Who controls your data
Latchra operator, Operator address not configured, Country not configured operates Latchra and is the controller for account, product, support and direct-billing data. A team customer may be the controller for workspace content and Latchra its processor.
Privacy requests: support@example.com.
Data we process
- Account and profile data: name, email, authentication identifiers, locale and preferences.
- Connected-source data: provider account identifiers, encrypted OAuth tokens, message metadata and the minimum message content required to detect obligations.
- Product data: obligations, deadlines, parties, notes, status history, team membership, permissions and audit events.
- Billing data: plan, entitlement and transaction references. Payment card data is handled by the payment provider, not stored by Latchra.
- Device, security and support data: device tokens, IP-derived security signals, diagnostic events and content you deliberately send to support.
Purposes and legal bases
- Contract: provide the service, authenticate you, synchronize authorized sources, detect and track commitments, send requested reminders and manage subscriptions.
- Legitimate interests: secure the service, prevent abuse, diagnose failures and improve reliability with minimized telemetry. We balance these interests against your rights.
- Consent: optional analytics, marketing communications and provider permissions where consent is the applicable basis. You may withdraw consent at any time.
- Legal obligation: tax, accounting, fraud prevention and responses required by law.
Mail sources and automated analysis
You choose whether to forward messages or authorize read-only Gmail or Microsoft access. Latchra extracts structured facts such as the responsible party, deadline, amount and resolution state. Low-confidence results are sent to review; Latchra does not make legal or similarly significant decisions about you.
Jev is the primary decision provider and OpenAI may be used as a structured fallback when enabled. Input is minimized to what the analysis needs. Provider access can be revoked from Settings and from the provider account.
Retention
- Raw inbound message material is scheduled for deletion within 24 hours after successful normalization unless needed to resolve a processing failure.
- Source excerpts are retained for up to 365 days or a shorter workspace setting; deleting the related obligation removes the excerpt from active systems.
- Security logs are ordinarily retained for 90 days.
- Requested exports expire after 24 hours. Account deletion is targeted within 30 days after any displayed grace period.
- Invoices and legally required accounting records may be retained for up to 10 years or the period required by applicable law. Backups age out on the documented backup cycle.
Your rights and choices
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may complain to your local supervisory authority. We may verify identity and will explain any lawful limitation.
- Request an account export
- Delete an account
- Change optional analytics choices
- Email support@example.com for any other request.
Children, changes and contact
Latchra is not directed to children under 16. If local law requires a higher age for independent consent, that higher age applies. Contact us if you believe a child supplied data without valid authorization.
We will post material changes here and, when appropriate, notify account owners before they take effect. Continued use never removes rights granted by applicable law.