Privacy Policy
1. Controller
Mailery (mailery.co) is operated by Hasna Tools ("Mailery", "we"). For account and platform data we act as the data controller. For the contents of email messages that you store or route through the Service — which typically contain personal data of your correspondents — we act as a data processor on your instructions; you are the controller of that content.
2. What we collect
- Account data: email address, name (optional), Argon2id-hashed password, workspace/tenant name, role.
- Email content you store or route: messages including subject, sender and recipient addresses, message bodies (raw MIME, text, HTML, extracted markdown), attachments, labels, and AI-generated summaries/classifications. This is the core of the Service and can include any category of personal data your correspondents put in email.
- Domain data: the domains you connect, their DNS/verification state, and deliverability events (bounces, complaints, DMARC aggregate reports).
- Billing data: subscription and credit-purchase records, Stripe customer/session identifiers, and a credit ledger. Card details are processed by Stripe and never stored by us.
- Security and usage data: API key metadata (hashed secrets only), session records, IP-scoped rate-limit counters, and a security audit log (logins and failed logins, logouts, API key creation/revocation, password changes, credit adjustments, account deletion).
We do not use advertising trackers or third-party analytics cookies. The landing page stores only your theme preference in your browser's localStorage.
3. Why we process it (legal bases)
- Contract (GDPR Art. 6(1)(b)): providing the Service — hosting mailboxes, syncing, parsing, sending, billing.
- Legitimate interests (Art. 6(1)(f)): security, abuse and spam prevention, deliverability protection, audit logging, service improvement.
- Legal obligation (Art. 6(1)(c)): tax and accounting records for payments.
- Consent (Art. 6(1)(a)): only where we ask for it explicitly (e.g. optional communications).
4. Subprocessors and recipients
We use the following subprocessors to operate the Service:
| Provider | Purpose | Location |
|---|---|---|
| Service operations providers | Hosting, database, storage, and email delivery/receiving | United States |
| Stripe | Payment processing, subscriptions, customer billing portal | United States / global |
| Groq | AI inference for message parsing, classification, and digests (message content you submit for parsing) | United States |
| Cloudflare | DNS and network edge for mailery.co | Global |
We do not sell personal data. We disclose data only to these subprocessors, when required by law, or to protect the Service and its users. We will update this list before adding a subprocessor that processes Customer Content.
5. International transfers
The Service is hosted in the United States. Where GDPR/UK GDPR applies, transfers outside the EEA/UK rely on the European Commission's Standard Contractual Clauses (or the provider's equivalent approved mechanism, such as the EU–US Data Privacy Framework where certified).
6. Retention
- Email content, mailboxes, labels, domains: retained until you delete the individual items or delete your account.
- Account data, API keys, sessions: retained until account deletion; revoked API keys and expired sessions are kept only as inert records until account deletion.
- Account deletion: deleting your account (
DELETE /api/v1/account, from the CLI) permanently removes the tenant and all rows that belong to it — users, sessions, API keys, mailboxes, messages, attachments, labels, domains, and credit balance — in a single cascading delete. - Backups: encrypted database backups age out automatically within 35 days; deleted data disappears from backups on that cycle.
- Billing and tax records: retained for the statutory period (typically 7‑10 years) as required by law; these records reference invoices and amounts, not your email content.
- Security audit log: audit entries are retained for up to 24 months and then purged. Entries survive account deletion with the workspace reference severed, but a small number of retained entries remain identifying where the event itself requires it: the account-deletion record keeps the workspace name and account email address (so the deletion itself stays provable), and failed-login records keep the attempted email address and client IP (abuse prevention). We process these under legitimate interests (Art. 6(1)(f)) and use them only for security.
7. Your rights (GDPR and similar laws)
- Access and portability (Art. 15, 20): export your data as JSON at any time via
GET /api/v1/account/export— profile, mailboxes, messages with bodies, labels, domains, and credit history. - Erasure (Art. 17): delete individual messages/mailboxes/domains via the API, or delete the whole account via
DELETE /api/v1/account. - Rectification (Art. 16): update your profile via the API/CLI; contact us for anything you cannot change yourself.
- Restriction and objection (Art. 18, 21): contact support@mailery.co.
- Complaint: you may lodge a complaint with your local supervisory authority.
If we process email content as your processor, data-subject requests from your correspondents should be directed to you as controller; we will assist as required by Art. 28.
8. Security
- Transport encryption (TLS) for all traffic, including verified TLS to the database.
- Passwords hashed with Argon2id; API keys stored as SHA-256 hashes and shown only once at creation.
- Tenant isolation enforced on every query, with Postgres row-level-security policies as defense in depth.
- Security audit logging of authentication and key-management events; rate limiting on authentication endpoints.
- Secrets held in encrypted managed secret storage; production access restricted to least-privilege roles.
If we learn of a personal-data breach affecting you, we will notify you and the competent authority as required by law.
9. Children
The Service is not directed to children and may not be used by anyone under 16 (or the local age of digital consent).
10. Changes
We may update this policy; material changes will be announced by email or an in-product notice at least 14 days before they take effect.
11. Contact
Hasna Tools
Data protection contact: support@mailery.co
Email: support@mailery.co