PrivacyPolicy
Data controller
The data controller responsible for your personal information under this Privacy Policy is JOKR Global LLC, a limited liability company organized under the laws of the State of Wyoming, doing business as Let'sText. Registered address: 2232 Dell Range Blvd, Suite 303 #1481, Cheyenne, WY 82009, United States.
Privacy inquiries: privacy@jokrglobal.com
Customer service: support@letstextapp.com
1. Introduction
Let'sText operates a software-as-a-service platform that enables digital content creators to manage fan conversations, sell pay-per-view digital content, and process payments through messaging channels including iMessage.
This Privacy Policy describes how we collect, use, disclose, store, and protect personal information when you use our Platform, visit our website, or otherwise interact with us. It applies to all users, including Creators, team members (Typers, Managers, Admins), and Fans or Buyers. If you do not agree with this Privacy Policy, do not use the Platform.
2. Information we collect
Information you provide directly:
- Account information: full name, email address, password (encrypted), profile photo, role and permissions.
- Creator profile information: display name, handle, bio, WhatsApp number, social links, pricing, watermark preferences and profile images.
- Content and media: photos, videos and other media uploaded to the vault, content metadata, PPV pricing and message templates.
- Communication data: messages sent and received through the Platform, timestamps, read receipts, delivery status, fan phone numbers, conversation notes and tags, and mass messages.
- Payment information: transaction amounts and currency, descriptions, status and history, and checkout URLs. We do not collect or store card numbers or bank account details. These are handled entirely by our PCI DSS-compliant payment processor.
Information collected automatically:
- Usage and analytics data: pages visited, features used, click patterns, time on the Platform and search queries.
- Device and technical data: IP address, browser, operating system, device type, screen resolution, language and time zone.
- Log data: server access logs, error logs, API request logs, authentication events and activity logs.
Information from third parties: we may receive information from our payment processor (payment processing), our messaging infrastructure (message delivery), and traffic sources (referring platforms), and we rely on service providers for infrastructure and hosting under written data-processing agreements.
3. How we use your information
- Providing and operating the Platform: accounts, messaging, content delivery and team management
- Payment processing: transactions, refunds, revenue reports and fraud detection
- Analytics and reporting: revenue dashboards, team performance and traffic sources
- Communication: notifications, billing alerts, service announcements, and marketing with consent
- Safety, security and compliance: fraud detection, enforcing our Terms, content moderation and audit logs
- Improving and developing the Platform
5. Data retention
| Data type | Retention period |
|---|---|
| Account information | Duration of account plus 90 days |
| Messages and conversations | Duration of account plus 90 days |
| Vault content (media) | Duration of account plus 30 days |
| Payment records | 7 years (tax and legal compliance) |
| Activity and audit logs | 3 years |
| Analytics events | 2 years |
| Server and access logs | 90 days |
| Authentication logs | 1 year |
6. Data security
We use industry-standard administrative, technical and physical safeguards, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest
- Secure password hashing and time-limited authentication tokens
- Role-based access control limiting data to authorized personnel
- Authenticated API access and webhook verification
- Input validation at every system boundary, security headers and restricted cross-origin requests
Card data is processed exclusively by our PCI DSS-compliant payment processor. Let'sText does not store, process or transmit card data on its own systems. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your rights and choices
- Access and portability: get a copy of your personal information in JSON or CSV.
- Correction: ask us to correct inaccurate information.
- Deletion: ask us to delete your personal information.
- Restriction and objection: object to processing and opt out of marketing.
- Withdrawal of consent: withdraw consent at any time.
9. U.S. state privacy rights (CCPA/CPRA)
California residents have the right to know, delete and correct personal information, to opt out of sale or sharing (we do not sell personal information), to limit use of sensitive information, and to non-discrimination for exercising these rights. Residents of Virginia, Colorado, Connecticut and other states with comparable laws have similar rights.
10. European Economic Area and United Kingdom (GDPR)
If you are in the EEA or UK, we process your data on the basis of contract performance, legitimate interest, legal obligation and consent. You may lodge a complaint with your supervisory authority, object to or restrict processing, and request portability of your data.
11. Children's privacy
The Platform is intended exclusively for users 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn we have, we delete it immediately. If you believe a minor has provided us with personal information, contact privacy@jokrglobal.com.
12. Data breach notification
If a breach affects your personal information, we will:
- Notify affected users within 72 hours of becoming aware of it, as required by GDPR Article 33
- Notify the relevant supervisory authority for EEA and UK users within 72 hours where feasible
- Describe the nature of the breach, who is affected, the likely consequences and the measures taken
- Notify the California Attorney General if more than 500 California residents are affected
- Record every breach in an internal breach register and give affected users practical guidance
13. Federal and state legal compliance
We comply with the Electronic Communications Privacy Act and Stored Communications Act, CAN-SPAM, COPPA, Section 5 of the FTC Act, and PCI DSS through our payment processor, as described in our Terms of Service.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes are notified at least 30 days before they take effect. Continued use after the effective date means you accept the update.
15. Contact us
To ask a question or exercise your privacy rights, contact privacy@jokrglobal.com. We respond to verifiable requests within 45 days, or sooner where the law requires, and may need to verify your identity first.