Privacy policy
Effective date: July 25, 2026
This policy explains how EmailPal (“EmailPal”, “we”, “us”) collects, uses, stores and shares personal data when you visit emailpal.io, create an account, or use the EmailPal platform, REST API or MCP server (together, the “Service”). It also explains how we handle data belonging to people who receive email sent through the Service, because an email platform that only talks about its customers’ privacy is describing half of what it does.
Questions about this policy or about your data can be sent to privacy@emailpal.io. We answer these ourselves, not through a form.
1. The two roles we play
For the personal data of our customers and website visitors — your account details, billing information, usage of the dashboard and API — we are the data controller. We decide what is collected and why, and this policy is our explanation.
For the personal data of recipients — the addresses our customers upload, the messages they send, and the replies that come back — we are a data processor. That data is controlled by the customer who sent the mail. We process it only to provide the Service, to protect the deliverability of our infrastructure, and to prevent abuse, all as described in this policy and in our terms of service. If you received an unwanted email sent through our infrastructure, section 8 below is written for you.
2. Data we collect from customers and visitors
Account data
When you sign up we collect your email address, and during onboarding we ask for your name, company details, website, and a description of what you send and where your recipient lists come from. We ask this because we verify every account by hand before it can send, and the answers are part of that verification record. Authentication is by emailed sign-in link, so we never collect or store a password.
Billing data
Payments are processed by Stripe. We never see or store full card numbers. We keep the billing records we generate ourselves — plans, invoice line items, usage quantities, and your prepaid domain balance — because we compute every invoice from our own records and must be able to explain any charge to you line by line.
Usage and log data
We record how the Service is used: dashboard actions, API requests (including the API key used, endpoint, timestamps and originating IP address), jobs run on your behalf, and the automated decisions the platform takes about your sending, such as throttles applied or warming schedules changed. We keep these records because the platform acts automatically and you are entitled to an explanation of every action it took.
Technical data
Standard web server logs: IP address, browser type, pages requested, and timestamps. We use only cookies that are strictly necessary to operate the Service — session cookies that keep you signed in. We do not use advertising cookies, tracking pixels from ad networks, or third-party analytics that profile you across other sites.
3. Data we process on customers’ behalf
Mailbox content
The Service hosts mailboxes. Messages sent from and received by those mailboxes — including their content, headers, and attachments — are stored on our infrastructure so that features like the unified inbox, reply detection and exports work. This content belongs to the customer. We do not read it out of curiosity, sell it, or use it to train machine-learning models. We do inspect it, by automated means and where necessary by a human, for the abuse prevention purposes described in section 5.
Recipient lists
When a customer submits a recipient list for verification, we classify each address (deliverable, invalid, risky, suppressed, duplicate) and return the assessment. Verification is designed to minimise what we keep: the addresses are processed to produce the assessment and are not retained as a browsable list on our side beyond what is needed to complete the job and record its outcome.
The suppression list
When a recipient unsubscribes from mail sent through our infrastructure, or complains about it via a provider feedback loop, we record that address on a platform-wide suppression list. This is a deliberate retention: the entire purpose of the record is to make sure that address is never mailed again through our infrastructure, by any customer. We consider this processing to be in the clear interest of the recipient, and it is the one category of recipient data we will not delete on a customer’s instruction, because deleting it would cause the very harm it exists to prevent.
Unsubscribe links
Every message relayed through our infrastructure carries a one-click unsubscribe header. The link contains a signed token rather than a database identifier, which means we store nothing about a recipient at the moment of sending — a record is created only if the recipient actually unsubscribes, at which point their address enters the suppression list described above.
4. How we use data
- Providing the Service — provisioning domains, DNS and mailboxes, warming, routing mail, measuring inbox placement, and operating the dashboard, API and MCP server.
- Reputation management — classifying SMTP responses, monitoring blocklists and provider reputation programs, and adjusting sending automatically. This is the core of the product and it necessarily involves processing delivery metadata about every message.
- Abuse prevention — verifying accounts, screening recipient lists, detecting prohibited content and behaviour, and enforcing our acceptable use policy.
- Billing — metering usage and computing invoices.
- Support and communication — answering your requests and sending you operational notices about your account. We do not send marketing mail to recipients, and we do not add our customers to marketing lists without asking.
- Legal obligations — responding to lawful requests from authorities, and keeping the records that tax and accounting law require.
5. Message inspection for abuse prevention
We operate shared sending infrastructure. One customer sending fraud or spam damages the deliverability of every other customer, so we reserve the right to inspect message content, headers, sending patterns, recipient list characteristics and delivery outcomes — by automated systems routinely, and by a human where the automated systems flag something or where we receive an abuse report. This inspection is limited to what is needed to decide whether the acceptable use policy is being followed. Its outcomes (throttles, suspensions, terminations) are recorded, and serious findings such as phishing or fraud may be reported to hosting providers, blocklist operators or law enforcement.
6. Who we share data with
We do not sell personal data, and we do not share it with anyone for their own advertising. We share data with the service providers we build on, each only receiving what its function requires:
| Provider | Function | What it processes |
|---|---|---|
| Supabase | Database and authentication | Account data, platform records, sign-in email delivery |
| Vercel | Web and API hosting | Request logs, IP addresses |
| Stripe | Payments | Billing identity and payment details |
| Dynadot | Domain registration | Registrant contact details for domains you purchase |
| Cloudflare | DNS | DNS records for managed domains |
| OVH | Mail infrastructure hosting | Mail traffic and mailbox content on our servers there |
| Google, Microsoft, Yahoo | Reputation and feedback programs | Delivery and complaint data those providers report about our sending ranges |
Beyond these, we disclose data only when the law requires it, to enforce our agreements, or as part of a merger, acquisition or asset sale — in which case this policy continues to apply to data transferred, and we will tell you before a new policy does.
7. International transfers, retention and security
Our infrastructure is operated in the United States and the European Union. Where personal data subject to the GDPR or UK GDPR is transferred outside those regions, we rely on adequacy decisions or standard contractual clauses.
We keep account and billing records for as long as your account exists and for the period afterwards that accounting and tax law require. Mailbox content is deleted when a mailbox is deleted, and account content becomes unrecoverable following the export window described in the terms of service. Operational logs are kept for up to twelve months. Suppression list entries are kept indefinitely, for the reason given in section 3.
Some mailboxes are leased rather than owned, and the same address is later leased to a different customer. Reuse of an address is never reuse of its contents. When a lease ends we destroy the mailbox on the mail server outright rather than emptying it, delete the stored messages, message index, sync state and credentials from our database, and clear the sender identity attached to it. The address is then recreated from nothing with new credentials, so there is no path by which the previous customer’s mail or logins reach the next one. What survives is the address string and its aggregate deliverability metrics — counts of messages sent, placement outcomes and health scores — which contain no message content and no recipient identities. Mail arriving at a reclaimed address is discarded, not delivered, for a quarantine period before it is leased again.
Sensitive material — mailbox credentials, signing keys, and credentials for connected services — is encrypted at rest, with keys segregated so that no single system holds all of them. Access to production data is restricted, logged, and used for operating the Service rather than exploring it. No description of security is a guarantee, but if a breach affects your personal data we will notify you and the relevant authorities as the law requires.
8. If you received email sent through EmailPal
The sender of that message — our customer — is the controller of your data, and chose to contact you. What we can do, and will do, is this:
- Unsubscribe: use the unsubscribe link in the message. It works with one click, requires no login, and places your address on a platform-wide suppression list so that no customer of ours can mail it again.
- Report abuse: forward the message with its headers to abuse@emailpal.io. Abuse reports are read by a person and acted on against the sending account.
- Exercise data rights: requests to access or delete data held by the sender should go to the sender, who is identified in the message. If you cannot reach them, contact privacy@emailpal.io and we will pass the request to the customer and suppress your address in the meantime.
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive it in a portable format, object to or restrict certain processing, and complain to a supervisory authority. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR and UK GDPR; California residents have analogous rights under the CCPA/CPRA, including the right to know and the right to delete. We do not “sell” or “share” personal information as the CCPA defines those terms.
To exercise any of these rights, email privacy@emailpal.io from the address associated with your account, or with enough information for us to verify who you are. We respond within the time the applicable law allows, and we do not discriminate against anyone for exercising their rights.
10. Children
The Service is business infrastructure and is not directed at anyone under 18. We do not knowingly collect personal data from children, and we delete any we discover.
11. Changes to this policy
When we change this policy we will update the effective date above, and for material changes we will notify account holders by email before the change takes effect. Continued use of the Service after a change takes effect means the updated policy applies.
12. Contact
Privacy questions and requests: privacy@emailpal.io
Abuse reports: abuse@emailpal.io
Everything else: support@emailpal.io