Privacy Policy
1. Who We Are
This page explains how we collect, use, disclose, retain, and protect personal data when you use DevMail.
Depending on the processing context and the people affected, this notice may be relevant under the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
DevMail applies GDPR-aligned privacy and security controls as a baseline standard across the service, not only where the GDPR legally applies.
DevMail is built for development and QA inbox testing. It is not intended for sensitive, personal, or production communications.
2. What Data We Process
- Account data, such as your login email, password hash, plan, retention settings, and account timestamps.
- Mailbox data, such as generated inbox addresses, received email content, headers, sender/recipient metadata, timestamps, attachment metadata, and retained attachment files. Stored email content and attachments are encrypted at rest as part of our technical and organizational security measures.
- Security and technical data, such as session and authentication records, API-key metadata, limited request and device data, essential cookies, anti-abuse records, and short-lived logs.
- Billing, support, and compliance data, such as subscription status, external billing references, support or privacy request records, and records needed for accounting, security, or legal compliance.
Payment card details are handled by payment providers and are not stored by DevMail.
We use only essential cookies needed for sign-in, security, and remembering the cookie notice. We do not use advertising cookies, third-party analytics cookies, or behavioral tracking cookies.
3. Where It Comes From
We receive personal data from three main sources.
- Directly from you when you create an account, sign in, change settings, buy a paid plan, contact us, or make a privacy request.
- Automatically from your browser, device, and use of the service, including session cookies, request metadata, and security or anti-abuse signals.
- Indirectly from emails sent to generated inboxes by third-party senders or sending systems, including sender and recipient metadata, headers, message content, and attachments.
To create and use an account, you must provide the account data needed for sign-up and authentication. For paid plans, you must also provide the checkout and billing data required to complete the purchase and renewal flow.
4. Why We Use It and Legal Bases
We process personal data only as needed to run, secure, and support DevMail.
- To provide account creation, authentication, inbox access, message retrieval, retention settings, account deletion, billing, and support. Our main legal basis for this is contract or steps taken before entering into a contract.
- To secure the service, prevent abuse, investigate incidents, enforce rate limits, maintain recovery copies, and troubleshoot reliability issues. Our main legal basis for this is our legitimate interests in operating a safe and reliable service.
- To comply with legal obligations, respond to valid legal requests, keep records required by law, and protect or enforce our legal rights. Our legal bases for this are legal obligations and, where appropriate, legitimate interests.
- If we rely on consent for a specific feature or communication, we will say so at that time. Most core DevMail processing is not based on consent.
If you do not provide the required account or billing data, we may not be able to create your account, authenticate you, or complete paid-plan purchase and renewal flows.
5. Who We Share It With and International Transfers
We share personal data only when needed to run the service, support users, or comply with law.
- Email delivery providers for transactional account emails.
- Billing and payment providers for checkout, subscriptions, renewals, and cancellations.
- Logging, monitoring, and support providers.
- Infrastructure and storage providers that help us deliver the service and maintain short-lived disaster-recovery backups.
- Professional advisers, authorities, or other parties where disclosure is required by law.
Some providers may process personal data outside the EEA, including in the United States, depending on service configuration and provider infrastructure.
Where cross-border transfer rules apply, we use the lawful transfer basis or safeguard required by the applicable law. You can contact us for more information about the transfer basis relevant to your request.
6. How Long We Keep It
Mailbox content and attachments follow the plan-based retention setting. Free accounts are retained for 7 days. Pro accounts default to 7 days and can use any whole-day period from 1 through 21 days.
Account profile data is generally kept until account deletion, unless some data is removed earlier for operational reasons such as stale unverified-account cleanup.
Free-account profile, mailbox, generated inbox, and API access data may also be deleted earlier if a free account remains inactive for 60 consecutive days, measured from the last successful login or API-key use. We may try to notify you before deletion, but advance notice is not guaranteed.
Authentication, session, verification, rate-limit, and similar anti-abuse records are kept only for short-lived operational periods.
Billing, support, privacy-request, accounting, compliance, and legal records are kept as long as reasonably needed for those purposes.
Short-lived disaster-recovery backups may temporarily contain deleted or expired data until the rolling backup set rotates out.
You can request immediate account deletion from the in-app Danger Zone. This removes your local account profile, generated inbox identity, mailbox emails, and API-key records from active systems and ordinary retention stores. For active paid subscriptions, deletion may be blocked until cancellation is confirmed.
You should not treat DevMail as an archive or system of record.
7. Your Rights and California Notices
Depending on your location and the applicable law, you may have rights of access, correction, erasure, restriction, objection, portability, and complaint. You may also ask how your personal data is processed.
DevMail offers a self-service JSON export of currently retained account and mailbox data from the Privacy & Data settings page. This export is not a historical archive. It includes account details, plan and retention settings, mailbox usage, retained messages, attachment metadata only, billing subscription summary, and API-key metadata. It does not include secrets, internal-only records, attachment binaries, or data already deleted by retention or account actions.
If your personal data appears in an email sent to a generated inbox and you are not the account holder, you can still contact us and we will assess the request under the applicable law. We may need to verify identity before fulfilling a request, and we may limit or refuse a request where permitted by law.
California residents can also contact us to exercise rights to know, access, correct, delete, and receive a portable copy of personal information, subject to legal exceptions. We will not discriminate against you for exercising applicable privacy rights.
For the last 12 months, our California notice is as follows: we collected identifiers, account records, mailbox content, attachment metadata, internet or network activity information, billing records, and support or compliance records; we collected them from you directly, from your use of the service, from billing and support interactions, and indirectly from emails sent to generated inboxes; we used them to provide and secure the service, process billing, support users, comply with law, and protect our rights; and we disclosed them for business purposes to email delivery, billing/payment, logging/monitoring, infrastructure/storage, and legal or regulatory recipients.
DevMail does not sell personal information and does not share personal information for cross-context behavioral advertising.
8. Security, Changes, and Contact
We use reasonable technical and organizational measures to protect personal data, but no system can be guaranteed 100% secure.
Stored email content and attachments are encrypted at rest as part of our technical and organizational security measures. This helps us protect personal data and strengthen the security of the service.
If we become aware of a personal data breach affecting DevMail data, we will document it, assess notification duties, and notify authorities or affected individuals where required by the applicable law, including under the GDPR where relevant.
We may update this Privacy Policy from time to time. If we make a material change, we will update the date at the top of this page.
Legal entity details
You can contact us at [email protected] with privacy questions or requests. You can also use this contact point to exercise applicable data protection rights. Depending on your location, you may also have the right to lodge a complaint with a competent data protection authority.
This page is for product policy transparency and is not legal advice.