This policy explains what data mailstein handles, why, and for how long. We built mailstein to store as little of your message content as possible — by default, the body of an email is deleted the moment we confirm delivery. The short version is below; the detail follows.
When you create an account we collect your first and last name, email address, a hashed password (we never store it in plain text), and your team name. If you sign in with a provider, we receive your basic profile from that provider.
When paid plans launch, payments are processed by Stripe. We store a customer reference and plan status; we never see or store your full card number — Stripe handles that directly.
To deliver an email we necessarily receive its recipients, subject, body (HTML/text) and attachments. What happens next is governed by your team's content-retention setting:
If you upload contacts for broadcasts, we store them to send the mail you schedule and to honor unsubscribes and suppressions. You control this data; you can delete it at any time.
If you enable inbound, messages sent to your addresses are received, parsed, and made available to you (via webhook and/or the built-in inbox). They are stored so you can read them, and removed when you delete them or your account.
Like any web service we log IP addresses, request metadata and error logs for security, abuse prevention and debugging, and we set a small number of cookies (a session cookie to keep you signed in; a site-preview cookie on the marketing site). We do not use third-party advertising trackers.
We do not sell your data, and we do not use the content of your emails to train models or for advertising.
| Data | Retention |
|---|---|
| Message body / attachments (sent) | Until delivery confirmed by default (max 30 days); your setting can extend to 7 or 30 days |
| Delivery metadata & logs | Up to 30 days |
| Raw message at the mail server | ~1 day |
| Account, contacts, inbound mail | While your account is active; deleted when you delete them or close your account |
| Billing records | As required by law/accounting once paid plans exist |
We use a small set of infrastructure providers to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Server hosting & databases | Germany (EU) |
| Cloudflare | DNS & network | Global |
| Stripe | Payments (when paid plans are active) | US/EU |
Delivering email inherently means transmitting your message to your recipients' mail providers (Gmail, Outlook, etc.). Other than the providers above and delivery to recipients, we don't share your data — except where required by law.
Data is encrypted in transit (TLS). Access to production systems is restricted. Our delivery-driven retention model is itself a security measure: the content we don't keep can't be exposed. No system is perfectly secure, but we work to protect your data and to minimize what we hold.
Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California) you may have rights to access, correct, export or delete your personal data. mailstein gives you direct control:
Because you are the controller of the email you send, requests from your recipients should be directed to you; we'll assist you as your processor.
Our servers are located in the EU (Germany). If you access mailstein from elsewhere, your data is processed in the EU. Recipient delivery may involve mail providers in other countries.
mailstein is a tool for businesses and developers and is not directed to children under 16. We don't knowingly collect data from children.
We'll update this page and the "last updated" date when this policy changes. Material changes will be communicated through the service.
Questions about privacy or a data request? Email privacy@mailstein.com.