Skip to content
Privacy
Trust centerSecuritySupport
Connect inbox

Privacy Notice

Version
2026-07-28
Effective
July 28, 2026
PrivacyTermsDPA
hi@supamail.dev
OperatorSupaMail is operated by Federico Altepost, a sole proprietor based in San Francisco, California.

This Notice explains how SupaMail handles personal data. SupaMail is the controller for account, billing, support, security, and website data. For mailbox content processed on a business customer's instructions, the customer is normally the controller and SupaMail is its processor under the Data Processing Addendum.

1. Data we handle

  • Account data: email address, name, authentication identifiers, and Tenant membership.
  • Billing data: Stripe customer and subscription identifiers, plan, status, quantity, and transaction metadata. SupaMail does not store full payment-card numbers.
  • Mailbox and Customer Content: mailbox address and configuration, encrypted credentials, message metadata and bodies, headers, folders, flags, attachment metadata, and attachment bytes when fetched live.
  • BYO Supabase data: project identifiers, region and status, encrypted OAuth or database credentials, and encrypted Storage access credentials.
  • Product and security data: IP address, browser and device information, auth/session cookies, requests, sync runs, errors, webhook delivery records, token metadata, and support messages.

2. Why we use it

  • provide, synchronize, search, secure, troubleshoot, and support the service;
  • authenticate users, enforce Tenant boundaries, and prevent abuse;
  • administer trials, subscriptions, payments, and customer support;
  • comply with law and establish, exercise, or defend legal claims; and
  • improve reliability using limited operational data.

The legal bases for account and website data are performance of the contract, legitimate interests in operating and securing the service, and legal obligations. Where SupaMail acts as processor, it processes Customer Content on the customer's documented instructions. SupaMail does not sell personal data or use mailbox content for advertising.

3. Where data goes

SupaMail uses these service-provider categories and subprocessors:

  • Supabase: authentication, Postgres control-plane and mirror data, and private object storage;
  • Vercel: website and stateless product surfaces;
  • Fly.io: hosted synchronization, API, MCP, and runtime services;
  • turbopuffer: tenant-isolated hosted search indexes for Managed Hosting;
  • Stripe: Checkout, subscriptions, invoices, and billing portal;
  • Rackspace: transactional authentication email delivery;
  • GitHub: optional authentication when the User chooses GitHub sign-in;
  • Google Fonts: font delivery when public or product pages load; and
  • your providers: connected mail and BYO Supabase providers as needed to perform your instructions.

SupaMail may also disclose data to professional advisers, authorities when legally required, or a successor in a merger, financing, acquisition, or sale, subject to appropriate confidentiality and notice where required.

4. International transfers

SupaMail is operated from the United States, and SupaMail and its providers may process data in the United States and other countries. Where required, SupaMail relies on adequacy decisions, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. BYO Supabase location is chosen by the customer; Managed Hosting currently uses United States infrastructure.

5. Retention and deletion

Account and Customer Content are retained while needed to provide the service. Operational sync events are normally pruned after 90 days and webhook delivery records after 30 days. Provider-deleted messages are removed from hosted body storage and search after the mirror accepts the deletion. Attachment bytes are streamed from the mail provider and are not durably stored by SupaMail. The current provider-log and backup schedule is published on the Retention and deletion page.

After closure, SupaMail retains data only as reasonably necessary for deletion, backup expiry, security, billing, legal obligations, and dispute resolution. Because automated account deletion is not yet available, request closure or deletion at hi@supamail.dev. SupaMail will confirm the applicable timeline and any data that must be retained by law.

6. Security

SupaMail uses tenant isolation, access controls, encrypted transport, encrypted stored credentials, application-layer encryption for stored message bodies, restricted service credentials, and logging designed to avoid plaintext secrets. Stored message headers and other metadata are not yet application-layer encrypted. No system is completely secure. If a breach creates a legal notification duty, SupaMail will notify affected customers or people as required.

7. Cookies

SupaMail uses essential cookies for authentication, security, OAuth state, and one-time credential display. These are required for the service. SupaMail does not currently use advertising cookies or a cross-site analytics cookie. Browser or provider settings may control other storage used by third-party sites you visit.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing, and to receive portable data. You may withdraw consent where consent is the legal basis, without affecting earlier processing. You may also complain to your local privacy or data-protection authority.

Email hi@supamail.dev to exercise a right. SupaMail may verify your identity and, when it is a processor, direct the request to the customer that controls the mailbox.

California residents may also request to know the categories and specific pieces of personal information collected, request correction or deletion, and receive equal service when exercising applicable rights. SupaMail does not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics. An authorized agent may submit a request, subject to verification of their authority and your identity.

9. Children

SupaMail is a business-oriented service and is not directed to children under 18. Do not create an account or connect a mailbox if you are under 18.

10. Changes and contact

Material changes will be posted here and, where required, notified or presented for renewed acknowledgment. Privacy questions, requests, and complaints may be sent to hi@supamail.dev.

Agency over inertia.
GitHubGuidesTrustSecurityStatusPrivacyTermsDPASupport