Privacy Policy
Last updated: March 16, 2026
Introduction
LetterShot ("we," "us," or "our") operates the website getlettershot.com. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. We are committed to minimizing data collection and retaining information only as long as strictly necessary to provide our service.
Data We Collect
Resume and Job Description Text
When you use LetterShot, you paste or upload your resume text and the target job description. This text is sent to our server solely to generate your cover letter via the OpenAI API. We do not permanently store your resume or job description text. It is held in memory only during the generation process and discarded immediately afterward.
Email Address
When you make a purchase, your email address is collected by our payment processor (Lemon Squeezy) as part of the transaction. We use your email for the following purposes:
- Payment receipt: A one-time email confirming your purchase.
- Bundle credit management: If you purchase a multi-letter bundle, your email is stored in our database to associate your credits with your identity so you can access them across sessions and devices.
- Feedback follow-up: A single follow-up email sent 3 days after purchase asking about your experience. You can ignore this email; no further emails will be sent.
Your email is never added to any marketing list, newsletter, or shared with third parties for advertising purposes.
Usage and Analytics Data
We collect anonymized usage data to improve the Service. This includes:
- Funnel events: Which steps you complete in the generation flow (e.g., resume uploaded, letter generated, download initiated). These events do not contain the content of your resume or cover letter.
- Feature usage: Interactions such as switching letter versions, checking ATS scores, using the ATS checker tool, or copying preview text. These are logged as anonymous event counts tied to a session ID, not to your identity.
- Aggregated performance data: Page load times, API response times, and error rates collected via Plausible Analytics and Vercel Analytics. No personally identifiable information is included.
This data is used solely to identify bugs, improve the user experience, and measure conversion rates. It is never sold, shared with third parties, or used for advertising purposes.
Feedback Responses
If you submit feedback via our 1-click feedback system (accessed through a link in the follow-up email), we store your rating (positive or negative) and any optional testimonial or improvement suggestion you provide. Feedback responses are associated with your session ID and stored for up to 90 days. If you provide a testimonial and consent to its use, we may display it on our website. We will never publish feedback alongside your name or email without your explicit permission.
Generated PDF Files
Your cover letter text is temporarily stored on our servers for up to 24 hours to enable download after payment. After this period, it is automatically deleted. PDF files are generated on-demand when you download and streamed directly to your browser. We do not permanently store your cover letter content.
Payment Information
Payments are processed through Lemon Squeezy. We never see or store your full credit card number. We retain order records (order ID, amount, bundle type, and associated email) permanently for accounting, refund processing, and credit management. No sensitive financial data (card numbers, CVV, etc.) is ever stored on our servers.
How We Use Your Data
- Cover letter generation: Your resume and job description text are sent to the OpenAI API to produce your cover letter. This is the sole purpose for which we process this data.
- Payment processing: Transaction metadata is used to confirm your purchase and enable refunds if needed.
- Receipt delivery: We use your email to send a one-time payment receipt.
- Credit management: For bundle purchases, your email is stored to associate credits with your identity, so you can access remaining credits across sessions and devices.
- Feedback collection: A single follow-up email is sent 3 days after purchase to ask about your experience. No further emails are sent.
Third-Party Services
OpenAI API
Your resume and job description data is transmitted to OpenAI, a third-party AI service, for the purpose of generating your cover letter. This data is processed in real-time and is not permanently stored by LetterShot after generation is complete.
OpenAI processes this data under their API terms of service. Data submitted via the API is not used to train OpenAI models.
OpenAI may retain API inputs for up to 30 days for abuse monitoring purposes, after which it is deleted. You can learn more about OpenAI's data handling at their privacy policy.
Lemon Squeezy
Payment processing is handled by Lemon Squeezy. Their privacy policy governs how they handle payment data. We recommend reviewing their privacy policy for details.
Plausible Analytics
We use Plausible Analytics for website usage statistics. Plausible is a privacy-focused analytics tool that does not use cookies, does not collect personal data, and does not track individual visitors. All data is aggregated and anonymous.
Vercel Analytics
We use Vercel Analytics for performance monitoring. Vercel Analytics collects anonymized, aggregated page view data (page path, browser type, country) to help us improve site speed. It does not use cookies or collect personally identifiable information.
Cookies
LetterShot does not use cookies. We do not set any first-party or third-party cookies. Our analytics provider, Plausible, is entirely cookieless. No cookie consent banner is needed because no cookies exist.
Data Retention
- Resume and job description text: Not stored. Processed in memory and discarded immediately after generation.
- Generated PDF files: Not stored on our servers. Generated on-demand and streamed directly to your browser.
- Order records: Order ID, amount, bundle type, and email are retained permanently for accounting and credit management. Download tokens are deleted within 24 hours.
- Email address: Retained as long as you have active bundle credits or outstanding orders. You may request deletion at any time by contacting us.
- Bundle credits and transaction history: Retained permanently to ensure you can always access purchased credits.
- Usage analytics: Anonymized event data (funnel steps, feature usage) is retained indefinitely in aggregated form. No personally identifiable information is included.
- Feedback responses: Stored for up to 90 days, then automatically deleted. Testimonials you explicitly consent to share may be retained longer for display on our website.
- OpenAI (third-party processor): May retain API inputs for up to 30 days for abuse monitoring purposes, after which they are permanently deleted by OpenAI.
GDPR and Your Rights
If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR).
Legal Basis for Processing
We process your personal data based on your explicit consent when you submit your resume and job description for cover letter generation. By submitting this information, you consent to it being transmitted to OpenAI for the sole purpose of generating your cover letter. You may withdraw this consent at any time by not using the service; data already submitted cannot be recalled once generation has begun.
Your Rights
Under GDPR (and applicable laws in other jurisdictions), you have the following rights with respect to your personal data:
- Right of access: You may request a copy of any personal data we hold about you.
- Right to erasure: You may request deletion of any personal data we hold about you ("right to be forgotten").
- Right to data portability: You may request that we provide your personal data in a structured, machine-readable format.
- Right to rectification: You may request correction of inaccurate personal data we hold about you.
- Right to object: You may object to our processing of your personal data in certain circumstances.
Because we retain minimal data and auto-delete most records within 24 hours, there is typically no personal data to retrieve by the time a request is made. However, to exercise any of the above rights, please contact us by email at support@getlettershot.com. We process all data subject requests manually and will respond within 30 days.
Children's Privacy
LetterShot is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. Your continued use of LetterShot after changes are posted constitutes acceptance of the revised policy.
Contact Us
If you have questions about this Privacy Policy, contact us at support@getlettershot.com.