Privacy and Security
How we protect your data, what we store, and your privacy rights.
Privacy and Security
Your privacy and security are our top priorities. Here's how we protect your data:
What We Store
ā We DO Store:
- Account information: Email, display name, password (encrypted)
- Usage metadata: Generation count, timestamps, subscription status
- Anonymized analytics: Usage patterns (no personal data)
- Payment information: Stored securely by Stripe (we never see your card details)
- Full email content: Your generated emails are not permanently stored
- Email recipients: We don't know who you're emailing
- Previous email threads: Pasted context is used only for generation, then discarded
- Credit card details: Handled entirely by Stripe
- That you generated an email (timestamp)
- How many generations you've used
- Your subscription status
- In transit: All data encrypted with TLS/SSL (HTTPS)
- At rest: Database encrypted at rest
- Passwords: Hashed and salted (we can't see your password)
- Hosting: Firebase (Google Cloud Platform)
- Payments: Stripe (PCI-compliant)
- API calls: OpenAI (SOC 2 compliant)
- What we send: Your prompt and context
- What they do: Generate the email
- What they keep: Subject to OpenAI's privacy policy
- Your control: See OpenAI's data usage policies
- What we send: Email, subscription plan
- What they do: Process payments securely
- What they keep: Payment details (we never see card numbers)
- What we send: Anonymized usage events
- What they do: Aggregate usage analytics
- What they don't get: Email content, personal identifiable info
- Contact support
- We'll send your data within 7 days
- Account information
- Usage statistics
- Subscription history
- Right to access your data
- Right to delete your data
- Right to data portability
- Right to be forgotten
- Sessions expire after 30 days of inactivity
- You can manually log out anytime
- Password resets invalidate all active sessions
- Minimum 8 characters
- No specific complexity requirements (but strong passwords recommended)
- Reset available anytime via email
- Email verification
- Password resets
- Subscription confirmations
- Monthly invoices
- Sell your email to third parties
- Send marketing emails without permission
- Share your email with partners
- Email verification (required for account security)
- Password resets (user-initiated)
- Billing notifications (required for subscription management)
- Product updates
- Feature announcements
- Marketing emails
- Publicly disclose before we've fixed it
- Test the vulnerability on production systems
- Access other users' data
- Read our full Privacy Policy
- Review our Terms of Service
- Contact support with specific questions
ā We DO NOT Store:
How Your Data is Used
During Generation
1. You submit a prompt 2. It's sent securely to OpenAI's API 3. AI generates the email 4. Email is displayed to you 5. Content is discarded (not permanently stored)
What We Keep
Why? For billing accuracy and usage limits only.
Data Security
Encryption
Infrastructure
All vendors are industry leaders in security.
Third-Party Services
We share minimal data with:
OpenAI (AI Generation)
Stripe (Payments)
Mixpanel (Analytics)
Your Privacy Rights
Access Your Data
Request a copy of all data we have about you:
Delete Your Data
Delete your account and all associated data: 1. Go to Settings ā Account ā Delete Account 2. Confirm deletion 3. All data is permanently deleted within 30 days
Export Your Data
Currently, we don't store your full email content, so there's minimal data to export. You can request:
GDPR Compliance
We comply with GDPR for all users (not just EU):
Session Security
Login Sessions
Password Requirements
Email Security
Account Emails
We send transactional emails only:
We never:
Unsubscribe
You can't unsubscribe from:
You can unsubscribe from:
Reporting Security Issues
Found a security vulnerability?
Please report responsibly: 1. Contact us immediately 2. Use subject line: "Security Issue" 3. Include details of the vulnerability 4. We'll respond within 24 hours
Do not:
Questions About Privacy?
Was this article helpful?