Privacy
What we collect about you as our customer, what we process on your behalf as your processor, and how long each is kept.
Two different roles
For your own account data — your name, your email, your billing details, your login history — we are the controller. For your contacts and your recipients, you are the controller and we are the processor acting on your instructions. This distinction decides who answers a data-subject request, and it runs through everything below.
What we hold as controller
| Data | Why | Retention |
|---|---|---|
| Name, email, password hash | To operate your account | Until you close it |
| Login history, device and IP | Security alerts and session management | 24 months |
| Billing details | Invoicing and tax | 10 years, a legal requirement |
| Audit log | Proving who did what | 24 months, append-only |
| Support correspondence | Answering you | 24 months |
What we process as processor
| Data | How it is stored | Retention |
|---|---|---|
| Recipient addresses | Encrypted, with a hash for lookup | 13 months |
| Message metadata | Postgres, tenant-scoped | 13 months, then aggregated |
| Message bodies | Envelope-encrypted in EU object storage | 30 days transactional; mailbox until you delete |
| Attachments | Envelope-encrypted, metadata stripped | Same as the parent message |
| Open and click events | Analytics store, with geo and device | 25 months |
| IP addresses | Configurable: full, anonymised, or not at all | 13 months default, 30 days minimum |
| Consent evidence | Timestamp, IP, source, method | Retained after deletion as proof of prior consent |
What is never logged
Message bodies, subjects beyond a truncated support snippet, recipient addresses in plaintext, attachment contents or filenames, passwords, API keys, tokens, DKIM private keys and encryption keys are never written to a log, at any level, anywhere. This is enforced by a structured logger that accepts only allow-listed field types, a lint rule, and an automated test asserting that a full send request produces zero log lines containing an @ sign.
Where it lives
The EU by default: Hetzner in Germany and Finland, the sending provider in eu-central-1, and object storage pinned to the EU jurisdiction on creation. No production data goes to a US region without your explicit opt-in. Geolocation uses a local database file rather than a lookup API, specifically so no recipient IP address is ever transmitted to a third party.
Your rights
- Access and portability — a complete machine-readable export, from the API or the dashboard.
- Erasure — deleting a contact removes the row; the consent record is retained as legally required, and the recipient hash goes on a permanent do-not-contact list so a re-import cannot resurrect them.
- Rectification — contact attributes are editable.
- Objection — a recipient-facing preference centre on the tracking domain lets any recipient opt out of tracking and unsubscribe from all mail from a workspace.
Deleting a workspace destroys its encryption key