Security and compliance
We keep as little of your data as we can. We store send metadata for 45 days, and we never store email bodies.
What we store, and for how long
| Data | Stored | Retention |
|---|---|---|
| Send metadata (time, template, sender profile, recipient, status, error code) | Yes | 45 days |
| Rendered email bodies | No | Never stored |
| Suppression list (hard bounces, complaints) | Yes | While you're a customer |
| Sender profiles and domain settings | Yes | While you're a customer |
| HubSpot OAuth tokens | Yes, encrypted | Until you uninstall |
When you uninstall, we email your admins, cancel the subscription, and delete your sending setup and data 14 days after cancellation. Reinstall inside that window and everything comes back.
Isolation between customers
Each HubSpot portal sends from its own isolated tenant. We track bounces, complaints, and reputation per portal. If one customer's sending goes bad, their tenant gets paused, not everyone else's.
Your domain, authenticated
Live sending stays locked until your sending domain passes DKIM, SPF, and DMARC checks. Mail goes out signed for your domain, so recipients' mail servers can confirm it came from you.
Where data lives
Data is processed and stored in the United States on Amazon Web Services.
Subprocessors
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Hosting, email delivery (Amazon SES), and AI template review (Amazon Bedrock) |
| Stripe | Billing |
| HubSpot | The platform the app runs on |
| PostHog | Error tracking |
Acceptable use
The app is for transactional messages only. You accept our Acceptable Use Policy before going live, and every template gets an AI review before it sends. We block promotional content, and we can suspend accounts that abuse the service. It's how we keep mail landing in the inbox for everyone.
Data Processing Agreement
A DPA is available on request. Contact us
[LEGAL REVIEW: confirm retention terms, subprocessor list, and DPA availability before publishing]