Skip to content
Legal · 2026.10.05.draft1

Privacy notice

Version 2026.10.05.draft1. DRAFT — PENDING REVIEW BY A UNITED STATES ATTORNEY. The legal entity, formation state, business address, privacy contact and effective commercial date remain pending. No claim of complete legal compliance is made.

Pre-launch draftRequires legal review before commercial launch.

Information processed

Administrative name/email, declared customer type and US residence or establishment region, credentials stored as password hashes, domain and mailbox settings, message content and MIME, attachments, senders/recipients, delivery status, API/webhook data, support requests, usage, security logs, audit and document-acceptance evidence are processed. Messages can contain information about people outside the United States; the customer eligibility limit does not prevent that.

Purposes and providers

We use data to authenticate, provision domains and mailboxes, send and receive email, provide API/webhooks, enforce quotas, prevent abuse, answer support and investigate incidents. AWS operates infrastructure including SES, S3, SQS, CloudWatch and Secrets Manager in us-east-1. PostgreSQL is external; the contracting processor identity, hosting location, subprocessors and backup terms must be verified before release. Recipient email providers and customer webhook destinations receive data needed for delivery.

Access and optional features

Tenant and mailbox authorization restrict ordinary access; privileged operational actions are audited. Dashboard and Webmail use separate HttpOnly session cookies. Optional configured analytics are subject to the cookie notice; GA4 requires analytics consent. Writing assistance can transmit selected text to a configured AI provider when invoked; provider, processing terms and retention need review. No antivirus guarantee is made.

Retention and deletion

Trash access ends 30 days from entry or on permanent deletion; S3 cleanup is asynchronous and retried. Other mailbox copies and attachments referenced by drafts or active sends remain. A minimal message identity is kept to prevent redelivery from recreating deleted mail. Message metadata, audits and acceptance evidence do not yet have a fully automated disposal schedule. Application logs use configured staging retention; external database backups and provider logs require verified retention terms. We do not promise immediate or universal deletion.

Exceptional legal preservation

An authorized, scoped preservation suspends affected physical deletion and keeps normal deleted-mail access unavailable. Access, creation and release are restricted and audited. Log exports and provider backups must be secured through the documented operational procedure; the application alone cannot override third-party retention. Preservation does not authorize disclosure; legal requests require separate validation.

Requests and unresolved details

Privacy and deletion requests require verified identity and a designated legal contact that is still pending. State-specific rights, exceptions, deadlines, minors, notices of security incidents and international-access implications require attorney review. Do not infer that all state privacy laws apply identically or that US-only contracting eliminates other obligations.