How Startup Mail handles data.
Effective August 2, 2026
1. Our role
Startup Mail is controller for account, billing, website, security, and support data. For customer messages, attachments, recipient data, and similar content, Startup Mail generally acts as a processor or service provider following the customer’s instructions. That customer is responsible for its own notices, permissions, and lawful basis.
2. Data we process
- Names, email addresses, authentication records, memberships, settings, and policy acceptances.
- Domains, DNS records, sender and recipient addresses, messages, headers, attachments, delivery events, forwarding, and suppression records.
- API-key identifiers and scopes, MCP requests, webhooks, usage, subscriptions, and payment status. Stripe processes payment-card details; Startup Mail does not store full card numbers.
- IP addresses, user agents, request identifiers, authentication attempts, errors, abuse signals, and diagnostic logs.
- Support messages and abuse reports.
We receive this data from you and workspace members; senders, recipients, and their mail providers; applications and agents you connect; payment and infrastructure providers; and automatically from use of the Service.
3. Why we use it
We use data to route, store, display, forward, and deliver email; verify domains; authenticate users and integrations; bill for the service; provide support; prevent spam, malware, fraud, and security incidents; enforce our policies; improve reliability; and comply with law.
Where required, our legal bases are performance of a contract, legitimate interests in operating and securing the Service, compliance with law, and consent for optional communications. We do not use private email content to train general-purpose AI models without explicit agreement.
4. How data is shared
Cloudflare hosts the application, D1 database, R2 objects, queues, and network security. AWS provides SES email transport and the temporary S3/SNS inbound bridge. Stripe processes subscriptions and payments. See our subprocessor list for the current providers and purposes.
We also send data to mail providers, recipients, forwarding addresses, webhook endpoints, and API or MCP clients when a customer instructs us to do so. We may disclose data to professional advisers, auditors, insurers, a business acquirer, or authorities where reasonably necessary or legally required. MCP support does not make mailbox data public: a client receives data only through the customer’s scoped credentials.
5. International transfers
Providers may process data in countries other than yours. Where required, we rely on an adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism.
6. Retention
- Messages and attachments remain until deleted; trashed threads are permanently removed from active systems after 30 days.
- A workspace deletion has a seven-day cancellation window, followed by deletion from active systems and provider recovery windows.
- The temporary AWS inbound copy expires after one day; unused attachment uploads expire after one hour.
- Suppression, fraud, billing, tax, dispute, and security records may remain longer where needed or legally required.
Deletion from backups and provider-managed point-in-time recovery may take additional time. We may keep a minimal record where necessary to comply with law, resolve disputes, prevent fraud, or enforce our agreements.
7. Security
We use TLS, private object storage, scoped credentials, tenant and mailbox authorization, signed callbacks, encrypted recoverable secrets, rate limits, and monitoring. No method of transmission or storage is perfectly secure. Ordinary email may also pass through recipient systems outside Startup Mail’s control.
8. Your choices and rights
Depending on location, you may request access, correction, deletion, restriction, objection, or portability; withdraw consent; opt out of certain processing; and complain to a data-protection authority. We will not discriminate against you for exercising a privacy right. Customers can export workspace data and schedule deletion in the Service. For other requests, contact hello@startupmail.dev. We may need to verify identity and authority.
If your data appears in a customer’s mailbox, contact that customer first because it normally controls the data. We will assist that customer as required by applicable law.
9. Sale, advertising, and automated decisions
We do not sell personal data. We do not share personal data for cross-context behavioral advertising and do not use third-party advertising cookies. Startup Mail does not make decisions producing legal or similarly significant effects based solely on automated processing. Automated abuse controls may pause sending, with support review available.
10. Cookies and communications
We use storage needed for secure sessions and product operation and do not currently use third-party advertising cookies. We send service, security, verification, billing, and support communications. Any optional marketing communication will include the required controls.
11. Children
The Service is for business users aged 18 or older and is not directed to children. Contact us if you believe a child has provided personal data.
12. Changes and contact
Material policy changes will be communicated by email, dashboard notice, or this website and will apply from their stated effective date. Privacy questions and requests may be sent to hello@startupmail.dev.