01What this policy covers
This policy explains what MailFleet collects, why, and what you can do about it. It applies to the MailFleet application and website. In short: you own your data, we process it to run your outreach, and we never sell it.
02Information we collect
- Account details — your name, work email, password hash, workspace name and timezone.
- Connected mailboxes — OAuth tokens (never your mailbox password), IMAP/SMTP settings you provide, and the message content and metadata needed to send campaigns, detect replies and run warmup.
- Lead data you import — names, email addresses and custom fields in the lists you upload or paste.
- Usage and device data — pages viewed, actions taken, browser and IP, used for security and product improvement.
- Billing — handled by our payment processor; we never store card numbers.
03How we use it
- To run the service: sending sequences, pausing on replies, routing answers to your queue.
- To operate the warmup network and compute sender-health and deliverability analytics.
- To secure accounts, prevent abuse of shared sending infrastructure, and enforce our anti-spam rules.
- To support you and improve the product.
We do not sell personal data, serve ads, or use your email content to train advertising or general-purpose AI models.
04Your leads and email content
Lead lists and the emails you send are your data. We process them only on your instructions, as a processor, to deliver the service. Unsubscribes and bounces are added to your suppression list so they are never contacted again from your workspace.
05The warmup network
Warmup works by exchanging automated messages between consenting member mailboxes. These messages are machine-generated, archived out of sight in each inbox, and never contain marketing or personal lead data.
06When we share
Only with subprocessors that run the service — cloud hosting, email infrastructure, payment processing and product analytics — under data-processing agreements, and with authorities when the law requires it. A current subprocessor list is available on request at hello@mailfleet.co.
07Retention
- Mailbox tokens are deleted immediately when you disconnect a sender; its warmup history is kept 30 days, then erased.
- Lead data and campaign history live for the life of your workspace and are deleted 30 days after you close it.
- Encrypted backups roll off within 35 days.
08Security
Data is encrypted in transit and at rest. Mailbox access uses OAuth wherever the provider supports it, credentials are stored in a dedicated secrets store, and internal access follows least-privilege. Report security issues to hello@mailfleet.co — we respond within one business day.
09Your rights
Depending on where you live (including under GDPR and CCPA), you can access, correct, export, delete, or object to the processing of your personal data. Email hello@mailfleet.co and we will act within 30 days. People who receive your emails can also contact us to have their address suppressed across the workspace that emailed them.
10Cookies & international transfers
We use essential cookies for sign-in and a first-party analytics cookie — no advertising trackers. Where data crosses borders, transfers rely on Standard Contractual Clauses.
11Children & changes
MailFleet is a work tool and not intended for anyone under 16. If this policy changes materially, we email every workspace owner at least 14 days before the change takes effect.