RecLet Privacy Policy
Effective date: September 4, 2026
Last updated: September 4, 2026
Published at: https://www.reclet.now/privacy
Entity: Mautonce LLC
Mail Address: 980 N Michigan Ave, Ste 1090, PMB 108751, Chicago, IL 60611, United States
Contact Form: https://www.reclet.now/helpdesk
Email: privacy@reclet.now
Section 1: Introduction
Mautonce LLC is a limited liability company organized under the laws of the State of Illinois. We are the developer and publisher of the RecLet application.
This Privacy Policy explains what information Mautonce LLC ("Mautonce", "company," "we," "us," or "our") collects, how we use it, and the choices you ("User" or "you") have in connection with the RecLet application (the "app"). This Privacy Policy applies to all users of RecLet.
By downloading, installing, using, and/or tapping "Agree & Continue" as required by the app's first-launch screen, you ("User" or "you") acknowledge that you have read and agree to be legally bound by this Privacy Policy ("Policy").
If you do not agree to this Privacy Policy, uninstall and discontinue use of the app.
If you are using the app on behalf of an organization, you represent and warrant that you have the authority to bind that organization to this Policy and that the organization agrees to be bound by it.
For privacy-related inquiries, Users may contact us at the help contact form above or via the email address above. Mautonce will make commercially reasonable efforts to respond within thirty (30) days of receipt.
This Privacy Policy should be read together with our Terms of Use, available at: https://www.reclet.now/terms
Section 2: What RecLet Does and Doesn't
RecLet is designed around a single principle: your creative work is yours, and it stays with you. We built the app so that the company technically cannot access your content, not as a policy choice we could reverse, but as an architectural reality.
2.1 What RecLet Does
Store your creative work on your device (or your own cloud)
Use anonymous crash reports to fix bugs (via Sentry)
Use anonymous, opt-in product analytics — off unless you turn them on — to see which features are used (via PostHog)
Let you use the app without any account or sign-in
Process payments entirely through Apple or Google, and validate purchases through a receipt-management service (via RevenueCat) that never sees your payment details
Request microphone access only when you use audio recording
Request photo library access only when you add a background image
Never sell, rent, or trade your data
2.2 What RecLet Doesn't
Store your content on our servers
Read, analyze, or train AI on your content
Handle or store your payment information directly
Access your microphone in the background
Access your photo library without your action
Access your device's camera without your action
Section 3: Information RecLet Collects and Doesn't
This section describes every category of data that flows to or through the app. We have organized it as explicitly as possible so you can make an informed decision.
3.1 Information RecLet Does NOT Collect
The Company does not collect, receive, access, transmit to its servers, or store any of the following:
- The content of your creative work: including text, titles, file names, chapter names, script pages, podcast notes, audiobook narrations, audio recordings, or any document you create or edit within the app
- Your precise or approximate location: the app does not request location permissions of any kind
- Your contacts, calendar entries, reminders, or tasks
- Health or fitness data
- Biometric identifiers: including fingerprints, face geometry, voiceprints, iris scans, or any other biometric data as defined under the Illinois Biometric Information Privacy Act, 740 ILCS 14/ ("BIPA"), or comparable law. The app does not collect, process, or store biometric information. Microphone access is used solely to capture audio recordings that remain on your device; the app does not perform voice recognition, speaker identification, or any biometric analysis on audio captured through the microphone.
- Browsing history, search queries, or activity across other apps or websites
- Payment card numbers, bank account information, or financial data: all purchases are processed exclusively by Apple (App Store) or Google (Play Store); we never see or touch payment information
- Any data from your camera: the app does not access your device's camera without your action and photos stay on your device unless you choose to share them.
3.2 Information RecLet Does Collect: Anonymous Diagnostic and Analytics Data
The information the Company collects is limited to anonymous, non-content data in the three categories below. None of it includes your creative work, and none of it identifies you personally: (a) anonymous crash and error reports (Sentry); (b) anonymous, opt-in product-analytics events (PostHog); and (c) anonymous purchase-validation data if you buy a subscription (RevenueCat). Each is described below.
3.2(a) Crash and Error Reports (Sentry)
Anonymous crash and error reports are sent to us when the app experiences a software failure. This data is collected for one purpose only: to diagnose and fix bugs so the app works reliably for you.
What these reports contain:
- A randomly generated, per-installation identifier (not your device's hardware ID, not an advertising ID, and not linked to any personal identifier) used solely to count how many users are affected by a given crash
- The type and version of your operating system (e.g., iOS 18.2 or Android 15)
- The app version number at the time of the crash
- Device model category (e.g., "iPhone 15 Pro" or "Pixel 8"), without any hardware serial number
- A technical stack trace describing where in the app's code the error occurred
- The timestamp of the crash event
- Whether the app was in the foreground or background at the time of the crash
What these reports do NOT contain:
- Any content you have created, typed, or recorded in the app
- Any file names, document titles, or folder names
- Your name, email address, or any personal identifier
- Your location
- Any audio captured through the microphone feature
Service Provider — Sentry: We use Sentry (Functional Software, Inc., d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105) to process these crash reports on our behalf. Sentry acts as a data processor under our instruction. Sentry does not use crash data submitted through our app to build advertising profiles, and by default, Sentry's mobile SDKs do not use hardware device identifiers or advertising identifiers. For more information about Sentry's data practices, see Sentry's Privacy Policy at sentry.io/privacy and Sentry's mobile data privacy documentation at docs.sentry.io/security-legal-pii/security/mobile-privacy/.
3.2(b) Product Analytics (PostHog)
To understand which features are used and improve the app, the Company may collect anonymous product-analytics events — but only if you turn them on. Analytics are off by default. You can enable them during first-run setup or at any time in Settings → Privacy → "Share anonymous usage data," and turn them back off the same way. While off, no analytics events are sent at all.
What these events contain:
- A randomly generated, per-installation identifier (a UUID generated on your device; not your device's hardware ID, not an advertising ID, and not linked to any personal identifier)
- The name of a product-interaction event (for example, a challenge accepted or the letter-lock feature enabled) and non-content metadata about it (such as a word count)
- Standard technical context automatically attached by the analytics SDK (such as app version and operating-system version)
What these events do NOT contain:
- Any content you have created, typed, or recorded in the app
- Any file names, document titles, or folder names
- Your name, email address, or any personal identifier
- Your location
- Any audio captured through the microphone feature
The app's analytics are configured to not capture page views, not perform automatic DOM/interaction "autocapture," and not record sessions. Analytics run only in production builds; they are disabled in development.
Service Provider — PostHog: We use PostHog (PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114) to process these analytics events on our behalf, hosted on PostHog's U.S. Cloud (us.i.posthog.com). PostHog acts as a data processor under our instruction and does not use this data for its own advertising or profiling. For more information, see PostHog's Privacy Policy at posthog.com/privacy.
3.2(c) Purchase Validation (RevenueCat)
If you purchase an optional subscription (see Section 7.3), the Company uses RevenueCat to validate the purchase receipt issued by Apple or Google and to determine which features your subscription entitles you to. RevenueCat never receives your payment card number, bank details, or billing address — those are handled exclusively by Apple or Google. The data RevenueCat processes on our behalf is limited to:
- The App Store receipt / subscription transaction and its status (for example, active, in trial, expired)
- The product identifier purchased and the entitlement it grants
- A randomly generated, anonymous app-user identifier used to associate a purchase with an installation (not your name or email)
If you never make a purchase, no data is sent to RevenueCat. Service Provider — RevenueCat (RevenueCat, Inc., San Francisco, CA) acts as a data processor under our instruction. For more information, see RevenueCat's Privacy Policy at revenuecat.com/privacy.
3.3 Information You Voluntarily Provide — Optional Newsletter Sign-Up
You do not need an account, and you do not need to give us your email, to use any part of RecLet. The app has no login, no password, and no user registration; you remain anonymous to the Company during all use of the app.
Separately, RecLet may offer an optional way to subscribe to the RecLet Newsletter (our newsletter) and other occasional product updates from the Company. This is a marketing-email subscription, not an account, and it gates no app features. If — and only if — you choose to subscribe:
(a) Email address. We collect the email address you provide, used solely to send you the RecLet Newsletter and related product news. Providing it is entirely optional, and we do not use it to identify you within the app.
(b) Subscription status and date. We keep a record that you subscribed and your current subscribe/unsubscribe status, so we can send the newsletter and honor an unsubscribe.
We do not collect a password (there is no login), your name, phone number, physical address, location, any content you create, or any payment information as part of the newsletter sign-up.
3.4 Communications Preferences
If you subscribe to the RecLet Newsletter, you will receive marketing emails from the Company at the address you provide. You may opt out at any time by:
(a) Clicking the unsubscribe link in any RecLet Newsletter email; or
(b) Contacting us using the information at the start of this Privacy Policy and asking to be removed.
Because the newsletter is optional and unrelated to app functionality, unsubscribing simply stops the emails; it does not affect your use of the app. The Company does not send transactional or "account" emails, because there are no accounts — see Section 15 for how notices of material changes to this Policy are delivered.
3.5 Information You Voluntarily Provide Through Contact Channels
If you contact the company through a web-based inquiry form, postal mail, or email, we will use the information you provide solely to respond to your inquiry. We do not retain contact inquiry data for any secondary purpose beyond legal record-keeping.
Section 4: Device Permissions
Some features of the app require access to hardware capabilities of your device. In every case, the data captured stays on your device (or in your chosen third-party cloud storage account). None of it is transmitted to the Company.
4.1 Microphone
- When accessed: Only when you actively initiate an Audio Recording feature within the app. The microphone is never accessed in the background.
- What happens to the audio: The audio file is saved locally on your device (or synced to your own connected cloud storage account) exactly like any other file you create. It is not transmitted to, processed by, or accessible to the company.
- Biometric note: The app performs no voice analysis, speaker identification, voiceprint generation, or any processing of audio that would constitute collection of biometric data under BIPA or any comparable statute.
- How to revoke: You may revoke microphone access at any time in your device's system Settings → Privacy & Security → Microphone. Revoking permission does not affect recordings you have already made; it only prevents the audio recording feature from requesting new access until you re-enable it.
4.2 Photo Library
- When accessed: Only when you choose to add a photo background to your writing environment. The app accesses the specific image you select; it does not scan or index your broader photo library.
- What happens to the image: The selected image is saved locally on your device as part of your app settings or letter content, exactly like any other content. It is not transmitted to the Company.
- How to revoke: You may revoke photo library access at any time in your device's system Settings → Privacy & Security → Photos. Revoking permission only prevents future background image selection; it does not remove backgrounds already set.
4.3 Camera
The app does not access your device's camera without your action.
Camera-based features are opt-in, will request camera permission only at the moment you choose to use it. Any resulting image are handled exactly as described for other on-device content: saved locally on your device, never transmitted to the Company.
4.4 Other Permissions
The app does not request access to your contacts, calendar, reminders, health data, location services, Bluetooth, local network, or any other device capability not described above.
Section 5: Device and Cloud Storage
5.1 On-Device Storage
By default, all content you create in the app, letters, scripts, drafts, audio recordings, and notes, is stored locally on your device's internal storage. The company has no access to this content.
5.2 Optional Third-Party Cloud Sync
If you choose to enable sync or backup with a third-party cloud storage service, such as iCloud (Apple Inc.), Dropbox (Dropbox, Inc.), OneDrive (Microsoft Corporation), or Google Drive (Google LLC), your content will be transmitted to and stored with that service, subject to that service's terms of service and privacy policy. Mautonce is not a party to your relationship with any third-party cloud storage provider and does not receive, access, or process your content through those services.
You are responsible for reviewing the privacy practices of any third-party cloud service you choose to use. Mautonce makes no representations about, and is not responsible for, the data practices of Apple iCloud, Dropbox, OneDrive, Google Drive, or any other third-party cloud storage service.
5.3 No Company Server Storage
The Company does not operate cloud servers for storing user content and has no mechanism to receive, access, back up, or restore your content. This is an architectural design decision, not merely a policy. As a result:
- If you delete the app or lose your device without an independent backup, your content may be permanently lost. The company cannot recover it.
- If you experience data corruption or accidental deletion, the company cannot restore your content.
- Any request for the company to produce, disclose, or preserve your content in response to legal process will be technically impossible to fulfill, as the Company does not possess it.
Section 6: How Information Is Used
Mautonce uses the information described in Section 3 for the following purposes only:
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Anonymous crash reports | Bug diagnosis, app stability monitoring, security incident detection | Legitimate interest |
| Anonymous product-analytics events (opt-in) | Understanding which features are used to improve and prioritize the app | Consent — off by default; enable in first-run setup or Settings → Privacy |
| Purchase-validation data (RevenueCat) | Validating subscription receipts and granting the correct entitlements | Performance of contract |
| Email address (RecLet Newsletter subscribers) | Sending the RecLet Newsletter and related product news | Consent (affirmative opt-in at sign-up); you may unsubscribe at any time |
| Voluntary inquiry content | Responding to user support and privacy requests | Legitimate interest / legal obligation |
The Company does not use any data, including RecLet Newsletter subscribers' email addresses, for:
- Sale, rental, lease, trade, or transfer to any third party for any purpose
- Advertising targeting, behavioral profiling, or user segmentation for commercial purposes beyond the Company's own marketing
- Training, fine-tuning, or improving any artificial intelligence or machine learning model
- Any purpose not listed in the table above
6.1 Marketing Communications
Marketing and promotional communications (including the RecLet Newsletter) are sent only to users who have affirmatively subscribed and have not since unsubscribed. Sign-up uses a clear, affirmative opt-in that is unchecked by default. Marketing communications are never sent without affirmative opt-in consent, and the app is fully usable without providing an email.
Section 7: How We Share Information
7.1 We Do Not Sell Your Data
The Company does not sell, rent, lease, trade, or otherwise transfer your personal information to third parties for monetary or other valuable consideration. This applies under the California Consumer Privacy Act (CCPA/CPRA), as amended, and under any other applicable state privacy law that defines "sale" or "sharing" of personal data.
Because the Company does not sell or share your personal information and does not engage in cross-site tracking or targeted advertising, there is nothing to opt out of through a Global Privacy Control (GPC) or Do Not Track (DNT) browser signal. The app and website do not track you across other websites or services.
7.2 Service Providers
The Company relies on a small number of service providers ("data processors"), each of which processes only the limited, anonymous data described in Section 3.2 and only on the Company's behalf:
- Sentry — anonymous crash and error reports (Section 3.2(a));
- PostHog — anonymous, opt-in product-analytics events (Section 3.2(b)); and
- RevenueCat — anonymous subscription-receipt validation, only if you make a purchase (Section 3.2(c)).
None of these providers receives your content, and none receives your payment card or billing details. Each is contractually bound to process this data only on our behalf and only for the purposes we specify.
All service providers are contractually bound to:
(a) Process data only on the company's behalf and only for the purposes specified;
(b) Implement appropriate technical and organizational security measures;
(c) Not use data provided by the company for their own commercial or marketing purposes; and
(d) Delete or return data upon termination of the service relationship.
7.3 Platform Providers
The app is distributed through the Apple App Store and Google Play Store, and is also available as a web application. On the Apple App Store and Google Play, these platform providers may collect data about your device and app usage independently through their own systems and in accordance with their own privacy policies. Their data collection is governed by their own policies, not ours. The Company does not control and is not responsible for data collected by Apple or Google through the operation of their respective platforms.
Purchases, subscriptions, and in-app transactions are processed exclusively by Apple or Google. The Company does not receive, access, or retain payment card numbers, bank account information, or billing details. The Company uses RevenueCat (Section 3.2(c)) only to validate the purchase receipt Apple or Google issues and to determine your subscription entitlement; RevenueCat likewise never receives your payment card or billing details.
7.4 Legal Requirements and Safety
The Company may disclose information in its possession — which, as noted throughout, is limited to the anonymous diagnostic, product-analytics, and purchase-validation data described in Section 3.2 — if it reasonably believes disclosure is necessary to:
(a) Comply with a valid legal obligation, court order, subpoena, or governmental request;
(b) Enforce the Terms of Use, including investigation of potential violations;
(c) Detect, prevent, or address fraud, security vulnerabilities, or technical failures; or
(d) Protect the rights, property, or safety of the Company, its users, or the public, as required or permitted by law.
Apart from an email address you may have voluntarily provided to subscribe to the RecLet Newsletter (Section 3.3), the Company does not possess user content, contact information, or personal identifiers, so any response to legal process will be limited to that narrow set of data.
7.5 Business Transfers
In the event of a merger, acquisition, sale of substantially all assets, bankruptcy, reorganization, or other corporate transaction, information in the Company's possession — limited to the anonymous diagnostic data described in this Policy — may be transferred to a successor entity. In such event, the Company will use commercially reasonable efforts to notify users through an in-app notification prior to any such transfer, and the successor entity will be required to honor the commitments made in this Privacy Policy.
Section 8: Data Retention
8.1 Diagnostic, Analytics, and Purchase-Validation Data
Anonymous crash and error reports submitted to Sentry are retained only for the limited period configured in the Company's Sentry project, after which they are automatically deleted from Sentry's systems.
Product-analytics data (PostHog) is retained only for the limited period configured in the Company's PostHog project, after which events are deleted or aged out per those settings. If you turn analytics off in Settings → Privacy, no further events are collected; previously collected anonymous events remain subject to this retention window.
Purchase-validation data (RevenueCat) is retained for as long as the associated subscription entitlement is active and thereafter only for the period required for tax, accounting, and dispute-resolution purposes.
8.2 Your Content
Your content is stored on your device or in your chosen third-party cloud storage. The Company retains no copy and therefore has no retention period to disclose with respect to your content. Your content is under your sole control. You may delete it at any time from your device or cloud storage.
8.3 RecLet Newsletter Subscribers
If you subscribe to the RecLet Newsletter, the Company retains your email address and subscription status for as long as you remain subscribed. When you unsubscribe:
(a) Your email address is removed from the active mailing list and deleted from the Company's and its email provider's systems within thirty (30) days, except that
(b) the Company may keep your email address on a minimal suppression list solely to ensure you are not re-added to the newsletter, as described in Section 8.4; and
(c) Anonymous crash, analytics, and purchase-validation data are not linked to your subscription and are unaffected by unsubscribing; they are retained per Section 8.1.
How to unsubscribe: use the unsubscribe link in any RecLet Newsletter email, or contact the Company using the information in Section 16. There is no account to delete, because the newsletter is not an account.
8.4 Marketing Unsubscribe Records
If you unsubscribe from the RecLet Newsletter, the Company retains a minimal suppression record — your email address and opt-out status only — solely to ensure you are not re-added to the mailing list. You may ask the Company to delete this suppression record entirely by contacting it using the information in Section 16.
Section 9: Age Policy
RecLet is not directed to children under the age of thirteen (13). The Company does not knowingly collect personal information from children under 13. If you are under 13, you may not subscribe to the RecLet Newsletter or otherwise provide your email address to the Company.
For users who do not subscribe to the newsletter, the app's no-identifier architecture provides a practical layer of COPPA protection: no personal information is collected from anonymous users of any age.
For users who subscribe to the optional RecLet Newsletter, the Company relies on the sign-up to establish that the subscriber is 13 or older. The Company does not implement a technical age-verification mechanism. If you are a parent or guardian and believe your child under 13 has subscribed, please contact us immediately using the information in Section 16. The Company will promptly delete any subscription and email address it confirms belongs to a child under 13.
If the app is used in jurisdictions where a higher minimum age applies, including under applicable state law (e.g., laws requiring parental consent for users under 16), the Company does not knowingly collect personal information from users below the applicable age threshold for that jurisdiction.
If you are a parent or guardian and believe your child has provided personal information to the Company, please contact us using the information in Section 16.
Section 10: Your Privacy Rights
10.1 Applicable State Privacy Rights
Depending on where you live, you may have specific rights under applicable privacy law. The following chart summarizes the laws that may apply to you:
| State / Jurisdiction | Applicable Law | Key Rights |
|---|---|---|
| California | CCPA / CPRA (Cal. Civ. Code § 1798.100 et seq.) | Know, access, delete, correct, opt out of sale/sharing, limit use of sensitive data, non-discrimination |
| Virginia | VCDPA (Va. Code Ann. § 59.1-575 et seq.) | Access, correct, delete, portability, opt out of sale/targeted advertising/profiling |
| Colorado | CPA (Colo. Rev. Stat. § 6-1-1301 et seq.) | Access, correct, delete, portability, opt out of sale/targeted advertising/profiling |
| Connecticut | CTDPA (Conn. Gen. Stat. § 42-515 et seq.) | Access, correct, delete, portability, opt out of sale/targeted advertising/profiling |
| Texas | TDPSA (Tex. Bus. & Com. Code § 541.001 et seq.) | Access, correct, delete, portability, opt out of sale/targeted advertising/profiling |
| Illinois | BIPA (740 ILCS 14/), ICFA (815 ILCS 505/) | Biometric data rights; consumer fraud protections |
| All U.S. Users | FTC Act, Section 5 | Protection against unfair or deceptive acts or practices |
| EEA / UK Users | GDPR / UK GDPR | Lawful basis for processing, access, rectification, erasure, portability, objection, restriction |
10.2 How These Rights apply to RecLet — A Practical Note
Many of the rights listed above — such as the right to access, correct, delete, or receive a copy of your personal data — are practically fulfilled by the app's architecture itself:
- Because the Company does not collect, store, or possess your content or personal identifiers, there is no personal data held by the Company to access, correct, or delete on your behalf.
- Because the app does not sell or share your personal data for advertising or behavioral profiling, there is nothing to opt out of in that respect.
- Because the app does not create user profiles, there is no profiling to restrict or object to.
The only personal data the Company holds that could theoretically be subject to these rights is the anonymous crash report, product-analytics, and purchase-validation data described in Section 3.2, plus any email address you voluntarily provided to subscribe to the RecLet Newsletter (Section 3.3), which you can have removed at any time by unsubscribing or contacting us. However, because this data is associated only with a randomly generated per-installation identifier — and not with your name, device hardware ID, email, or any other identifier the Company possesses — the Company may be technically unable to locate, attribute, or delete a specific individual's records upon request, as it has no way to link them to a specific person without additional identifying information you would need to supply. You can, at any time, stop future product-analytics collection yourself in Settings → Privacy → "Share anonymous usage data."
10.3 How to Exercise Your Rights
To submit a privacy rights request, contact the Company using the information in Section 16. Please describe your request as specifically as possible. Because of the architecture described above, the Company will respond honestly about what data it holds (and does not hold) and what actions are technically feasible.
The Company will respond to verifiable privacy rights requests within the timeframe required by applicable law, and in no event later than forty-five (45) days of receipt, with a possible extension of an additional forty-five (45) days where reasonably necessary, consistent with CCPA and comparable state law requirements.
10.4 Non-Discrimination
The company will not discriminate against you for exercising any privacy right. We will not deny you access to the app, charge you a different price, or provide a degraded experience as a result of a privacy rights request.
10.5 Illinois Biometric Information Privacy Act (BIPA)
The Company specifically represents and warrants, for purposes of BIPA compliance, that:
(a) The Company does not collect, capture, purchase, receive through trade, or otherwise obtain biometric identifiers or biometric information from any user;
(b) The app's microphone permission is used solely to capture audio recordings that are stored on the user's device. The Company does not extract, derive, or process voiceprints, speaker recognition data, or any other biometric information from audio captured through the microphone;
(c) The Company does not possess a written policy establishing a retention schedule or guidelines for the destruction of biometric data because the Company does not collect biometric data. If the Company's practices ever change in a manner that implicates BIPA, the Company will establish and publish such a policy prior to any such collection;
(d) The Company has not and will not sell, lease, trade, or profit from any biometric identifier or biometric information; and
(e) The Company has not and will not disclose or redisclose any biometric identifier or biometric information without satisfying the requirements of 740 ILCS 14/15(d).
Section 11: European, UK, and International Users
11.1 Applicability
This Section applies to users located in the European Economic Area (EEA), the United Kingdom (UK), and other jurisdictions whose privacy laws impose specific requirements on the processing of personal data of their residents.
11.2 Data Controller
For users in the EEA and UK, Mautonce LLC is the data controller with respect to any personal data processed in connection with the app. Contact details are provided in Section 16.
11.3 Legal Bases for Processing
The Company processes the limited anonymous diagnostic data described in Section 3.2 on the following legal bases under the GDPR and UK GDPR:
| Processing Activity | Legal Basis | Article / Provision |
|---|---|---|
| Anonymous crash and error reporting | Legitimate interests (Art. 6(1)(f)) — specifically, the Company's interest in maintaining a stable, secure, and functioning application; this interest is not overridden by user interests given the anonymous, non-content-bearing nature of the data | GDPR Art. 6(1)(f) |
| Anonymous product analytics | Consent (Art. 6(1)(a)) — off by default; processed only after the user affirmatively opts in, and withdrawable at any time in Settings → Privacy | GDPR Art. 6(1)(a) |
| Purchase-receipt validation (RevenueCat) | Performance of a contract (Art. 6(1)(b)) | GDPR Art. 6(1)(b) |
| Responding to voluntary privacy inquiries | Legitimate interests or performance of a contract (Art. 6(1)(b)) | GDPR Art. 6(1)(b) / 6(1)(f) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) | GDPR Art. 6(1)(c) |
The Company does not process special categories of personal data as defined in GDPR Article 9 (including biometric data used for identification purposes) and does not engage in automated decision-making or profiling with legal or similarly significant effects.
11.4 International Data Transfers
The anonymous data described in Section 3.2 may be processed on servers located in the United States: crash reports by Sentry, product analytics by PostHog (U.S. Cloud), and, for purchasers, subscription-receipt data by RevenueCat. Each is a U.S.-based service provider that participates in applicable cross-border data transfer frameworks and/or executes Standard Contractual Clauses (SCCs) with its customers to lawfully transfer personal data from the EEA or UK to the United States. You may review each provider's international transfer mechanisms in its respective privacy policy (sentry.io/privacy, posthog.com/privacy, revenuecat.com/privacy).
11.5 EEA and UK Privacy Rights
In addition to the rights described in Section 10, EEA and UK users have the following rights under the GDPR and UK GDPR:
- Right of access (Art. 15): Request a copy of any personal data the Company holds about you
- Right to rectification (Art. 16): Request correction of inaccurate personal data
- Right to erasure ("right to be forgotten") (Art. 17): Request deletion of personal data
- Right to restriction of processing (Art. 18): Request that processing be limited in certain circumstances
- Right to data portability (Art. 20): Receive your data in a portable, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to lodge a complaint with your national data protection supervisory authority
As noted in Section 10.2, given the app's architecture, the Company holds only the anonymous crash-report, product-analytics, and purchase-validation data described in Section 3.2, which cannot practicably be linked to you without additional identifying information. The Company will respond honestly and transparently to all GDPR rights requests.
11.6 Data Protection Officer
The Company is not currently required under GDPR Article 37 to appoint a Data Protection Officer, given the nature and scale of its processing activities. If this status changes, the Company will update this Policy accordingly.
Section 12: Security
12.1 Company-Level Security
The Company implements industry-standard technical and organizational measures to protect the limited data it holds — specifically, the anonymous crash report, product-analytics, and purchase-validation data described in Section 3.2 — against unauthorized access, alteration, disclosure, or destruction. These measures include access controls, encryption in transit (TLS), and reliance on the security infrastructure of our processors (Sentry, PostHog, and RevenueCat), which maintain SOC 2 or comparable compliance.
12.2 On-Device and Cloud Security
The security of your content stored on your device or in your chosen third-party cloud storage service depends on:
(a) The security measures implemented by your device's operating system (iOS or Android) and hardware;
(b) The security practices of any third-party cloud storage provider you choose to use; and
(c) Your own security practices, including your device passcode, biometric authentication, and cloud account credentials.
The Company has no ability to protect content it does not possess. We strongly encourage you to use a strong device passcode, enable device encryption (which is on by default for modern iOS and Android devices), and use strong, unique passwords for any cloud storage service you connect to the app.
12.3 No Absolute Security Guarantee
No method of data transmission or storage is completely secure. While the Company takes the security of the data it holds seriously, the Company cannot guarantee absolute security of anonymous diagnostic data transmitted to Sentry. In the event of a security incident affecting data held by the Company, the Company will notify affected users and applicable regulators as required by applicable law.
Section 13: RecLet's AI Policy. Honest by Design.
Given the increasing prevalence of AI in software development and the legitimate concerns users have about AI processing of their creative work, the Company is committed to full transparency about its use of AI technology.
RecLet does not use artificial intelligence to read, analyze, summarize, generate, classify, or train on your content. This is not a marketing statement. It is a technical description of how the app is built. Because the Company's servers never receive your content, there is no technical pathway through which the Company's AI tools could access it.
AI tools are used in the development of the app's software. Like most modern software development teams, the Company may use AI-assisted coding tools in the process of writing, testing, reviewing, and maintaining the app's source code. These tools see the app's code. They never see your content, because your content never reaches the Company.
There is a meaningful and intentional distinction between:
- Using AI to build the software, which the Company does; and
- Using AI to read or process what you wrote, which the Company does not do and has architected the app to make technically impossible.
This distinction is the foundation of the app's privacy design and is preserved as a core commitment of the Company.
Section 14: Third-Party Links and Services
The app may display or reference links to third-party websites or services — for example, links to this Privacy Policy hosted on an external webpage, or links to App Store review pages. The Company is not responsible for the privacy practices of any third-party website or service. If you click a link to a third-party site, you leave the app's environment and the third party's privacy policy governs your interaction with that site.
The optional third-party cloud storage services described in Section 5.2 (iCloud, Dropbox, OneDrive, Google Drive) are third-party services governed by their own privacy policies. Your use of those services is subject to those policies, not this one.
Section 15: Changes to This Privacy Policy
15.1 Company's Right to Modify
The Company reserves the right to update or modify this Privacy Policy at any time to reflect changes in the app's functionality, applicable law, or the Company's data practices.
15.2 Notice of Material Changes
For material changes — meaning any change that meaningfully affects how data about you is collected, used, or shared — the Company will provide at least thirty (30) days' advance notice through an in-app notification displayed prominently within the app, consistent with the notice mechanism described in the Terms of Use. Because most users use the app without providing any email address, in-app notification is the primary method for delivering notice of material changes to this Policy (RecLet Newsletter subscribers may additionally be notified by email).
15.3 Effect of Continued Use
Your continued use of the app after the effective date of any updated Privacy Policy constitutes your acceptance of the updated Policy. If you do not agree with any material change, your sole remedy is to stop using the app and delete it from your device.
15.4 Effective Date and Version History
The effective date of the current Privacy Policy appears at the top of this document. The Company may, but is not obligated to, maintain a publicly accessible archive of prior versions of this Privacy Policy at www.reclet.now/privacy.
Section 16: Contact Us
For privacy-related questions, rights requests, or concerns about this Privacy Policy, please contact:
Mautonce LLC
Attn: Privacy
980 N Michigan Ave, Ste 1090,
PMB 108751, Chicago, IL 60611
United States
Email: privacy@reclet.now
Web-based privacy inquiry form: https://www.reclet.now/helpdesk
The Company will make commercially reasonable efforts to respond to all privacy inquiries within thirty (30) days of receipt.