STARTUP MAIL PRIVACY POLICY

How Startup Mail handles data.

Draft for legal review · Version 2026-08-02

Our role

Startup Mail is controller for account, billing, website, security, and support data. For customer messages, attachments, recipient data, and similar content, Startup Mail generally acts as a processor or service provider following the customer’s instructions.

Data we process

  • Names, email addresses, authentication records, memberships, settings, and policy acceptances.
  • Domains, DNS records, sender and recipient addresses, messages, headers, attachments, delivery events, forwarding, and suppression records.
  • API-key identifiers and scopes, MCP requests, webhooks, usage, subscriptions, and payment status.
  • IP addresses, user agents, request identifiers, authentication attempts, errors, abuse signals, and diagnostic logs.
  • Support messages and abuse reports.

Why we use it

We use data to route, store, display, forward, and deliver email; verify domains; authenticate users and integrations; bill for the service; provide support; prevent spam, malware, fraud, and security incidents; enforce our policies; improve reliability; and comply with law. We do not sell personal data.

Providers and recipients

Cloudflare hosts the application, D1 database, R2 objects, queues, and network security. AWS provides SES email transport and the temporary S3/SNS inbound bridge. Stripe processes subscriptions and payments. We also send data to mail providers, recipients, forwarding addresses, webhooks, and API or MCP clients when the customer instructs us to do so.

Retention

  • Messages and attachments remain until deleted; trashed threads are permanently removed from active systems after 30 days.
  • A workspace deletion has a seven-day cancellation window, followed by deletion from active systems and provider recovery windows.
  • The temporary AWS inbound copy expires after one day; unused attachment uploads expire after one hour.
  • Suppression, fraud, billing, tax, dispute, and security records may remain longer where needed or legally required.

Security and transfers

We use TLS, private object storage, scoped credentials, tenant and mailbox authorization, signed callbacks, encrypted recoverable secrets, rate limits, and monitoring. Providers may process data outside your country. Where required, we use recognized transfer safeguards.

Your rights

Depending on location, you may request access, correction, deletion, restriction, objection, or portability and may complain to a data-protection authority. Customers can export workspace data and schedule deletion in the service. For other requests, contact hello@startupmail.dev. We may need to verify identity and authority.

Cookies, children, and changes

We use storage needed for secure sessions and product operation and do not currently use third-party advertising cookies. The service is for business users aged 18 or older. Material policy changes will be communicated and may require renewed acknowledgment.

Contact

The final controller legal name, registered address, registration number, privacy contact, and supervisory authority will be inserted after the operating entity is confirmed. Until then, contact hello@startupmail.dev.