Free pilot now open — limited spots. Full access, hands-on onboarding.Apply →
Letco logo
Legal

Privacy Policy

Last updated: February 2026

1. Introduction

This Privacy Policy describes how Letco.ai ("Letco", "we", "our") collects, uses, and protects your personal information when you use our development orchestration platform. We are committed to protecting your privacy and handling your data transparently.

2. Data We Collect

We collect the following categories of information:

  • Account information — Email address, username, and hashed password (passwords are never stored in plain text)
  • Device information — Device names and cryptographically hashed authentication tokens for registered devices
  • Session metadata — Session identifiers, timestamps, state transitions, and project associations
  • Encrypted messages — All session messages (user input and AI responses) are stored encrypted at rest. We cannot read the content of your messages.

3. API Keys & Credentials

When you provide AI provider API keys (Anthropic, OpenAI, Google, etc.):

  • Keys are encrypted at rest using AES-256-GCM with your personal encryption key
  • Keys are never stored in plain text in the database
  • Keys are never shared with other users, third parties, or Letco staff
  • Keys are only decrypted in memory when actively needed for your sessions
  • You can revoke or change your keys at any time

4. Encryption & Zero-Knowledge Architecture

Letco implements a zero-knowledge encryption architecture:

  • AES-256-GCM — All sensitive data is encrypted using authenticated encryption with 256-bit keys
  • Argon2id key derivation — Your encryption key is derived from your password using the Argon2id algorithm, which is resistant to GPU and ASIC attacks
  • Zero knowledge after logout — Once you log out, the server cannot decrypt your data. Your encryption keys exist only in memory during active sessions.
  • Session-level encryption— Each session has its own Data Encryption Key (DEK), enabling secure session sharing without exposing other sessions' data
  • Recovery mnemonic — A 24-word BIP39 mnemonic is provided at registration for account recovery. This is your responsibility to store securely.

5. How We Use Your Data

We use your data to:

  • Provide and maintain the Platform services
  • Authenticate your identity and manage your sessions
  • Enable real-time session monitoring and collaboration features
  • Send service-related communications (account verification, security alerts)
  • Improve the Platform based on aggregated, anonymized usage patterns

We do not use your encrypted session content for training AI models, analytics, or any purpose other than delivering it back to you.

6. Data Retention

  • Session data — Retained as long as your account is active. You can delete individual sessions at any time.
  • Container metrics — Preview environment metrics are retained for 7 days and then automatically purged.
  • Audit logs — Permission approval records and administrative actions are retained for compliance purposes.
  • Account deletion — When you delete your account, all associated data is permanently removed.

7. Third-Party Services

Letco integrates with third-party AI providers solely at your direction:

  • AI providers (Anthropic, OpenAI, Google) — Your API keys are sent directly to these providers for AI operations. Each provider has its own privacy policy governing how they handle API requests.
  • GitHub — Optional OAuth integration for git operations. You provide your own GitHub OAuth App credentials.

We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes.

8. Your Rights

You have the right to:

  • Access — View all data associated with your account
  • Correction — Update your account information at any time
  • Deletion — Delete your account and all associated data
  • Export — Download your session data and planning documents
  • Revocation — Revoke device access or API key storage at any time

9. Security

We employ industry-standard security measures including:

  • End-to-end encryption for all sensitive data
  • JWT-based authentication with short-lived access tokens
  • Rate limiting and brute-force protection
  • SHA-256 hashing for device tokens and invitation codes
  • HTTPS/TLS for all data in transit

10. Contact

For privacy-related questions or to exercise your data rights, contact us at privacy@letco.ai.

The data controller is Letco s.r.o., Říční 456/10, Malá Strana, 118 00 Prague, Czech Republic, Reg. No. (IČO): 24406953 (ARES registry).