Legal
Privacy Policy
Last updated: 1 September 2026
We collect the minimum data needed to run your mailboxes and keep them secure — nothing more. We never read your mail for ads, never sell your data, and never use it to train models. This policy explains exactly what we collect, why, and how you stay in control of it.
1. Information we collect
We collect only what’s needed to run Mailyte and keep your workspace secure:
- Account information — name, email address, workspace name, and the domains you connect.
- Mail content — the messages you send and receive through mailboxes on your workspace.
- Usage & activity data — sign-in times, delivery and bounce counts, device and browser type, and admin actions recorded in your audit trail.
- Billing information — for paid plans, payment details are handled by our payment processor; we store only the last four digits of your card and your billing history.
- Support communications — anything you send us when you contact support or sales.
2. How we use it
We use the information above to:
- Deliver, receive, store and display your mail through mailboxes, webmail and our API.
- Verify domain ownership and authenticate your mail via SPF, DKIM and DMARC.
- Detect and prevent abuse, spam, fraud and security threats across the platform.
- Show you usage, delivery and security information in your dashboard.
- Respond to support requests and send service-related notices (never marketing, unless you opt in).
- Process payments and maintain billing records where legally required.
3. What we never do
We don’t read your mail content for advertising purposes, sell any personal data to third parties, or use your mail content to train machine learning models. Access to mail content by our staff is restricted to what’s strictly necessary to fix a bug or respond to a support ticket you have raised.
5. Storage & security
Mail is encrypted with TLS in transit and encrypted at rest on our servers. Self-hosted instances keep everything on your own server, under your own control, always. Access to production systems is restricted to authorised staff and logged. See our security overview for the detail.
6. Retention
We retain your data for as long as your workspace is active. Email logs retain full message content for 30 days to power search and troubleshooting; attachments are never stored in logs. If you cancel, we keep your workspace data for 30 days in case you change your mind, then permanently delete it. Billing records are retained longer where required by law.
8. Your rights
Depending on where you are located, you may have the right to access, correct, export or delete your personal data. You can export or delete your workspace’s data at any time from Settings — deletion is permanent after a 30-day grace window. To exercise any other right, contact us below.
9. International transfers
Depending on your plan and chosen region, data may be processed in a country other than your own. Where this happens, we use recognised legal safeguards to protect your data in transit and at rest.
10. Children's privacy
Mailyte is intended for business and professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
We’ll update the date at the top of this page when we make changes, and notify you by email or in-product notice for any change that materially affects how your data is handled.
12. Contact us
Privacy questions or requests go to privacy@mailyte.com. We aim to respond within five business days.