01What this policy covers
This policy explains what MailFleet collects, why, and what you can do about it. It applies to the MailFleet application and website. In short: you own your data, we process it to run your outreach, and we never sell it.
02Information we collect
- Account details — your name, work email, password hash, workspace name and timezone.
- Connected mailboxes — OAuth tokens (never your mailbox password), IMAP/SMTP settings you provide, and the message content and metadata needed to send campaigns, detect replies and run warmup.
- Lead data you import — names, email addresses and custom fields in the lists you upload or paste.
- Usage and device data — pages viewed, actions taken, browser and IP, used for security and product improvement.
- Billing — handled by our payment processor; we never store card numbers.
03How we use it
- To run the service: sending sequences, pausing on replies, routing answers to your queue.
- To operate the warmup network and compute sender-health and deliverability analytics.
- To secure accounts, prevent abuse of shared sending infrastructure, and enforce our anti-spam rules.
- To support you and improve the product.
We do not sell personal data, serve ads, or use your email content to train advertising or general-purpose AI models.
04Your leads and email content
Lead lists and the emails you send are your data. We process them only on your instructions, as a processor, to deliver the service. Unsubscribes and bounces are added to your suppression list so they are never contacted again from your workspace.
05Google user data
When you connect a Gmail or Google Workspace mailbox with Google sign-in, you allow MailFleet to send and read email for that mailbox (the https://mail.google.com/ permission) and to see its email address. This is exactly what we do with that access.
- What we access — the mailbox's email address; the emails MailFleet sends for you; and, when we check for replies, the envelope (sender, recipients, subject and date), the reply headers and the text of new messages in your Inbox and Spam folders, plus the delivery report of bounce messages. We never open your Sent mail, Trash or other labels, and we don't store attachments.
- How we use it — to send the campaign emails, test emails and replies you create in MailFleet; to find replies, bounces and out-of-office messages from your leads, so your sequences stop or pause at the right time and replies reach your MailFleet inbox; and, only if you turn warmup on for the mailbox, to send and receive warmup messages.
- What we keep — replies and bounces from your leads, and copies of the emails MailFleet sent. Messages from anyone who isn't one of your leads are discarded as soon as they're checked and never stored. Checking for replies never marks messages as read, moves them or deletes them.
- Warmup — if you turn warmup on, MailFleet looks only for the warmup messages it delivered to your mailbox, identified by a unique code it adds to each one. It moves them from Spam to your inbox, marks them read and starred, and sometimes replies. It never reads or changes any other message.
- AI reply tagging — to label a reply (for example interested, not now or out of office) when our built-in rules can't tell, and to read return dates from out-of-office replies, we send the reply's subject and new text to Anthropic's API. We don't send sender names, email addresses or attachments, and Anthropic does not use data sent through its API to train its models.
- Sharing — we don't sell Google user data or use it for advertising. It is processed only by the providers that run these features: our cloud hosting (Railway), the network servers that carry our encrypted connections to Google, Anthropic for reply tagging, and our email delivery provider if you set up reply forwarding. Forwarding addresses, webhooks and AI assistants you connect receive reply details only because you set them up. We also disclose data when the law requires it.
- People at MailFleet — our staff view your Google user data only when you ask us to (for example when we manage your campaigns and replies for you, or help you through support), when it's needed for security such as investigating abuse, or to comply with the law.
- Storage and security — Google access tokens are encrypted with AES-256 before they're stored in our database, and every connection to Google is encrypted.
- Retention and deletion — disconnecting a mailbox in MailFleet deletes its Google tokens immediately. To revoke MailFleet's access at Google too, remove MailFleet at myaccount.google.com/permissions. Replies and copies of sent emails stay with your workspace's campaign history; email support@mailfleet.co and we'll delete them within 30 days.
Limited Use. MailFleet's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data to develop, improve or train generalized AI or machine-learning models.
06The warmup network
Warmup works by exchanging automated messages between consenting member mailboxes. It is off unless you turn it on for a mailbox. These messages are machine-generated and never contain marketing or personal lead data. In each mailbox that receives one, MailFleet moves it out of spam, marks it read and starred, and sometimes replies, so mailbox providers see normal engagement.
07When we share
Only with subprocessors that run the service — cloud hosting, email infrastructure, AI processing for reply tagging, payment processing and product analytics — under data-processing agreements, and with authorities when the law requires it. A current subprocessor list is available on request at support@mailfleet.co.
08Retention
- Mailbox tokens are deleted immediately when you disconnect a sender; its warmup history is kept 30 days, then erased.
- Lead data and campaign history live for the life of your workspace and are deleted 30 days after you close it.
- Encrypted backups roll off within 35 days.
09Security
Data is encrypted in transit and at rest. Mailbox access uses OAuth wherever the provider supports it, credentials and tokens are encrypted with AES-256 before they are stored, and internal access follows least-privilege. Report security issues to support@mailfleet.co — we respond within one business day.
10Your rights
Depending on where you live (including under GDPR and CCPA), you can access, correct, export, delete, or object to the processing of your personal data. Email support@mailfleet.co and we will act within 30 days. People who receive your emails can also contact us to have their address suppressed across the workspace that emailed them.
11Cookies & international transfers
We use essential cookies for sign-in and a first-party analytics cookie — no advertising trackers. Where data crosses borders, transfers rely on Standard Contractual Clauses.
12Children & changes
MailFleet is a work tool and not intended for anyone under 16. If this policy changes materially, we email every workspace owner at least 14 days before the change takes effect.