Heirloom Privacy Policy
Effective: July 19, 2026
Heirloom: Old Letter Reader helps you transcribe photographs of handwritten letters. This policy explains the information used to provide that service.
Information Heirloom processes
- Letter images and text. Pages you scan or select, along with an optional language hint, are sent to Heirloom's service and Google's Gemini API to create the transcript, modernized text, translation, title, and confidence score.
- Purchase information. Apple processes purchases. RevenueCat processes an app-specific customer identifier and subscription status so Heirloom can determine whether the full service is unlocked.
- App integrity and service metadata. Apple App Attest supplies a cryptographic app-installation assertion. The service retains hashed identifiers needed to prevent replay, enforce the one-time scan, and limit requests. Operational logs can include a hashed installation identifier, page count, processing time, model and prompt versions, and token counts. They do not include letter images or transcript text.
Storage and retention
Letter images and generated text are saved locally in the app's private storage so they can appear in your library. The local library uses iOS file protection and is not uploaded by Heirloom for library synchronization. Heirloom's backend processes letter images in memory and does not write them to persistent storage. Google processes submitted images and prompts to return the transcription under the terms governing its Gemini API plan. While Heirloom uses Google's Free tier, Google may use submitted content and generated responses to provide, improve, and develop its products and machine-learning technologies. If Heirloom moves to a Paid Gemini API plan, Google states that prompts and responses are not used to improve its products, subject to Google's applicable terms and abuse-monitoring practices. Hashed anti-abuse records remain on the service for as long as needed to preserve the free-scan and integrity rules. Hosting logs are retained according to the hosting provider's operational retention settings.
Service providers
Heirloom uses Apple for App Attest and in-app purchases, RevenueCat for subscription management, Google Gemini for handwriting transcription, and Render for API hosting. These providers process information only for their respective service functions and under their own privacy terms.
Tracking and advertising
Heirloom does not sell personal information, display third-party advertising, or track you across other companies' apps and websites.
Your choices
You choose which images to submit. Removing Heirloom and its app data removes the locally stored letter library. Subscription management and cancellation are available through your Apple account settings.
Security
Heirloom uses HTTPS, App Attest request verification, short-lived one-time challenges, replay counters, server-side secret storage, and request limits. No internet service can guarantee absolute security.
Children
Heirloom is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and contact
This policy may be updated as the service changes. The effective date above identifies the latest version. Questions or privacy requests can be sent to randyventures06@gmail.com.