Privacy Policy
1. Introduction
MyAgentMail ("we," "us," "our") respects your privacy. This policy explains what data we collect, how we use it, and your rights regarding your information when you use our outreach infrastructure service ("Service"), including the email module and the LinkedIn module.
2. Information We Collect
| Data type | What | Why |
|---|---|---|
| Account data | Email address, name, authentication tokens (via Clerk) | Account creation and authentication |
| Email content | Email bodies, headers, attachments sent/received via the Service | Delivering and storing emails as part of the Service |
| Email metadata | Sender, recipient, timestamps, message IDs, bounce status | Threading, analytics, deliverability monitoring |
| LinkedIn session credentials | li_at, JSESSIONID cookies for tenants subscribed to the LinkedIn module | Performing API calls on the customer's LinkedIn account; AES-256-GCM encrypted at rest |
| Usage data | API call counts, inbox counts, send/receive volumes, LinkedIn action counts | Billing, rate limiting, abuse prevention |
| Analytics events | Page views, CTA clicks, signup funnel events, first-API-call timestamp; sent to Google Analytics 4 with synthetic IDs (no email/name/content) | Measuring conversion, debugging onboarding, prioritizing features |
| Payment data | Processed by Stripe — we do not store card numbers | Subscription billing |
3. How We Use Your Data
- Provide the Service — sending and receiving emails, performing LinkedIn actions on your behalf
- Maintain deliverability and quotas — monitoring bounce/complaint rates, enforcing sending and action limits
- Billing — tracking usage against plan limits
- Security — detecting abuse, preventing unauthorized access
- Support — responding to your inquiries
We do not sell, rent, or share your data with third parties for marketing purposes. We do not use your email or LinkedIn content to train AI models or for advertising.
4. Data Storage and Security
- Data is stored in encrypted databases on infrastructure hosted in the EU (Hetzner, Germany)
- Authentication is handled by Clerk (SOC 2 compliant)
- All connections use TLS encryption
- API keys are stored as one-way hashes — we cannot retrieve them after creation
- IMAP passwords are stored securely for mail server authentication
- LinkedIn session cookies (
li_at,JSESSIONID) are encrypted at rest with AES-256-GCM and never returned via API once stored
5. Data Retention
- Email content is retained as long as your account is active
- LinkedIn session metadata and action logs are retained for up to 12 months for abuse investigation and billing
- Upon account deletion, all email and LinkedIn data is permanently deleted within 30 days
- Usage logs and analytics are retained for up to 90 days
- Payment records are retained as required by applicable tax law
6. Third-Party Services
We use the following third-party services to operate:
- Clerk — authentication and user management
- Stripe — payment processing
- ZeptoMail / Amazon SES — outbound email relay
- Hetzner — infrastructure hosting (EU)
- LinkedIn (Microsoft) — when you subscribe to the LinkedIn module, we make API calls to LinkedIn on your behalf using credentials you provide
- Google Analytics 4 (Google) — product analytics. Receives the events described in section 9. We do not enable Ads / advertising integrations on this property.
- IPRoyal — residential proxy used for the LinkedIn login bootstrap so authentication attempts geo-match the user's normal sign-in country. Carries no application data; only the in-flight LinkedIn HTTP request goes through it.
- TypeSafe — mail safety and triage judgements on inbound mail and on agent-drafted replies. Receives the sender, recipient, subject, up to the first 1,500 characters of the message body and up to 800 characters of text hidden in the message's HTML, and returns typed signals (whether the text is trying to direct an AI agent, how urgent it is, what it is about). Attachments are never sent. See section 7.
Each service has its own privacy policy. We only share the minimum data necessary for each service to function.
7. Automated mail safety and triage
Inbound messages are assessed by an external model (TypeSafe) so that agents are protected from prompt-injection attempts and can sort mail by urgency and subject matter. It is on by default, new accounts are asked to confirm the choice during setup, and you can turn it off at any time as described below.
- What is sent — sender, recipient, subject, up to the first 1,500 characters of the message body, and up to 800 characters of any text hidden in the message's HTML (where attacks are usually placed). Attachments, raw message source and any other message are never sent.
- When — after the message is stored. Mail is never discarded, and if the assessment fails the message is delivered normally.
- Quarantine — when our own scanner and this assessment both judge a message to be a likely attack on an AI agent, it is held back from agents: they are told it arrived, but cannot read its subject or content, and it is removed from the IMAP mailbox. You can still read it in the dashboard and release it, which returns it to your inbox.
- What comes back — a probability that the text is addressed at an AI agent, an urgency level and a category. These are stored on the message and returned to you through the API.
- Replies — where you have enabled the reply check, an agent-drafted reply and the message it answers are assessed the same way before sending, so a reply that acts on instructions hidden in inbound mail can be held.
- Not used for training — the content is processed to return these signals and is not used by us, or on our instruction, to train models.
- Opting out — turn off Prompt-injection protection under Security in your dashboard, or email kamal@send.myagentmail.com. Your mail is then not sent to TypeSafe and is not quarantined; our own built-in scan still labels suspicious mail. Signals stored on your messages are removed with the rest of your data on account deletion.
8. Your Rights
You have the right to:
- Access your data via the API or dashboard
- Export your emails and data at any time
- Delete your account and all associated data
- Correct inaccurate information in your account
- Revoke any LinkedIn session at any time via
DELETE /v1/linkedin/sessions/:id
To exercise these rights, contact us at kamal@send.myagentmail.com.
9. Cookies and analytics
We use the following cookies:
- Session cookies for authentication (Clerk's
__sessioncookie). Required to keep you signed in to the dashboard. - Google Analytics 4 cookies (
_ga,_ga_*) for product analytics — we use these to measure how visitors discover MyAgentMail, which features they use, and where they drop out of the signup funnel. GA4 is configured to anonymize IP addresses and we do not enable any Google Ads / advertising features.
The data we send to Google Analytics is limited to:
- Page views and standard engagement events (scrolls, outbound link clicks)
- Stable internal identifiers — your tenant ID and Clerk user ID — used as the GA4
user_idto deduplicate cross-device sessions. These are synthetic UUIDs that only resolve to PII inside our own systems. - Funnel events such as
cta_clicked,signup_completed,first_api_call. Event parameters carry stable strings (CTA labels, page paths, endpoint paths) — never email addresses, names, passwords, message content, or LinkedIn session credentials.
We do not use advertising cookies, retargeting pixels, or any third-party trackers beyond GA4.
To opt out of GA4 entirely, install a browser extension such as Google's official opt-out add-on, or use a privacy-focused browser (Brave, Firefox with strict tracking protection, etc.).
10. Children's Privacy
The Service is not intended for use by anyone under 18 years of age. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy at any time. Material changes will be communicated via email. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For privacy-related questions or requests, contact us at kamal@send.myagentmail.com.