Skip to content
MailHaap
[01]Last updated 21 August 2026

Privacy

What we collect about you as our customer, what we process on your behalf as your processor, and how long each is kept.

Two different roles

For your own account data — your name, your email, your billing details, your login history — we are the controller. For your contacts and your recipients, you are the controller and we are the processor acting on your instructions. This distinction decides who answers a data-subject request, and it runs through everything below.

What we hold as controller

Data we hold about you as our customer
DataWhyRetention
Name, email, password hashTo operate your accountUntil you close it
Login history, device and IPSecurity alerts and session management24 months
Billing detailsInvoicing and tax10 years, a legal requirement
Audit logProving who did what24 months, append-only
Support correspondenceAnswering you24 months

What we process as processor

Data we process on your behalf
DataHow it is storedRetention
Recipient addressesEncrypted, with a hash for lookup13 months
Message metadataPostgres, tenant-scoped13 months, then aggregated
Message bodiesEnvelope-encrypted in EU object storage30 days transactional; mailbox until you delete
AttachmentsEnvelope-encrypted, metadata strippedSame as the parent message
Open and click eventsAnalytics store, with geo and device25 months
IP addressesConfigurable: full, anonymised, or not at all13 months default, 30 days minimum
Consent evidenceTimestamp, IP, source, methodRetained after deletion as proof of prior consent

What is never logged

Message bodies, subjects beyond a truncated support snippet, recipient addresses in plaintext, attachment contents or filenames, passwords, API keys, tokens, DKIM private keys and encryption keys are never written to a log, at any level, anywhere. This is enforced by a structured logger that accepts only allow-listed field types, a lint rule, and an automated test asserting that a full send request produces zero log lines containing an @ sign.

Where it lives

The EU by default: Hetzner in Germany and Finland, the sending provider in eu-central-1, and object storage pinned to the EU jurisdiction on creation. No production data goes to a US region without your explicit opt-in. Geolocation uses a local database file rather than a lookup API, specifically so no recipient IP address is ever transmitted to a third party.

Your rights

  • Access and portability — a complete machine-readable export, from the API or the dashboard.
  • Erasure — deleting a contact removes the row; the consent record is retained as legally required, and the recipient hash goes on a permanent do-not-contact list so a re-import cannot resurrect them.
  • Rectification — contact attributes are editable.
  • Objection — a recipient-facing preference centre on the tracking domain lets any recipient opt out of tracking and unsubscribe from all mail from a workspace.

Deleting a workspace destroys its encryption key

Every object belonging to that workspace becomes permanently unreadable in the same instant — including copies in backups and replicas. That is a verifiable answer to “delete all my data” that object-by-object deletion can never give.