Privacy Policy
Last updated September 2, 2026
Two very different kinds of data pass through this service, and conflating them is the most common mistake in email platform privacy policies. This one keeps them separate throughout.
Contact data is information about the people you send to. You are the controller; we only process it on your instructions. See the Data Processing Addendum.
1Account data we collect
- Identity: your name and email address, and your password stored as a salted hash. If you sign in with Google we receive your name, email, and profile image.
- Organization: workspace name, the business or personal name and postal address you supply for email footers, and your team members.
- Billing: your Stripe customer identifier, subscription state, and invoice history. We never see or store your card number — Stripe holds it.
- Usage: emails sent, contacts stored, assistant messages used, and API request counts, for metering and abuse detection.
- Technical: IP address, browser user agent, and timestamps for sessions and audit log entries.
- Support: whatever you write to us.
2How we use account data
- To operate the service and authenticate you.
- To bill you and collect payment.
- To detect and prevent abuse, fraud, and deliverability damage.
- To send you operational email — receipts, security alerts, quota warnings, deliverability warnings, and material changes to these policies. You cannot opt out of these while you have an account, because they are necessary to the service.
- To comply with legal obligations.
Our lawful bases under GDPR are contract performance for operating and billing, legitimate interests for abuse prevention and product security, and legal obligation where a law requires the processing.
We do not sell account data, we do not share it with advertisers, and we do not run third-party advertising or analytics trackers on the application.
3Contact data
Contact data is the addresses, names, and custom fields you upload, plus the delivery events we record about them: sends, deliveries, opens, clicks, bounces, and complaints.
We process it only to deliver the mail you tell us to deliver, to record the results, to suppress people who should not be mailed again, and to detect abuse. We never use your contacts for our own marketing, never sell them, and never share them across customers.
You are responsible for having a lawful basis to hold each contact and for giving them whatever privacy notice their jurisdiction requires.
6International transfers
Our infrastructure is primarily in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with a transfer impact assessment, and on the UK Addendum where applicable.
If your AI model provider is located outside those regions, that transfer is disclosed on the sub-processor page along with its safeguard, and can be avoided entirely by disabling the assistant.
7How long we keep things
- Account data: for as long as you have an account, then 30 days after closure.
- Contact data: until you delete it, or 30 days after account closure.
- Message content: for the retention window of your plan — 7 to 180 days — then deleted.
- Delivery events: same as message content.
- Suppression records: indefinitely, and deliberately. Someone who unsubscribed must never be mailed again because a list was re-imported or an account reactivated. This is a minimal record — an address, a reason, and a date.
- Audit log and billing records: up to 7 years, where tax and anti-fraud law requires it.
8Security
- Encryption in transit with TLS, and at rest for the database.
- Passwords stored as salted hashes. API keys stored as SHA-256 digests, so a database leak yields no working credentials.
- Every query in the application is scoped to a single organization, and each customer's sending is isolated in its own upstream tenant so one account's reputation cannot affect another's.
- Access to production data is limited to personnel who need it and is logged.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you without undue delay, and within 72 hours where GDPR requires it.
9Your rights
Depending on where you live you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent.
For account data, write to privacy@www.sendkernel.com and we will respond within 30 days.
For contact data, we are the processor and cannot act on a request without our customer's instruction. If you received mail sent through this platform and want your data removed, use the unsubscribe link — it suppresses you across the sender's entire account immediately — and contact the sender directly. If they do not respond, write to us and we will forward it.
If you are in the EEA or UK you may complain to your supervisory authority. We would rather you told us first.
10Children
The service is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, tell us and we will delete it.
11Changes and contact
We will post any update here and change the date at the top. For material changes we give at least 30 days' notice by email.
Privacy questions: privacy@www.sendkernel.com