Privacy Policy
postkeep Cloud Privacy Policy. Effective date: [TBD: effective date]
What postkeep Cloud keeps, why we keep it, for how long, and how to have it deleted.
DraftNot legal advice. A lawyer has not reviewed this text yet.
On this page 14 sections
- 1. Who we are
- 2. The short version
- 3. What we collect, why, and on what basis
- 4. Mail that belongs to other people
- 5. How we protect your data
- 6. Who we share data with
- 7. International transfers
- 8. How long we keep data
- 9. If there is a data breach
- 10. Your rights
- 11. Children
- 12. For organizations: data-processing agreement
- 13. Changes to this policy
- 14. Contact
1. Who we are
postkeep Cloud is run by [seller legal name] ("we", "us"). For the account and billing data described below, we are the controller. Contact: [privacy contact email: TBD]. Post: [postal address: TBD]. [eu/uk representative: TBD] Lawyer check: whether a representative (GDPR Art. 27) or a data protection officer is needed.
This policy covers postkeep Cloud: postkeep.ai and the MCP addresses at mcp.postkeep.ai. It does not cover the open-source postkeep server you run yourself, which sends us nothing: no telemetry.
2. The short version
- We keep your account details, message IDs and metadata for your mailboxes, and your mailbox credentials, encrypted.
- We do not store message bodies. When your agent asks for a message, we fetch it from your provider and pass it to your agent. It is not stored and is kept out of our logs.
- Payments go through Creem, our merchant of record, which handles your payment details under its own privacy notice.
- Delete your account and we destroy your workspace key at once; the rest of your data is deleted within 7 days, and backups expire within [backup window: TBD].
- We do not sell your data or use it for advertising. To confirm
3. What we collect, why, and on what basis
Where the GDPR (or the UK GDPR) applies, each use below has a lawful basis under Article 6(1). "Contract" means we need it to provide postkeep Cloud to you (6(1)(b)); "legal obligation" means a law requires it (6(1)(c)); "legitimate interests" means it is needed for a reasonable purpose that your rights do not outweigh (6(1)(f)). Lawyer check: each basis.
| Data | What it is | Why we use it | Lawful basis | How long we keep it |
|---|---|---|---|---|
| Account data | Your email address, how you sign in (email link, Microsoft, Google or Apple), your plan, workspace names, the hashes of your MCP keys, and, on Business, the people you invite | To create and run your account, sign you in and keep it secure | Contract | While your account exists; deleted within 7 days after you delete it |
| Billing data from Creem | Your name, country and email address, plus your plan, mailbox count, subscription and payment status, and renewal dates. We do not receive your full card details | To know which plan you have paid for, apply the grace period, and honor time paid | Contract; legal obligation for records we must keep | [billing record retention: TBD] |
| Mailbox connection data | Each mailbox's address, provider, server settings (for IMAP), connection status, and its credentials: an app password, or the access Microsoft grants after your sign-in, stored encrypted | To connect your mailboxes for your agent | Contract | Credentials are deleted at once when you disconnect the mailbox |
| Message IDs and metadata | [metadata fields: TBD], about mail in your connected mailboxes. This includes data about the people who write to you and the people you write to | So your agent can find and act on messages, and so new-mail alerts work To confirm | Contract; for other people's data, legitimate interests (see section 4) | While the mailbox is connected To confirm: what happens on disconnect; deleted within 7 days after you delete your account |
| Message contents your agent asks for | Message bodies and attachments, including other people's mail | To pass them to your agent when it asks | Contract; for other people's data, legitimate interests (see section 4) | Not stored. Processed only while being passed on, and kept out of logs |
| Mail your agent sends | The message your agent asks us to send | To send it through your provider | Contract | Not stored To confirm |
| Alert settings and events | Your alert addresses (webhooks), delivery status, and new-mail events waiting to be delivered To confirm: the fields stored with each alert event | To send new-mail alerts to your webhook | Contract | Settings: while set. Waiting events: [outbox limits: TBD] |
| Usage and stats | Messages seen, alerts sent, when each mailbox was last checked, and fair-use counters | For your dashboard, fair use and preventing abuse | Contract; legitimate interests | [stats retention: TBD] |
| Security logs | IP addresses, times and request details for sign-ins and MCP requests. Never message bodies | To keep postkeep Cloud secure and stop abuse | Legitimate interests | [log retention: TBD] |
| Support emails | What you write to us and our replies | To answer you | Contract; legitimate interests | [support retention: TBD] |
| Website | [analytics and cookies: TBD] | To run the website | [website lawful basis: TBD] | [website data retention: TBD] |
You need to give us an email address to have an account, and mailbox credentials to connect a mailbox; without them we cannot provide postkeep Cloud. We do not make decisions about you by automated means that have legal or similarly significant effects. (GDPR Art. 13(2)(e)-(f))
4. Mail that belongs to other people
Your mailboxes hold messages from and to other people. When your agent asks, we fetch those messages and pass them to your agent, and we keep IDs and metadata as described above. We process this mail only to provide postkeep Cloud to you and on your instructions. We do not contact those people or use their data for anything else. Lawyer check: our role for this data (processor for you, or controller), how the GDPR's household exemption applies to personal users, and how we meet the duty to inform people whose data we did not collect from them (GDPR Art. 14).
5. How we protect your data
- Mailbox credentials are encrypted. Each workspace has its own encryption key, and that key is itself encrypted by a master key held in a separate key service.
- MCP keys are stored only as a hash and shown to you once.
- Message bodies are not stored and are kept out of logs.
- There is no routine way for our staff to decrypt your credentials, and any emergency access is logged. To confirm: wording
- Each workspace is isolated, with its own MCP address and key.
No system is perfectly secure. Section 9 explains what we do if something goes wrong.
6. Who we share data with
We use a small number of providers (sub-processors) to run postkeep Cloud. Each one gets only what it needs.
| What they do | Who | Data involved | Where |
|---|---|---|---|
| Hosting | [hosting provider: TBD] | Everything passes through the servers they run | [data region: TBD] |
| Database | [database provider: TBD] | Account data, message IDs and metadata, encrypted credentials | [data region: TBD] |
| Key service | [key service provider: TBD] | The master key that protects workspace keys | [key service region: TBD] |
| Payments | Creem (Armitage Labs OÜ, Estonia) | Your payment, tax and receipt details | [creem region: TBD] |
| Transactional email | [email provider: TBD] | Your email address and the sign-in links and notices we send | [email provider region: TBD] |
About Creem. Creem sells you the subscription as merchant of record. It processes your payment data as a controller under its own privacy notice at creem.io/privacy, and it shares with us your name, country and email address along with your subscription details. Lawyer check: how to describe Creem's role; Creem's documents call both parties "data controllers".
Your mail providers and agent apps. When you connect a mailbox or an agent app, data flows between postkeep and that company because you asked for it. They are not our sub-processors; their own privacy policies apply.
When the law requires it. We may disclose data if the law requires it, and only as much as it requires. Lawyer check
Changes to this list. We keep this list current. Business customers with a data-processing agreement hear about new sub-processors in advance and can object (GDPR Art. 28(2)). To confirm: notice period
7. International transfers
We host postkeep Cloud in [data region: TBD]. If you are in the EU, the EEA, the UK or Switzerland, your data is transferred there. For those transfers we rely on [transfer mechanism: TBD]. (GDPR Arts. 44-46) Lawyer check
8. How long we keep data
- Message bodies: not stored.
- Mailbox credentials: deleted at once when you disconnect a mailbox.
- Paused mailboxes after a failed payment: kept for 30 days; after two warnings, their credentials are deleted.
- When you delete your account: we destroy your workspace key at once, which leaves stored credentials unreadable; the rest of your data is deleted within 7 days; backups expire within [backup window: TBD]. To confirm: that the "workspace key" in plan s.2 is the workspace encryption key
- Billing records, logs, stats and support emails: as shown in the table in section 3.
9. If there is a data breach
If a personal-data breach happens, we will give notice as the law that applies requires. Where the GDPR applies, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to people (GDPR Art. 33). In the UK, the ICO expects the same within 72 hours where feasible. If a breach is likely to result in a high risk to you, we also tell you directly, without undue delay (GDPR Art. 34). Business customers with a data-processing agreement hear from us without undue delay so they can meet their own duties. Lawyer check
10. Your rights
Depending on where you live, you can ask to see the personal data we hold about you, correct it, delete it, limit how we use it, receive it in a portable form, or object to how we use it (GDPR Arts. 15-21). Where we rely on your consent, you can withdraw it at any time. You can also complain to a data protection authority, in particular where you live or work (GDPR Art. 77).
- Many of these you can do yourself: disconnect a mailbox, remove a key, or delete your account in Settings.
- For anything else, email [privacy contact email: TBD]. We answer within one month, which the law lets us extend by two more months for complex requests (GDPR Art. 12(3)).
- [us state privacy rights: TBD]
Microsoft accounts. You can remove postkeep's access to a Microsoft account at any time: personal accounts at account.live.com/consent/Manage, and work or school accounts at myapps.microsoft.com. Disconnecting the mailbox in postkeep also deletes the access we hold. To confirm
Google accounts. You can sign in to postkeep with Google. Gmail mailboxes still connect over IMAP with a Google app password, not through that sign-in. postkeep's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. To confirm: final wording at the time of Google's verification
11. Children
postkeep Cloud is not meant for children. You must be at least [minimum age: TBD] to use it. If we learn that we hold personal data about a child below that age, we delete it. (GDPR Art. 8 sets 16, or a lower national age not below 13, where consent is the basis) Lawyer check
12. For organizations: data-processing agreement
If you use postkeep Cloud for an organization and need a data-processing agreement under GDPR Article 28, we offer one to Business customers on request: email [support email].
13. Changes to this policy
We post changes here. For a material change, we email you before it applies.
14. Contact
Email [privacy contact email: TBD]. Post: [postal address: TBD]. We reply to every email within 3 business days.