Privacy Policy
What data flows through MailOps, why, and for how long.
Last updated: September 24, 2026
1.Data we process
As an email relay, MailOps processes:
- Message data — sender/recipient addresses, subject, headers and body, transiently for delivery
- Event data — delivery, bounce, open, click and complaint events from vendor webhooks
- Account data — operator names, email addresses, roles and audit-log entries
- Audience data — contact lists, segments and engagement scores uploaded by you
2.How we use it
Message and event data is used solely to deliver mail, diagnose failures (including LLM-assisted bounce diagnosis), maintain suppression lists, and produce the analytics shown in the console. We do not sell data, use it for advertising, or read message content for any purpose unrelated to delivery and abuse prevention.
3.Retention
| Data | Retention |
|---|---|
| Message bodies | Transient — discarded after delivery (max 72 h in retry queue) |
| Message metadata & events | 90 days, then aggregated |
| Suppression list | Indefinite (required to honor opt-outs) |
| Audit log | 12 months |
| API token metadata | Life of the token + 30 days |
4.Vendors & subprocessors
Mail is delivered through the vendors you configure — SendGrid, AWS SES and/or Scaleway TEM — each bound by a data-processing agreement. LLM diagnosis runs against redacted bounce metadata; message bodies are never sent to the model provider.
5.Security
Credentials are stored KMS-encrypted; API tokens are hashed and shown once at creation. Transport is TLS-only, access is role-based, and every human admin action is recorded in the audit log.
6.Your rights
If MailOps processes personal data about you, you may request access, correction, export or erasure — see the GDPR page for how to exercise these rights.