1. Who we are
BeMyLetter is operated by Blue Insight Digital Private Limited, a company incorporated in India ("we", "us", or "our"). For the purposes of applicable data protection law — including the EU and UK General Data Protection Regulation ("GDPR") and India's Digital Personal Data Protection Act, 2023 ("DPDP Act") — Blue Insight Digital Private Limited is the data controller of personal data processed through the Service.
This Privacy Policy explains how we collect, use, store, and share personal data when you use our website at bemyletter.com and our application at /app (together, the "Service").
2. Scope
This policy applies to all users of the Service, regardless of where you live. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the GDPR sections of this policy apply to you in addition to any mandatory local protections. If you are located in India, the DPDP Act sections apply to you.
By creating an account or using BeMyLetter, you acknowledge that you have read and understood this Privacy Policy. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. If you do not agree, please do not use the Service.
3. Data we collect
We collect the following categories of personal data:
- Account information — your email address and name (obtained through Facebook Login), your selected role (founder or investor), and an optional profile bio you provide.
- Content you create — private meeting notes, perspective drafts and final text, contacts, topic tags, responses to limited actions, and any images you upload as part of a response.
- Relationship and activity data — delivery and witnessing status of perspectives, tie-strength scores derived from witnessed interactions, and references to other users you cite in notes or perspectives.
- Technical data — a session token stored in your browser's local storage to keep you signed in, and standard server logs generated by our hosting infrastructure (such as IP address, request timestamps, and error logs).
We do not collect your Facebook password. We receive only the profile fields you authorise through Facebook's login flow (typically email and name).
4. How we use your data
We use personal data to:
- Create and manage your account and authenticate your sessions.
- Provide the core Service — capturing notes, drafting perspectives, delivering them to counterparties, witnessing, coaching reads, and building your relationship record.
- Generate AI-assisted drafts and coaching when an AI provider is configured (see Section 7).
- Compute tie-strength metrics based on witnessed interactions.
- Show you profiles scoped to mutually witnessed interactions with a counterparty.
- Maintain the security and reliability of the Service.
- Respond to your requests, including data access and deletion.
- Comply with applicable law.
We do not sell your personal data to third parties.
5. Legal bases for processing (GDPR)
If you are in the EEA, UK, or Switzerland, we process your personal data only where we have a valid legal basis under the GDPR:
- Performance of a contract — to create and manage your account, provide the Service (notes, perspectives, witnessing, coaching, profiles), and communicate with you about your account.
- Consent — when you sign in via Facebook Login, deliver content to a counterparty, or use features that involve sending your data to an AI provider. You may withdraw consent by deleting content, stopping use of a feature, or contacting us; witness immutability rules may limit erasure of shared records (see Section 12).
- Legitimate interests — to maintain security, prevent abuse, improve reliability, and defend our legal rights, where those interests are not overridden by your rights. You may object to processing based on legitimate interests (see Section 14).
- Legal obligation — where we must comply with applicable law, regulation, or court order.
Where we ask for your consent, providing it is voluntary, but certain features may not be available without it.
6. The privacy membrane
BeMyLetter is designed with a strict boundary between private and shared content:
- Private notes — your raw meeting notes and capture answers never cross to your counterparty. They remain on your side of the account and are used to power coaching and to seed perspective drafts.
- Shared perspectives — only the short perspective text you review and approve is delivered to the designated counterparty. You see the exact wording before it is sent.
- Witnessed records — once a counterparty confirms your perspective is fair, it becomes part of a permanent, immutable record visible to that counterparty.
7. AI processing
BeMyLetter can use artificial intelligence to help draft perspectives, generate coaching reads, and suggest limited actions. When an AI provider is configured in our production environment, we send relevant content — such as your private notes, profile bio, contact name, and perspective text — to that provider to generate output. The AI output is a suggestion only; you review and approve anything before it is shared.
Our AI subprocessors may include:
- Anthropic (Claude models)
- OpenAI (GPT models)
Where the provider supports it, we request that AI requests are not stored or used for model training. When no external AI provider is configured, drafting runs using a local deterministic stub and your content is not transmitted to a third-party AI service.
8. Third-party services
We rely on the following third parties to operate the Service:
- Meta (Facebook) — for account authentication via Facebook Login. Meta's use of your data is governed by Meta's Privacy Policy.
- Microsoft Azure — for application hosting, PostgreSQL database storage, and blob storage for uploaded media files.
- Anthropic and/or OpenAI — optional AI subprocessors, as described in Section 7.
These providers act as our processors (or, in Meta's case, an independent controller for authentication data) under contractual arrangements that require appropriate data protection safeguards, including data processing agreements where required by the GDPR.
9. How we share data
We share personal data only in the following circumstances:
- With your counterparty — when you deliver a perspective, the approved text (and, once witnessed, the full witnessed record including tags and citations) is visible to the designated counterparty. Profile views show mutually witnessed interactions only.
- With service providers — as described in Section 8, to operate and secure the Service.
- For legal reasons — if required by law, regulation, court order, or to protect the rights, safety, or property of users or the public.
We do not share your private notes with any counterparty or third party for marketing purposes.
10. International data transfers
We are based in India and use infrastructure and subprocessors that may process personal data in India, the United States, and other countries outside the EEA and UK. When we transfer personal data from the EEA, UK, or Switzerland to a country that has not received an adequacy decision from the European Commission or UK government, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms permitted under applicable law.
You may request a copy of the safeguards we use for international transfers by contacting privacy@bemyletter.com.
11. Cookies and local storage
BeMyLetter does not use advertising or analytics cookies. We store a session token in your browser's local storage to keep you signed in for up to 30 days. This is functionally similar to a strictly necessary cookie and is essential to operate the Service. You can remove it by signing out or clearing site data in your browser settings.
Our marketing website at the root URL does not set tracking cookies. Third parties such as Meta may set cookies when you use Facebook Login; their use is governed by Meta's policies.
12. Data retention
We retain your account data and content for as long as your account is active and as needed to provide the Service. Witnessed perspectives are designed as permanent records and are retained even if you stop using the Service, because they form part of a shared history with your counterparty.
You can delete individual private notes from your account when they are not linked to a delivered or witnessed perspective, export all of your private notes at any time, or delete your account from account settings. Account deletion removes your private notes and draft perspectives and anonymizes your profile; witnessed perspectives you authored remain on the shared record without exposing your private notes. You may also request deletion by contacting us (see Section 19). We will honour deletion requests to the extent permitted by law and by the product's immutability rules for witnessed records. Some data may be retained in backups for a limited period or where retention is required by law.
13. Security
We use industry-standard measures to protect your data, including HTTPS encryption in transit, application-level encryption of private note content at rest, access controls on our infrastructure, and secure session management. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Your rights
Depending on where you live, you may have the following rights regarding your personal data. To exercise any right, contact privacy@bemyletter.com. We will respond within the timeframe required by applicable law (generally one month under the GDPR). We may need to verify your identity before fulfilling a request.
Rights under the GDPR (EEA, UK, and Switzerland)
If the GDPR applies to you, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten"), subject to exceptions including witnessed records that form part of a shared history with another user.
- Restriction — request that we limit how we use your data in certain circumstances.
- Data portability — receive personal data you provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller where technically feasible.
- Object — object to processing based on legitimate interests, including profiling carried out on that basis.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Lodge a complaint — with a supervisory authority in your country of residence, place of work, or where an alleged infringement occurred. A list of EU supervisory authorities is available from the European Data Protection Board. UK residents may contact the Information Commissioner's Office (ICO).
Rights under the DPDP Act (India)
If the DPDP Act applies to you, you have the right to:
- Access personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your personal data.
- Withdraw consent where processing is based on consent.
- Nominate another person to exercise your rights in the event of death or incapacity.
- Lodge a grievance with us regarding our handling of your data (see Section 15).
15. Grievance officer (India)
In accordance with the DPDP Act, you may contact our grievance officer for any complaints or concerns regarding the processing of your personal data:
Grievance Officer
Blue Insight Digital Private Limited
Email: privacy@bemyletter.com
We will acknowledge your grievance and endeavour to resolve it within the period prescribed under applicable law.
16. Automated decision-making
BeMyLetter does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Artificial intelligence is used only to suggest drafts, coaching reads, and limited actions — you review and approve all content before it is shared. Tie-strength scores are derived from witnessed interactions to surface relationship context; they do not determine access to the Service or legal outcomes.
17. Children
The Service is not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
18. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
19. Contact us
For privacy-related questions, data subject requests, or GDPR enquiries,
contact us at:
privacy@bemyletter.com
Data controller
Blue Insight Digital Private Limited
India
We do not currently maintain a separate establishment in the EEA or UK. EEA and UK residents may contact us directly at the address above to exercise their rights under the GDPR.