Privacy Policy
What personal data Mailfully handles, why, for how long, and who else touches it. Written to be read, not to be impenetrable.
Last updated July 29, 2026.
Who we are
Mailfully is a transactional email API operated by Even Flow Solutions LLC, a New York limited liability company (“Mailfully,” “we,” “us”).
For privacy questions, or to exercise any right described below, write to [email protected]. We answer every request from a human.
Two different roles, and why it matters
Mailfully handles personal data in two distinct capacities, and your rights differ depending on which applies.
As a controller — your account
For the data about you and your team as our customer — your name, email address, organization, sign-in credentials, and billing details — we decide how that data is used, and this policy governs it directly.
As a processor — the messages you send
For the personal data inside the emails you send through us — recipient addresses, subject lines, message bodies, attachments — you are the controller and we are your processor. We handle that data only to deliver your mail and operate the service, on your instructions. If you are a recipient of a message sent through Mailfully and want your data corrected or erased, contact the sender: they control that data, not us. We will assist them in responding.
What we handle
Account and authentication data
Your name, email address, and organization name. If you sign in with GitHub or Google, we receive the profile identifier and email address from that provider. If you use a password, we store only a scrypt hash of it — never the password itself. Sign-in links and password-reset tokens are stored hashed and are single-use.
Billing data
Your plan, subscription status, and metered usage. Payment card details go directly to Stripe and are never stored on our systems; we retain only Stripe's customer identifier and the records needed to invoice you and meet tax and accounting obligations.
Message data
For each message you send we store the sender address, recipient addresses (to, cc, bcc, reply-to), subject line, HTML and plain-text bodies, custom headers, tags, attachment metadata, and the recipient domain. This is what makes the per-message debug log useful — you can see exactly what was sent. It also means message content lives in our database for the length of your plan's retention window.
Delivery and reputation data
Delivery, bounce, complaint, and rejection events returned by the sending infrastructure, along with the provider's message identifier. Bounces and complaints add the affected address to your suppression list so we do not mail it again. We also compute aggregate reputation signals per sending domain and account.
Content scanning
Outbound messages are scored for abuse indicators, and a message may be quarantined if it looks like phishing, malware, or fraud. We retain the score and the action taken. This protects recipients and the shared sending reputation every customer depends on.
Technical data
IP addresses, timestamps, API key identifiers, and request metadata for the API and dashboard, used for security, rate limiting, abuse prevention, and debugging.
Website analytics
mailfully.com uses Plausible Analytics, which is cookieless and collects aggregate page views. We do not run advertising trackers, we do not build behavioral profiles, and we do not sell data to anyone.
Why we handle it
- To deliver the email you ask us to send — the core purpose, and the basis for handling message data.
- To operate your account: authentication, team access, dashboard reads, and support.
- To bill you accurately, including metered overage, and to meet tax obligations.
- To keep the platform safe: rate limiting, fraud scoring at signup, abuse detection, and suppression handling.
- To protect deliverability for every customer through reputation monitoring.
- To comply with law and respond to lawful requests.
Where the GDPR applies, our legal bases are performance of a contract (operating the service you signed up for), legitimate interests (security, abuse prevention, deliverability), and legal obligation (tax, accounting, lawful requests). We do not rely on consent for the core service, and we do not use your data or your recipients' data to train machine-learning models.
How long we keep it
Message content and logs are retained for your plan's retention window — 30 days on Free and Starter, 60 days on Growth, 90 days on Scale — after which message content ages out of the readable log.
Suppression lists outlive that window by design. An address that hard-bounced or filed a complaint has to stay suppressed to stop us mailing it again; discarding the record would defeat its purpose and harm the recipient.
Account and billing records are kept for the life of your account and afterward only as long as tax, accounting, and legal-defense obligations require.
Aggregate reputation and usage statistics may be retained in aggregated form that no longer identifies individual recipients.
Subprocessors
We use the following third parties to run the service. Each is bound by contractual confidentiality and data-protection obligations, and each receives only what its function requires.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Email delivery (SES), application hosting, database and cache storage, object storage, logging | Message content and recipients, account data, delivery events, application logs |
| Stripe | Payment processing, subscription billing, tax calculation | Billing contact details, payment method (held by Stripe, never by us), subscription and usage records |
| IPQualityScore | Fraud and abuse scoring at signup | Signup email address |
| Cloudflare | DNS and static site hosting for mailfully.com | Website request metadata, including IP address |
| Plausible Analytics | Aggregate website analytics for mailfully.com | Cookieless, aggregated page-view data. No cross-site tracking and no advertising profiles. |
We will give notice before adding a subprocessor that handles customer message data, so you have a chance to object. Beyond these, we disclose data only when law requires it, to protect rights and safety, or in connection with a merger or acquisition — in which case the acquirer is bound by terms no less protective than these.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
Security
Data is encrypted in transit and at rest. Access follows least-privilege principles, API credentials are stored only as hashes with a lookup prefix (never the secret), and tenant data is isolated at the query layer so a request can only ever read its own organization's records. We log administrative access and maintain a documented incident-response process. No system is perfectly secure, but we treat this as a first-order engineering concern rather than a compliance checkbox.
International transfers and residency
Our default infrastructure runs in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses, and our Data Processing Addendum covers the required processor obligations. Customers who need data to remain in the EU can run on our EU region, where sending infrastructure and message-log storage stay in an EU region — write to us to provision one.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to object to or restrict certain processing; and to withdraw consent where we rely on it. Residents of California and other US states with comprehensive privacy laws have rights of access, deletion, correction, and portability, plus the right not to be discriminated against for exercising them.
Email [email protected] to exercise any of these. We verify the request, respond within the timeframe the applicable law requires, and will not charge you or degrade your service for asking. If you are in the EEA or UK you may also complain to your local supervisory authority.
Much of this is also self-service: you can export your message logs and suppression lists from the dashboard, edit your account details, and delete your organization, which removes its message data.
Children
Mailfully is a developer tool sold to businesses. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, write to [email protected] and we will delete it.
Changes to this policy
We will update this page when our practices change and revise the date above. For material changes that affect how we handle your data, we will notify account owners by email rather than relying on you to notice a quiet edit.
Contact
Privacy questions and data-subject requests: [email protected]. Security reports: [email protected]. Abuse reports: [email protected].
Even Flow Solutions LLC, New York, United States.