MepMail

Privacy Policy

Last updated: September 28, 2026

This policy explains what data MepMail collects, how it is used, and the choices you have. We keep it short on purpose: collect little, encrypt the sensitive parts, and name our subprocessors.

1. In short

  • We collect the data needed to run your account and billing — nothing more.
  • Email content you send is encrypted at rest and is processed only to deliver your messages. We do not read it, sell it or use it to train anything.
  • Payments run on Stripe; we never see or store your card number.
  • We work with a short list of infrastructure providers, named below.
  • You can export or delete your data at any time.

2. Data we collect

  • Account: name, email address, password (stored as a hash), team membership.
  • Billing: plan, payment status and invoice references. Card data goes directly to Stripe.
  • Sending data: sending domains, contacts you upload, suppressions, and message metadata (recipient, subject, status, events).
  • Message content: the HTML/text you send, stored encrypted at rest, processed to deliver the message.
  • Technical data: IP address, user agent, session cookies and application logs.

3. How we use data

  • To provide the service: authenticate you, send your email through Amazon SES, show delivery events, enforce quotas.
  • To bill you and handle refunds.
  • To secure the service: detect abuse, spam and unauthorized access, and comply with legal obligations.
  • To communicate with you about your account or material service changes.

4. Legal bases

Where the GDPR applies, we process data to perform our contract with you (running the service), on the basis of our legitimate interest (security and abuse prevention), to comply with legal obligations (billing records), and with your consent where required (non-essential cookies). Under Brazil's LGPD, the corresponding bases apply.

5. Subprocessors

We use a deliberately short list of providers to run the service:

  • Amazon Web Services (Amazon SES) — email delivery and event notifications. Message content and metadata pass through it for delivery.
  • Stripe — payment processing, invoices and receipts.
  • Cloudflare — DNS, CDN and network protection in front of our servers.

6. Retention

Account and sending data are kept while your account is active. After you delete your account, we remove personal data within 30 days, except where retention is required (for example, billing records kept for tax and accounting obligations) or where limited delivery logs are needed for security. Aggregated, non-identifying statistics may be kept.

7. Security

Traffic is encrypted in transit (TLS). Message content is encrypted at rest. Passwords are hashed. Access to production systems is restricted to the operator, and API keys are stored only as hashes with a short prefix for identification.

8. Your rights

Depending on where you live, you can request access, correction, portability, restriction or deletion of your personal data, and object to processing. You can delete your account directly from the dashboard, and you can contact us at privacy@je4ndev.com for any privacy request. We respond within 30 days.

9. International transfers

Our infrastructure, including Amazon SES and Stripe, processes data in the United States and other countries where these providers operate. Transfers rely on the providers' standard contractual clauses and equivalent safeguards.

10. Cookies

We use only essential cookies: a session cookie for the dashboard, and a language cookie that remembers your locale choice. We do not use advertising or cross-site tracking cookies.

11. Changes

We may update this policy. Material changes are announced by email or on this page before they take effect.

Privacy requests and questions: privacy@je4ndev.com

Terms of ServicePrivacy PolicyRefund Policy

© 2026 MepMail