Privacy Policy

Last updated: June 1, 2025

1. Who We Are

WebMail ("we", "us") operates the transactional email platform at webmail.io. Our registered address is 123 Main Street, Suite 100, San Francisco, CA 94105, United States.

2. Data We Collect

  • Account data — email address, password hash, billing information.
  • Message data — from/to addresses, subject, body, send status.
  • Event data — open timestamps, clicked URLs, IP addresses (hashed after 30 days).
  • Usage data — API request logs, error traces, rate-limit counters.
  • Cookies — see our Cookie Policy.

3. How We Use Your Data

  • To provide and improve the Service;
  • To detect and prevent abuse and fraud;
  • To send transactional notices (password resets, billing receipts);
  • To comply with legal obligations.

We do not sell your personal data to third parties.

4. Data Retention

Message bodies are stored for the duration of your plan's history window (7 / 30 / 90 days). Account data is retained for 30 days after deletion, then permanently erased.

5. Third-Party Processors

  • AWS — email relay (SES) and infrastructure.
  • Stripe / Paddle — payment processing.
  • Sentry — error monitoring (no PII in traces).

6. Your Rights (GDPR / CCPA)

You may have the right to access, correct, delete, or export personal data we hold. Submit a request to privacy@webmail.io and we will respond within 30 days.

7. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). API keys are stored as SHA-256 hashes; raw values are never logged.

8. Contact

Privacy inquiries: privacy@webmail.io.

Terms of Service Cookie Policy