Legal
Privacy Policy
Last updated 27 August 2026 · Effective 27 August 2026
MailMonk hosts email on domains you own. That means we necessarily hold some of the most personal data there is: your correspondence. This policy explains what we collect, why we are allowed to, where it lives, who else touches it, how long we keep it, and how to get rid of it.
This policy forms part of our Terms and Conditions. Words defined there — Account, Customer Data, Domain, Mailbox, Plan, User — have the same meaning here.
1. Who we are
The Service is operated by Norbert Shavdia, an individual trading as MailMonk, of 17 Abashidze Street, Tbilisi, Georgia. MailMonk is a trading name and not a separate legal entity. For questions about this policy or about your data, write to legal@mailmonk.co.
2. Controller or processor: which one we are
The distinction decides who you ask about what, so it is worth stating plainly. Under the GDPR and equivalent laws:
- We are the controller of the data that exists because you are our customer: your name and sign-in address, the Domains and Mailboxes you create, your Plan and billing status, and our logs and security records.
- We are a processor for the contents of your Mailboxes — the messages, attachments, and the personal data of the people who write to you. You are the controller of that data. We handle it on your instructions, which are the ones you give through the product, and under our Data Processing Addendum.
In practice: if you want a copy of your mail or want it deleted, you can do both yourself from the dashboard. If somebody who emailed you wants their data removed from your mailbox, that request belongs to you, not to us — see section 10.
3. What we collect
- Account data. Your name and email address, provided when you sign up through Clerk. Clerk also keeps authentication records such as sign-in times, IP address, and the method used.
- Domains and DNS. The Domains you add, the DNS records we generate and check for them, the results of those checks, the DNS provider we detect from your nameservers, and the DKIM key pairs we create on your behalf.
- Mailboxes and aliases. The addresses you create, their display names and signatures, and their storage use.
- Mail. Messages received by and sent from your Mailboxes, including headers, bodies, and attachments, together with the authentication and scanning results that AWS attaches on receipt — SPF, DKIM, DMARC, spam, and virus verdicts.
- Billing data. Your Plan, subscription status, billing period, and your Stripe customer and subscription identifiers. Card details go directly to Stripe; we never see or store them.
- Operational data. Request logs kept by our hosting provider (IP address, route, status code, timing), error reports when something in the app fails, counters used for rate limiting and Plan limits, and a per-account list of addresses that have bounced or complained.
- Support correspondence. What you send us at our support, abuse, and legal addresses, and our replies.
We do not collect special categories of personal data deliberately. Mail is free-form, so such data may end up in a message you receive; clause 6.4 of the Terms asks you not to use the Service to store it intentionally.
4. Why we use it, and our legal basis
Where the GDPR applies, we rely on the following bases. We do not rely on consent for anything necessary to run the Service, so there is no consent for you to withdraw that would leave your mail unreachable.
- Performance of a contract. Receiving, storing, and displaying your mail; sending what you ask us to send; provisioning Domains and Mailboxes; verifying DNS; enforcing Plan limits; providing support.
- Legitimate interests. Keeping the Service secure and available; preventing spam, fraud, and abuse; protecting the sending reputation shared by every customer; maintaining the suppression list; debugging failures; and defending legal claims. We have weighed these against your rights and consider them proportionate because each is narrow and none involves profiling or advertising.
- Legal obligation. Keeping tax and accounting records, and responding to lawful requests from competent authorities.
- Consent. Only where we ask for it explicitly and separately, such as an optional product announcement email. You may withdraw it at any time without affecting the Service.
5. What we do not do
We do not sell your data or share it for advertising. We do not read message content to profile you or to target you. We do not use your mail, or anything in it, to train machine-learning models — ours or anyone else’s. There are no advertising or analytics trackers on the dashboard.
Automated systems do process message content, because email cannot work otherwise: spam and malware scanning on receipt, search indexing so you can find a message, and abuse detection. None of this produces a decision with legal or similarly significant effect on anyone. A person at MailMonk reads message content only in three situations: you ask us to investigate something that requires it, we are investigating a specific abuse or security incident, or we are legally compelled. We keep those accesses to the minimum the task needs.
6. Who else processes it
We run on infrastructure operated by the companies below. Each processes data only on our instructions, under a data processing agreement, and none is permitted to use it for its own purposes. This is the subprocessor list referred to in clause 7.3 of the Terms; we will give notice before adding to it, and you may object on reasonable data protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Receiving and sending mail (SES), storing message bodies and attachments (S3), and bounce and complaint notifications (SNS) | United States (us-east-1) |
| Neon | Database holding accounts, domains, mailboxes, and message metadata | United States |
| Vercel | Application hosting, request routing, and platform logs | United States, with global edge routing |
| Clerk | Sign-in, session management, and account security | United States |
| Stripe | Payments and subscription billing for paid plans | United States and Ireland |
| Sentry | Error reporting — stack traces and the request that failed. Never message bodies, attachments, or session recordings | United States |
Beyond these, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or in connection with a merger or sale of the business — in which case we will tell you before your data becomes subject to a different policy.
7. Where it is stored, and international transfers
Mail content and account records are stored in the United States. If you are in the EEA, the UK, Switzerland, or Georgia, that is a transfer outside your jurisdiction. Those transfers rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, and our providers’ own certifications under the EU-US and UK-US Data Privacy Framework. Copies of the clauses we rely on are available from legal@mailmonk.co.
Email is also transferred by its nature. When you send a message, it goes to the receiving provider your recipient uses, wherever that is. We cannot control what happens to it after delivery.
8. How long we keep it
| Data | Retention |
|---|---|
| Messages, attachments, and mailbox contents | Until you delete them, delete the mailbox or domain they belong to, or close your account. After termination, see the 30-day window below. |
| Raw inbound copies | Held briefly in S3 while a message is processed, then removed once it has been delivered to your mailbox. |
| Account and profile records | For the life of the account. Deleted when you close it. |
| Billing records and invoices | Retained by Stripe and by us for as long as tax and accounting law requires, typically seven years, even after the account closes. |
| Suppression list (addresses that bounced or complained) | While your account exists. Sending to a hard-bounced address again damages deliverability for every customer, so this survives mailbox deletion. |
| Request and platform logs | Kept by our hosting provider for a limited period — currently around 30 days — then discarded. |
| Error reports | Up to 90 days. |
| Abuse and security records | Where an account is terminated for abuse, longer, for legal and evidentiary purposes. |
After termination. Under clause 10.2 of the Terms, Customer Data is retained for 30 days after an Account terminates so that you can request an export, then removed from active systems, with deletion from backups following within 90 days.
If you delete it yourself. Deleting a message, mailbox, domain, or your whole account from the dashboard is immediate and irreversible: the records and the stored message bodies and attachments are erased at once, without the 30-day window. Export what you want to keep first.
9. Security
All traffic to MailMonk is encrypted in transit. Data is encrypted at rest by our storage and database providers. Access to our infrastructure uses short-lived, role-based credentials issued per deployment rather than long-lived keys. Incoming HTML mail is sanitised before it is stored and displayed in an isolated frame, so content in a message cannot run code in your browser. Attachments are served with pinned content types so they cannot execute as active content. Sign-in, sessions, and any second factor are handled by Clerk rather than by credentials we store ourselves.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you without undue delay, and the relevant supervisory authority within 72 hours where the law requires it.
10. People who email you
Most personal data in a mailbox belongs to somebody who is not our customer: the people who write to you. We hold their messages as a processor, on your instructions, and we have no direct relationship with them.
If you are one of those people and want access to, correction of, or deletion of a message you sent, ask the person or organization whose mailbox received it — they control it and can delete it. If you contact us instead, we will refer you to them, and we will help them respond as our DPA requires. We will not delete a customer’s mail on a third party’s instruction.
11. Your rights
Most of these you can exercise yourself, immediately, without asking us. Your account page lets you export everything on the account as a ZIP archive — records as JSON, and every message as a standard .eml file that any mail client can open — and lets you delete individual messages, mailboxes, domains, or the whole account.
Depending on where you live, you also have the right to:
- Access the personal data we hold about you, and be told how we use it.
- Correct data that is inaccurate or incomplete.
- Erase your data, subject to records we must keep for tax, legal, or abuse-prevention reasons.
- Port your data — receive it in a structured, commonly used, machine-readable format. The export in the dashboard is built for this.
- Restrict or object to processing we carry out on the basis of legitimate interests, including the right to object at any time.
- Withdraw consent where we asked for it, without affecting the Service.
- Complain to a supervisory authority. In Georgia this is the Personal Data Protection Service (personaldata.ge). In the EEA or UK it is the authority for your country of residence. You may complain to them without contacting us first, though we would rather you gave us the chance to fix it.
To exercise a right that is not available in the app, email legal@mailmonk.co from the address on your account. We respond within 30 days, and will tell you if we need longer because a request is complex. We do not charge for this and will not treat you differently for asking.
12. If you are in California
We collect the categories of personal information described in section 3: identifiers, commercial information (your Plan and billing status), internet activity (request logs), and the contents of electronic mail. We collect them for the business purposes in section 4, from you and from your use of the Service.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, including for anyone under 16. You have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising those rights. Use the export and delete tools in your account, or write to legal@mailmonk.co. You may use an authorized agent; we will ask for proof of their authority.
13. Cookies
We use only the cookies needed to keep you signed in and to protect against cross-site request forgery. They are set by Clerk and by the application itself, are strictly necessary, and there is no consent banner because there is nothing optional to consent to. There are no advertising, tracking, or third-party analytics cookies on the dashboard.
14. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from them. If you believe a child has created an account, write to legal@mailmonk.co and we will remove it.
15. Changes to this policy
We may update this policy. If a change matters — a new purpose, a new category of data, a new subprocessor, or a shorter retention promise becoming longer — we will email the address on your account before it takes effect, giving at least 30 days’ notice where the change is material. The date at the top tells you when this was last revised.
Contact
Norbert Shavdia, trading as MailMonk
17 Abashidze Street, Tbilisi, Georgia
Privacy and data requests: legal@mailmonk.co · General: support@mailmonk.co · Abuse: abuse@mailmonk.co