTTP status code returned, and (in case of failure) a generic error message. We do not log your photos, IP address, or letter content in our backend logs. Our hosting provider (Vercel) records standard edge metadata.

2.6 The website and the waitlist form (tryblueletter.com)

This section covers the website only — none of it applies to the app.

We use your waitlist email address for one purpose: to tell you when BlueLetter is available. Every email we send includes a way to unsubscribe, and you can ask us to delete your address at any time by writing to privacy@tryblueletter.com.

3. Why we collect this data and the legal basis

DataPurposeLegal basis (GDPR)
Letter photos and extracted contentTo translate, summarize, and extract deadlines from your letters.Art. 6(1)(b) (contract performance) + Art. 9(2)(a) (explicit consent for special categories).
Onboarding answersTo personalize the in-app experience.Art. 6(1)(a) (consent).
Subscription informationTo grant access to paid features.Art. 6(1)(b) (contract).
Technical logsTo debug failures and operate the service.Art. 6(1)(f) (legitimate interest).
Waitlist email address (website)To notify you once when BlueLetter is available to download.Art. 6(1)(a) (consent, given by submitting the form).
Website request metadata (IP, user agent)To serve, route, and protect the website via our DNS/CDN provider.Art. 6(1)(f) (legitimate interest in a working, protected site).

4. Who we share data with

We share data only with the processors strictly necessary to deliver the service. Each is bound by a Data Processing Agreement (DPA) where required.

ProcessorPurposeCountry
Anthropic (Claude AI)Extracts text from your letter photos and produces the translation, summary, and deadlines.United States
VercelHosts the backend service that forwards requests to Anthropic.United States (with EU edge locations)
SupabaseAccount authentication and cloud storage/sync of your letters and deadlines across your devices. Your letter photos are never uploaded — they stay on your device.European Union (Frankfurt, Germany)
RevenueCatManages and verifies in-app subscription purchases and entitlements.United States
AppleDistributes the app, processes in-app purchases, and provides push notification and calendar APIs.Ireland / United States
ResendSends transactional account emails (sign-up confirmation, password reset).United States / European Union
SentryCrash and error diagnostics. Configured to exclude request bodies, screenshots, and personal identifiers.European Union (Frankfurt, Germany)
PostHogAnonymous product-usage analytics (e.g. "a scan completed"). Receives no personal identifiers, no account email, and no letter content.European Union
Google (Sheets + Apps Script)
website only
Stores waitlist sign-ups — email address and timestamp. Receives nothing from the app.United States
Cloudflare
website only
DNS, CDN, and bot protection for tryblueletter.com; routes mail sent to our support@ and privacy@ addresses; serves the GSAP animation library the site loads. Sees your IP address and request metadata when you visit the site.United States (global edge network)

We do not share data with advertising networks or data brokers, and we do not sell your data. Beyond the processors listed above, no third party receives your data. Our analytics (PostHog) and diagnostics (Sentry) are EU-hosted and receive only anonymous, non-identifying information — see section 11.

We do not sell your personal data. We do not allow our service providers to use your letter content to train AI models. Anthropic's commercial API terms (under which we operate) explicitly exclude API inputs and outputs from training data unless the customer opts in — we have not opted in.

5. International transfers

Your account data and letters are stored in the European Union (Supabase, Frankfurt). Our analytics (PostHog) and crash diagnostics (Sentry) are also EU-hosted. This data does not leave the EU.

Some processors are based in the United States: Anthropic and Vercel (which process your letter photos in transit during a scan), RevenueCat (subscription management), and Resend (account emails). When data is sent to them it leaves the European Union; these transfers are covered by the Standard Contractual Clauses (SCCs) adopted by the European Commission, included in each provider's standard Data Processing Agreement.

Two further US transfers concern the website only. If you join the waitlist, your email address and the submission timestamp are written to a Google Sheet and are therefore stored in the United States. And because tryblueletter.com is served through Cloudflare, your IP address and request metadata are processed on Cloudflare's global edge network, which includes locations outside the EU. Both providers rely on the Standard Contractual Clauses, and both are certified under the EU–US Data Privacy Framework. Neither receives any letter content, and neither is involved in scanning.

6. How long we keep data

DataWhereRetention
Letter photosYour device onlyUntil you delete the letter or uninstall the app. Never uploaded to our cloud.
Letter text, summary & deadlinesYour device + Supabase (EU)Until you delete the letter or your account.
Letter photos transitAnthropic / VercelAnthropic retains inputs for up to 30 days for trust & safety review, then deletes them. Vercel does not persist them at all.
Anonymous analytics & crash reportsPostHog / Sentry (EU)Per provider defaults; no personal identifiers attached.
Onboarding answersYour deviceUntil you reset onboarding or uninstall the app.
Subscription informationAppleGoverned by Apple.
Technical logsVercel~30 days, then automatically rotated out.
Waitlist email addressGoogle Sheets (US)Until you ask us to remove it, or until we close the waitlist after launch and delete the sheet.
Website request metadataCloudflarePer Cloudflare's own retention defaults; we do not query or store it ourselves.

7. Your rights under GDPR

You have the following rights regarding your personal data. To exercise any of them, contact us at privacy@tryblueletter.com — we will respond within 30 days.

8. AI-generated content; automated decision-making

BlueLetter uses Anthropic's Claude AI to translate and summarize your letters. AI translations can contain errors, missing nuance, or factual mistakes — especially for complex legal language. For decisions with significant financial or legal consequences, always verify against the original Dutch text and consult a qualified professional.

BlueLetter is a translation and summarization tool. It is not legal advice, tax advice, immigration advice, financial advice, or any other form of professional advice. See sections 6, 8, and 9 of our Terms of Service for the full scope of these limitations.

8.1 GDPR Article 22 — no qualifying automated decisions

BlueLetter does not make automated decisions about you that produce legal or similarly significant effects within the meaning of Article 22 GDPR. The AI generates a translation and summary; you remain the decision-maker for any subsequent action. We do not score, rank, or profile users based on AI output.

8.2 EU AI Act

BlueLetter operates under the EU AI Act (Regulation (EU) 2024/1689). The translation system used is a general-purpose AI model accessed through a commercial API. BlueLetter is not classified as a high-risk AI system under Annex III. We follow the transparency obligations applicable to AI-generated text: every translation and summary is clearly identified as AI-generated inside the app and in any exported document.

9. Security

We protect your data using:

In the unlikely event of a personal data breach affecting your rights and freedoms, we will notify the Dutch Data Protection Authority within 72 hours of becoming aware of it and, where required, notify you directly.

10. Children

BlueLetter is not directed at children under 17 years of age. We do not knowingly collect personal data from anyone under 17. If we learn that we have inadvertently collected personal data from a person under 17, we will delete that data without undue delay. Parents and guardians who believe their child has used BlueLetter without consent can contact privacy@tryblueletter.com.

11. Analytics, diagnostics, and tracking

BlueLetter is a native iOS app and uses no cookies, no web tracking, no advertising, and no cross-app tracking. We do not use Apple's advertising identifier (IDFA) and do not ask for tracking permission. The tryblueletter.com website likewise sets no cookies and runs no analytics or advertising scripts — see section 2.6 for what the website does receive.

We do use two privacy-preserving, EU-hosted services to keep the app working and improve it:

Both providers are hosted in the European Union, so this data does not leave the EU.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will note the new effective date at the top of this page, provide at least thirty (30) days' notice via in-app notice or push notification, and where the change broadens the categories of data processed or the purposes of processing, ask you to re-consent inside the app. Continued use after the effective date constitutes acceptance of the updated policy.

13. Contact

Questions, requests, or complaints: privacy@tryblueletter.com

If you are not satisfied with our response, you may file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
https://autoriteitpersoonsgegevens.nl/