Privacy Policy

What we collect, why we are allowed to, who else touches it, how long it stays, and what you can make us do about it.

Effective 25 July 2026.

1. Who is responsible

The data controller is CROapps Oy, a limited company registered in Finland, business ID 3550932-5, VAT FI35509325, Pohjoinen Rautatiekatu 29B, 00100 Helsinki, Finland. Reach us through the contact form for anything in this policy.

This policy covers everyone who uses MCPmailer, wherever you are. It also covers people whose personal data reaches us because a customer's agent emailed them; section 4 is about you.

For most of what you put into MCPmailer we are a processor, not a controller: your mail, contacts, and notes are yours, and we handle them on your instructions. The Data Processing Addendum sets out those obligations and forms part of your contract.

2. What we collect

  • – Account data: your name and email address, and a hashed password if you sign in with one. We never store a password in a readable form.
  • – Workspace data: workspace names, subdomain slugs, plan and trust tier, and the domains you verify.
  • – Mail: messages your agents send and receive, including sender and recipient addresses, subjects, bodies, headers, and attachments. Raw MIME and attachment bytes go to object storage; headers and text go to the database.
  • – Delivery events: bounces, complaints, deliveries, and rejections reported by the sending infrastructure, plus per-day usage totals.
  • – Open tracking: if, and only if, you switch it on for a message, a count of opens and the first time it was opened. It is off by default.
  • – Contacts, notes, and templates: everything you or your agents store in the workspace address book, shared notes, and template library.
  • – Vault records: encrypted secrets. We hold ciphertext, an initialisation vector, a salt, and a verifier, and nothing else. We cannot read them.
  • – API keys: a prefix for display and a hash for verification. The key itself is shown once and never stored.
  • – Sessions and connections: session tokens, the IP address a session was created from, browser user agent, and OAuth clients you have authorised.
  • – Sign-in history: for each sign-in, the method used, the two-letter country the request came from, and a browser and platform family such as "Chrome on macOS". No IP address is kept here. It is what lets us tell you when your account is signed into from somewhere new, it is visible to you on the security page, and it is deleted after 90 days.
  • – Billing data: plan, invoices, usage totals, and a Stripe customer identifier. Card details are collected and held by Stripe, never by us.
  • – Affiliate data: if you join the affiliate program, your PayPal address, application details, referrals, commissions, and payouts.
  • – Technical logs: request and error logs generated when you use the service, kept for security and troubleshooting.
  • – Contact form messages: what you write to us, the name and address you give, and the network address it came from, kept so we can answer and so we can spot a pattern of abuse.

We do not use advertising trackers, we do not sell personal data, and we do not share it for cross-context behavioural advertising as US state privacy laws define that term.

3. Why we use it, and on what legal basis

  • – To provide the service: authenticate you, deliver and receive mail, run agent tools, and show you your own data. Legal basis: performance of a contract.
  • – To bill you: subscriptions, usage above the allowance, invoices, and tax records. Legal basis: contract, and legal obligation for accounting records.
  • – To keep the service safe: rate limiting, duplicate-content detection, bounce and complaint monitoring, quota enforcement, and investigating abuse reports. Legal basis: legitimate interest in protecting recipients, our sending reputation, and the service.
  • – To support you: answering what you send through the contact form and diagnosing faults you report. We keep those messages, and the address you gave us, so we can reply and so we can see whether a problem is recurring. Legal basis: contract and legitimate interest.
  • – To run the affiliate program: attributing referrals, calculating commission, and making payouts. Legal basis: contract.
  • – To comply with the law: responding to lawful requests and meeting retention obligations. Legal basis: legal obligation.

We do not read message content, and we never use it to train models. Abuse enforcement runs on sending behaviour and metadata. The one automated exception is a duplicate-content check that hashes a message body to spot the same mail being blasted repeatedly: we store the hash, not the body, and hashes are deleted on a short cycle.

4. If an agent emailed you

If you received mail from an agent on MCPmailer, the customer running that agent decides what it says and who it goes to. They are the controller of your data; we only carry the message. Ask them to stop, correct, or delete your data, and they must act on it.

You can also unsubscribe using the link in the message, or by replying to ask. An unsubscribe adds your address to a suppression list that blocks further sending to you from that workspace, and suppression records are kept precisely so that we can keep honouring the request.

If you cannot reach the sender, or if mail from MCPmailer looks like abuse, tell us through the contact form and we will act on it. We can suspend a sender even when we cannot delete data that belongs to their workspace.

5. Who else sees it

We use a small set of sub-processors to run the service: hosting and storage, the database, the mail infrastructure, payments, and affiliate payouts. Each is bound by contract to process data only on our instructions. The current list, with what each one does and where it is, is on the sub-processors page.

We also share data where the law requires it, and with professional advisers under confidentiality. If our business is sold, data moves with it, and we will tell you before that happens.

We do not sell your data to anyone, for any purpose.

6. Where data is processed

The service runs on infrastructure in the United States and on a global edge network, and mail is sent and received through infrastructure in the United States. That means personal data leaves the EEA.

Those transfers rely on the European Commission's Standard Contractual Clauses, together with the technical measures described in section 8, including encryption in transit and at rest. Where a provider is certified under the EU-US Data Privacy Framework, we rely on that as well.

You can ask us for details of the safeguards in place for any specific transfer.

7. How long we keep it

  • – Mail, contacts, notes, templates, and vault records: for as long as your workspace exists, because they are the service. You can delete individual items at any time.
  • – Delivery and activity events: 90 days, then deleted automatically.
  • – Duplicate-content hashes: a short rolling window measured in hours, then deleted automatically.
  • – Suppression records: for as long as the workspace that created them exists, because forgetting that someone unsubscribed would mean emailing them again. They go when the workspace goes, and so does its ability to email anyone.
  • – Sessions: until they expire or you sign out.
  • – Invoices and accounting records: as long as Finnish accounting law requires, currently six years, even after an account closes.
  • – Everything else: erased immediately when you delete a workspace from its settings page, including the stored bytes of every message. If you leave an account behind instead, it stays available for export for 30 days and is deleted within 90 days of closure.

8. Security

Data is encrypted in transit and at rest. API keys and passwords are stored hashed, never in plain text. Access to production data is limited to the people who need it to operate the service, and administrative actions are logged.

The vault is end-to-end encrypted, so vault secrets are unreadable to us and would stay unreadable to anyone who obtained a copy of the database.

If a breach affects your personal data we will notify the Finnish Data Protection Ombudsman within 72 hours where required, and tell you directly where the risk to you is high. Report a vulnerability through the contact form; we will not pursue researchers who act in good faith and give us a reasonable chance to fix things.

9. Cookies

We set four cookies, all of them necessary to operate the service: a session cookie, a workspace-selection cookie, an affiliate-referral cookie, and the cookies our authentication library needs to complete a sign-in. We set no advertising or analytics cookies, which is why there is no consent banner. The Cookie Notice explains each one.

10. Your rights

Under the GDPR you can:

  • – Ask for a copy of the personal data we hold about you, and for it in a portable format.
  • – Have inaccurate data corrected.
  • – Have data deleted, where we have no overriding reason or legal duty to keep it. You do not have to ask us for this: your settings page deletes your account, every workspace you own, and the mail inside them, on the spot.
  • – Restrict or object to processing we base on legitimate interest.
  • – Withdraw consent where we relied on it, without affecting what happened before.
  • – Complain to a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi); you may also complain where you live or work.

Use the contact form and pick "Privacy request" to exercise any of these. We answer within 30 days, and free of charge unless a request is repetitive or excessive. We may need to verify who you are first, which for an account holder usually means writing from the address on the account.

If your data is in a customer's workspace rather than your own account, we will pass your request to that customer and support them in answering it, because the data is theirs to act on.

11. Children

MCPmailer is a tool for developers and businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, tell us and we will delete it.

12. Requests from public authorities

We disclose data to an authority only where we are legally obliged to. We check that a request is valid and limited in scope, we produce the narrowest set of data that answers it, and we tell the affected customer unless the law forbids it. We do not give any government direct or unsupervised access to our systems.

13. Changes

We may update this policy. For changes that materially affect how we handle your data we will email account holders at least 30 days beforehand, and the effective date at the top of this page will change.

Privacy questions and rights requests: use the contact form and choose "Privacy request". It reaches us directly, and unlike a published address it does not fill with the automated mail this product exists to discourage.