Legal

Privacy Policy

What personal data we hold, why we hold it, how long it stays, and the rights you have over it.

Last updated 2026-08-10

What this says, in short

  • We never sell your data or train models on your email.
  • Stored mail is deleted automatically after 15 days, on every plan.
  • Sign-in is passwordless and API keys are stored hashed.
  • You can access, export or delete your data at any time.

This summary is for orientation only — the numbered sections below are the terms that apply.

01

Two kinds of data, two different roles

This distinction runs through the whole policy, so it comes first.

  • Your account data — who you are, what you pay, how you use the console. Here we are the controller: we decide why and how it is processed, and this policy is our commitment to you.
  • The mail you route through us — the messages themselves and everyone named in them. Here we are your processor: you decide what is collected and why, and we act on your instructions. You are responsible for having a lawful basis to process it.

In plain terms: We answer for your account data. You answer for the contents of the mail you route through us.

02

Account data we collect

  • Identity: your email address, and your name if you give one.
  • Authentication: session records, passkey public keys and device metadata, and identifiers from any social login you choose. We never hold a password — sign-in is passwordless.
  • API keys: stored only as a hash, plus a short non-secret prefix so you can tell keys apart. We cannot recover a key once shown.
  • Billing: your Stripe customer and subscription identifiers, your plan, and cycle dates. Card details go straight to Stripe and never reach our servers.
  • Usage counters: how many emails you received and sent in each billing cycle, used to apply plan limits and bill overage.
  • Operational logs: request and delivery records, including webhook attempt status, timing and response data, used to debug failures and detect abuse.

03

Mail data we process for you

When mail arrives at a domain you have connected, we store what is needed to make it usable:

  • Envelope and headers: sender, recipients, subject, message id, and the In-Reply-To/References headers used to thread conversations.
  • Bodies: the plain-text and HTML parts.
  • Attachments: filename, type and size on every plan; the file contents themselves only on plans that include attachment storage.
  • The original raw message, kept in object storage so a message can be re-parsed or forwarded intact.
  • Authentication results: SPF, DKIM, DMARC, spam and virus verdicts from the receiving infrastructure.

Outbound mail you send through the API is stored the same way, along with the delivery events our provider reports back — including bounces and spam complaints, which we add to a suppression list so we stop mailing addresses that have rejected you.

04

Why we process it

  • To perform our contract with you: running the service, routing and storing mail, and taking payment.
  • For our legitimate interests: keeping the service secure, preventing abuse and spam, protecting sending reputation, and debugging.
  • To comply with legal obligations, such as tax and accounting rules.
  • With your consent where it is required — for example optional cookies, if we ever add any.

05

What we do not do

We do not sell your data. We do not rent or share it with advertisers. We do not read your mail to build a profile of you, and we do not use the contents of your mail to train machine-learning models. Staff access to message content happens only when you ask us to investigate something, or where we must to keep the service running or meet a legal obligation.

In plain terms: No selling, no ads, no training models on your email.

06

How long we keep it

Stored mail is deleted 15 days after it arrives — the same window on every plan, free included, as listed on the pricing page. A scheduled job deletes messages past that window, together with the associated objects in storage. Raw messages additionally expire on a 90-day storage lifecycle rule.

Account and billing records are kept while your account is open and afterwards for as long as tax and accounting law requires. Suppression entries are kept while the account is open, because removing them would mean mailing addresses that already complained. Operational logs are kept for a short, rolling period.

In plain terms: Your mail is deleted on your plan's schedule, automatically — not kept indefinitely.

07

Who we share it with

Only the service providers we need to run the product. They fall into five categories: email sending and receiving infrastructure, cloud object storage, a managed database, application hosting, and payment processing. Each is engaged under terms requiring it to protect the data, process it only to provide its service to us, and apply appropriate security measures.

We keep that list deliberately short — no analytics, advertising or data-enrichment vendors sit in the path your mail travels. If you need the current providers named, for a vendor review or your own compliance records, email privacy@inboundr.net and we will send you the list.

We also share data where the law requires it, and we may transfer it as part of a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.

Note that email is, by design, sent to third parties. When you send a message, its contents go to the recipient's mail provider, which is outside our control.

08

International transfers

Our infrastructure runs in the United States, so data you route through us is processed there. Where data moves out of the UK or European Economic Area, we rely on the appropriate safeguards for that transfer, such as the European Commission's Standard Contractual Clauses.

09

How we protect it

  • Traffic is encrypted in transit with TLS; stored data is encrypted at rest by our infrastructure providers.
  • Sign-in is passwordless — magic link, passkey or a social provider — so there is no password of yours for us to lose.
  • API keys are stored hashed, never in plain text.
  • Webhook payloads are signed with an HMAC so your endpoint can verify they came from us, and outbound webhook URLs are screened to stop the service being pointed at internal networks.
  • Authentication attempts and public API requests are rate limited per account.

10

Your rights

Depending on where you live you may have the right to access, correct, delete, export, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Email privacy@inboundr.net and we will respond within the time your law allows.

Much of this is self-service: your data is readable through the API and console, and deleting your account removes your stored mail. If you are in the UK or EEA you also have the right to complain to your data protection authority.

If you contact us about mail we hold as a processor for one of our customers, we will point you to that customer, who controls it.

11

Children

The service is for businesses and developers and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.

12

Cookies

We use strictly necessary cookies only — principally the session cookie that keeps you signed in, which is set when you sign in and not before. Interface preferences, such as your light or dark theme, are kept in your browser's local storage and never leave your device. We do not use advertising or cross-site tracking cookies.

13

Changes to this policy

We will post any update here with a new date at the top. For changes that materially affect how we handle your personal data we will notify you by email or in the console before they take effect.

14

Contact

The controller of your account data is Lumenify Bridge LLC, a Wyoming limited liability company, of Sheridan, WY, USA.

Privacy questions and rights requests: privacy@inboundr.net.