mailstein
Product ▾

Features

Email APISMTP Service Message StreamsTransactional Email Email DeliveryEmail Templates Inbound EmailAnalytics & Retention Bulk APIBroadcastsData Privacy

mailstein for

StartupsBootstrapped Startups AgenciesEnterprise Side Projects

mailstein vs

ResendPostmark SendGridAmazon SES MailgunMandrill
Why mailstein
Resources ▾
Getting StartedEmail Guides GlossaryPricing
Pricing
Sign in
Start free →
Legal

Privacy Policy

Last updated: July 27, 2026
PrivacyTermsAcceptable Use

This policy explains what data mailstein handles, why, and for how long. We built mailstein to store as little of your message content as possible — by default, the body of an email is deleted the moment we confirm delivery. The short version is below; the detail follows.

Controller vs. processor. For your account information (name, login, billing), mailstein is the data controller. For the email content and contacts you send through us, you are the controller and mailstein is your processor — we act on your instructions to deliver mail on your behalf.

1. Information we handle

Account information

When you create an account we collect your first and last name, email address, a hashed password (we never store it in plain text), and your team name. If you sign in with a provider, we receive your basic profile from that provider.

Billing information

When paid plans launch, payments are processed by Stripe. We store a customer reference and plan status; we never see or store your full card number — Stripe handles that directly.

Email you send through us

To deliver an email we necessarily receive its recipients, subject, body (HTML/text) and attachments. What happens next is governed by your team's content-retention setting:

  • By default (delivery-driven): the body, HTML and attachments are scrubbed the instant we confirm the recipient's server accepted the message. Mail that fails to deliver is kept only so you can inspect and resend it, up to a 30-day hard cap. No message content survives 30 days.
  • Delivery metadata — recipient address, delivery status, opens/clicks (if enabled), bounce/complaint reasons and timestamps — is retained for up to 30 days so you have a record of what happened.
  • At the mail-server layer, the raw message is purged within about a day.

Contacts and audiences

If you upload contacts for broadcasts, we store them to send the mail you schedule and to honor unsubscribes and suppressions. You control this data; you can delete it at any time.

Inbound email

If you enable inbound, messages sent to your addresses are received, parsed, and made available to you (via webhook and/or the built-in inbox). They are stored so you can read them, and removed when you delete them or your account.

Technical data

Like any web service we log IP addresses, request metadata and error logs for security, abuse prevention and debugging, and we set a small number of cookies (a session cookie to keep you signed in; a site-preview cookie on the marketing site). We do not use third-party advertising trackers.

2. How we use it

  • To provide the service — deliver your email, show your logs, run broadcasts and inbound.
  • To secure the platform and prevent abuse and spam (rate limits, bounce/complaint handling, suppression).
  • To handle billing when paid plans are active.
  • To provide support and send you essential service notices.

We do not sell your data, and we do not use the content of your emails to train models or for advertising.

3. How long we keep it

DataRetention
Message body / attachments (sent)Until delivery confirmed by default (max 30 days); your setting can extend to 7 or 30 days
Delivery metadata & logsUp to 30 days
Raw message at the mail server~1 day
Account, contacts, inbound mailWhile your account is active; deleted when you delete them or close your account
Billing recordsAs required by law/accounting once paid plans exist

4. Who we share it with (subprocessors)

We use a small set of infrastructure providers to run the service:

ProviderPurposeLocation
HetznerServer hosting & databasesGermany (EU)
CloudflareDNS & networkGlobal
StripePayments (when paid plans are active)US/EU

Delivering email inherently means transmitting your message to your recipients' mail providers (Gmail, Outlook, etc.). Other than the providers above and delivery to recipients, we don't share your data — except where required by law.

5. Security

Data is encrypted in transit (TLS). Access to production systems is restricted. Our delivery-driven retention model is itself a security measure: the content we don't keep can't be exposed. No system is perfectly secure, but we work to protect your data and to minimize what we hold.

6. Your rights

Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California) you may have rights to access, correct, export or delete your personal data. mailstein gives you direct control:

  • Access & export — your logs and data are available through the dashboard and API.
  • Deletion — you can delete individual data, or permanently delete your whole account (Settings → Team → Danger zone), which removes your team, domains, mailboxes, contacts, and sent/received mail.

Because you are the controller of the email you send, requests from your recipients should be directed to you; we'll assist you as your processor.

7. International data

Our servers are located in the EU (Germany). If you access mailstein from elsewhere, your data is processed in the EU. Recipient delivery may involve mail providers in other countries.

8. Children

mailstein is a tool for businesses and developers and is not directed to children under 16. We don't knowingly collect data from children.

9. Changes

We'll update this page and the "last updated" date when this policy changes. Material changes will be communicated through the service.

10. Contact

Questions about privacy or a data request? Email privacy@mailstein.com.

mailstein
ProductPricingCompareDocsWhy mailsteinPrivacyTerms
© 2026 mailstein