Most secure messengers optimise for one thing: nobody but the participants can ever know anything. That is the right goal for personal messaging. It is the wrong goal for a law firm, a trustee or an asset manager, who must be able to show — years later — what was sent, to whom, and when.
Letro separates the two questions.
Content is end-to-end encrypted
Message bodies and attachments are encrypted on the sender's device with Matrix Olm/Megolm. The server stores ciphertext. Letro cannot read it, and neither can anyone who compromises the server. See the Encryption Model.
The record is kept
Alongside the ciphertext, the homeserver keeps a structured record of events: who sent a message, who received it, when it was delivered and read, and which verified PostNumber identity each party holds. Each event is timestamped and the chain of events is tamper-evident — any alteration after the fact is detectable.
Retention and export
The record is retained for the period defined by your plan — 10-year archive retention is included in every tier — and can be exported as evidence in a form that a counterparty, auditor or court can verify. Export is available in all tiers and is triggered on demand by an authorised administrator.
What this means in practice
- Letro does not have a "no-log" policy, and we do not claim one. A no-log platform cannot produce evidence.
- Letro cannot hand over readable message content, because it does not have it.
- Letro can produce the delivery record for a conversation, because that is what the product is for.
If you need a communication channel that can be forgotten, Letro is the wrong tool. If you need one that can be relied upon, this is the model.

