Plain-language privacy.
Effective .
Ask an assistant to explain it
Get a short, plain-language summary of this page.
What this policy covers
This is our privacy policy. It explains what data we collect and why. We keep it in plain English. No legal jargon unless the law requires it. If you have questions, just email us.
Who we are
Mails.ai (“we”, “us”) operates the agent-native email infrastructure described on this site. Contact: support@mails.ai. For security disclosures see /security.
What we collect
- Account data. The email address you sign up with, workspace slug + display name, billing identity (handled by Stripe).
- Message data. Email you send through your agents and email your agents receive: headers, addresses, subject, body content, extracted reply text, attachments metadata. Stored against your workspace_id; not shared with other customers.
- Classifier output. Typed-event fields derived from inbound messages (intent, entities, urgency, injection_score, sender_reputation). Stored with the inbound message; not shared with other customers.
- Operational logs. Audit-log rows for every API call (API-key prefix, action, target, timestamp, IP, user-agent), webhook delivery attempts, billing meter increments. Standard server access logs on public surfaces (Hetzner for this site, Vercel for the dashboard and the API).
We run product analytics on this site: Google Analytics, PostHog and our own analytics server for traffic, and Grain for heatmaps and session recordings, so we can see where people get stuck. PostHog’s recordings mask all text and inputs. We run no cross-site advertising pixels and no retargeting.
If you are in the EEA, the UK or Switzerland we ask before any of it loads, and nothing is fetched unless you accept. Elsewhere it is on by default and you can switch it off below — that setting is remembered, and turning it off also deletes what Grain and PostHog had stored. If your browser sends a Global Privacy Control signal we treat that as off everywhere and never ask. The /signup form collects only the email you type.
Two services on this site load for every visitor, wherever you are: Gleap’s support chat and Better Stack’s status pill in the footer. Videos come from YouTube in privacy-enhanced mode and load only once you press play, and blog posts with diagrams load the diagram library from jsDelivr.
In the dashboard, PostHog records how the product is used, with all text and inputs masked in its session recordings, and knows your user ID and email; our own analytics server records page views, your account email and billing events; Sentry receives error reports from your browser, with a masked replay of the moments before an error; and Gleap runs support chat and product updates. These run for every signed-in user and do not ask first.
Why we collect it (lawful basis)
- Contract performance (GDPR Art. 6(1)(b)). Account, message, and billing data — we can’t send your email or charge you without them.
- Legitimate interest (GDPR Art. 6(1)(f)). Operational logs for security, abuse prevention, deliverability protection. Classifier inference to label inbound for your agent.
- Legal obligation (GDPR Art. 6(1)(c)). Tax records (Stripe), abuse reports, lawful requests from competent authorities.
Retention
Active-account data is retained for as long as the account is active. Audit-log rows: target 90 days for Free/Pro, 1 year for Scale; long-term archival is on the Phase 2 roadmap, so retention is currently bounded by database size, not policy. Stripe billing data follows Stripe’s retention. Classifier requests go to OpenAI with its storage setting off, so it keeps no response for later retrieval; it keeps abuse-monitoring logs, which can include the request, for up to 30 days, and does not train on API data by default (see /sub-processors).
On account closure or erasure request: workspace + message data is deleted within 30 days, with a cryptographic audit trail of the deletion. Anonymized aggregate data (cost-per-call, classifier accuracy) may be retained beyond this for operational analytics.
Sub-processors
We use third-party vendors to operate the service. Each receives only the data needed for its purpose. Each vendor’s name, purpose, data category, region (where a source names one) and added-at date are at /sub-processors. We publish a changelog entry tagged sub-processors whenever a vendor is added, removed, or its scope changes.
Your rights (GDPR Art. 15–22)
You can request, at any time:
- Access (Art. 15). A copy of the personal data we hold about you.
- Rectification (Art. 16). Correction of inaccurate or incomplete data (most fields are self-serve from the dashboard).
- Erasure (Art. 17). Deletion of your account and associated data. Self-serve: sign in, open Settings → Danger zone, and delete a workspace or your whole account — it is erased at once and you get a deletion receipt. Or email support@mails.ai and we close out within 30 days.
- Portability (Art. 20). Machine-readable export of your messages, events, agents, and audit-log rows. Self-serve at Phase 1 launch.
- Restrict / object (Art. 18, 21). Email us; we’ll honor the request unless we have an overriding legitimate interest (e.g., we’re investigating an abuse report against the account).
No fee for a first request in any 12-month period. We respond within 30 days (extendable by 60 days for complex or repetitive requests, per Art. 12(3)). You also have the right to lodge a complaint with your supervisory authority.
Cookies + tracking
The dashboard sets a single HttpOnly + Secure session cookie (mails_session) required to keep you signed in. That one is necessary for the service and is not optional. PostHog, which runs in the dashboard for every signed-in user, keeps a cookie and local-storage entries of its own.
On this site, the analytics follow the rule under What we collect: we ask first in the EEA, the UK and Switzerland, and everywhere else they are on until you switch them off. Google Analytics sets two first-party cookies (_ga and _ga_ with its property ID), PostHog keeps a cookie and local-storage entries, and Grain and our own analytics server keep an identifier in your browser’s local storage. Switching them off stops all four and deletes what Grain and PostHog had stored; the Google Analytics cookies and our analytics server’s identifier stay until you clear your browser’s data. No advertising or retargeting pixels anywhere.
International transfers
Many of our sub-processors are in the United States. Where required, transfers from the EEA / UK rely on the European Commission’s Standard Contractual Clauses (and the UK IDTA) as the legal mechanism — flag this in your DPA request and we’ll provide our SCC-aligned addendum.
Children
Mails.ai is a developer infrastructure product. It is not directed at children under 16 and we don’t knowingly collect data from them. If you believe a minor has signed up, email support@mails.ai and we’ll close the account.
Security
Posture summary at /trust. Vulnerability disclosure at /security. We notify affected customers of any confirmed personal-data breach without undue delay (Art. 33 / 34).
Changes
Material changes ship a /changelog entry and update the “Effective” date above. Non-material edits (typos, restructuring without scope change) ship silently.
Contact / DPO
Email support@mails.ai for any DSR, DPA, or privacy-related question. Legal entity details are available on request. A dedicated DPO email + Article 27 EU representative are scoped for Phase 2 once headcount supports a separate role.
What to read next.
The vendors that handle data are on the sub-processors list. Our security posture is on the Trust page, and the terms for using mails.ai, in plain English, are in the terms of service.