Privacy Policy
Last updated: September 7, 2026
Table of Contents
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Password (stored as bcrypt hash)
AWS Credentials
When you configure AWS SES integration, we store:
- AWS Access Key ID (encrypted)
- AWS Secret Access Key (encrypted)
- AWS Region
These credentials are encrypted at rest using AES-256 and are only used to access AWS SES APIs.
Email Data
We receive and store email metadata from SES webhooks:
- Message IDs
- Recipient addresses (hashed for privacy)
- Delivery status (delivered, bounced, complained)
- Bounce and complaint types
- Timestamps
We do NOT store email content. Only metadata is retained.
Usage Data
We collect anonymized usage data to improve our service:
- Pages visited
- Features used
- Browser type and version
- Device type
2. How We Use Your Information
We use collected information for:
- Providing the service: Monitoring your email deliverability, generating reports, and sending alerts
- Authentication: Verifying your identity and securing your account
- Communication: Sending service-related emails (alerts, reports, account notifications)
- Improvement: Analyzing usage patterns to improve MailPulse
- Support: Responding to your support requests
- Billing: Processing payments for paid plans
3. Data Storage and Security
We implement industry-standard security measures:
- Encryption at rest: AES-256 for sensitive data
- Encryption in transit: TLS 1.3 for all communications
- Access control: Role-based access with audit logging
- Infrastructure: Isolated Docker containers with minimal attack surface
- Network: Ports bound to localhost, Cloudflare WAF protection
Data is stored in secure data centers with 24/7 monitoring and physical security controls.
4. Data Sharing
We do NOT sell your data. We share information only in these limited cases:
- Service providers: Trusted third parties that help us operate (hosting, payment processing)
- Legal requirements: When required by law or to protect our rights
- Business transfers: In connection with a merger or acquisition (with notice to you)
All service providers are contractually obligated to protect your data and use it only for the purposes we specify.
6. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Deletion: Request deletion of your data
- Portability: Export your data in machine-readable format
- Objection: Object to processing of your data
- Restriction: Request restricted processing
To exercise these rights, contact us at [email protected].
We will respond to your request within 30 days.
7. Data Retention
We retain data based on your plan:
- Free plan: 7 days of email metadata
- Starter plan: 90 days of email metadata
- Pro plan: 1 year of email metadata
AWS credentials are retained until you delete them. Account information is retained until you delete your account.
When you delete your account, we permanently delete all your data within 30 days.
8. Children's Privacy
MailPulse is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or prominent notice on our website. Continued use of MailPulse after changes constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related inquiries:
- Email: [email protected]
- Twitter: @mailpulse
For GDPR requests, please include "GDPR Request" in your subject line.