Privacy Policy

Last updated: [DATE]

Short version: we read your new emails only to pick a category, using open-weight AI models we host ourselves. Email content is processed in memory and never stored. We keep sender, subject, category and confidence for 30 days so you can see what happened. We never send or delete your email, and we don't sell data.

1. Who we are (data controller)

MailTag is operated by [YOUR LEGAL NAME / COMPANY], [POSTAL ADDRESS], [COUNTRY], which is the data controller for personal data processed through mailtag.app. Contact: support@mailtag.app. [EU/UK REPRESENTATIVE OR DPO, IF REQUIRED]

2. What we collect

3. How we use it and our lawful basis (GDPR Art. 6)

Emails in your mailbox may contain personal data of third parties (your correspondents). We process that data only on your instructions and only to classify the message; for that processing you act as controller and we act as your processor. [OPTIONAL: LINK TO DATA PROCESSING AGREEMENT]

4. AI processing

Classification runs on open-weight language models hosted on our own infrastructure. Your email is not sent to OpenAI, Google, Anthropic or any other third-party AI provider, and it is not used to train models. Classification is automated but produces only a label in your own mailbox; it has no legal or similarly significant effect on you.

5. What we never do

6. Subprocessors

We share data only with providers needed to run the Service:

Webhook destinations (e.g. Slack, Discord, Zapier, Make, n8n) are chosen and configured by you; data you route there is governed by those services' policies.

7. International transfers

Where personal data is transferred outside the EEA/UK (for example to Stripe in the United States), we rely on adequacy decisions or Standard Contractual Clauses as appropriate.

8. Retention

9. Account deletion

You can delete your account at any time from your account settings. When you do, we delete your account data, stored mailbox credentials, categories, webhooks, API keys and activity log without undue delay [e.g. within 30 days, including backups], except billing records we must keep by law. Your emails and any labels already applied remain in your mailbox. You can also revoke our access at any time by deleting the app password in your email provider's settings.

10. Security

App passwords are encrypted at rest with AES-256-GCM, all traffic uses TLS, and webhook deliveries are signed with HMAC-SHA256. Access to production systems is restricted to the operator.

11. Your rights

Depending on where you live (including under the GDPR and UK GDPR), you have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent at any time. To exercise these rights, email support@mailtag.app; we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority [e.g. NAME OF YOUR LEAD SUPERVISORY AUTHORITY].

12. Cookies

We use only strictly necessary cookies to keep you logged in and protect forms against CSRF. We don't use advertising or third-party tracking cookies. [UPDATE IF YOU ADD ANALYTICS]

13. Children

The Service is not intended for anyone under 16, and we do not knowingly collect their data.

14. Changes

We will post any changes on this page and update the date above. For material changes we will notify you by email before they take effect.

15. Contact

[YOUR LEGAL NAME / COMPANY]
[POSTAL ADDRESS], [COUNTRY]
Email: support@mailtag.app