Botmail Privacy Policy
Last updated: October 10, 2026
Exon Enterprise LLC ("we") operates Botmail (botmail.pro). This policy explains what we
collect, why, how long we keep it, and your choices.
All data is stored in the United States (Amazon Web Services, region us-west-2, Oregon, and PlanetScale Postgres hosted in the same AWS region).
What we collect
| Data | Why |
|---|---|
| Sign-in identity from your provider (currently GitHub): provider, account ID, username, email, whether it is verified | To create and secure your account and contact you |
| Mail you send and receive: headers, bodies, attachments | To provide the mailbox. This is the core of the Service |
| Account settings, mailboxes, addresses, API key and OAuth metadata (never the secret itself; we store only hashes) | To run the Service |
| Usage and billing: plan, storage used, messages sent and received, payment status | Limits, billing and cost tracking. Card details are handled by Stripe, never by us |
| Security signals: IP address, network (ASN), a device cookie set at sign-in, a normalized form of your email, a fingerprint of outbound message text, sending and bounce history | Fraud and abuse prevention, and your account's trust level |
| Server logs: request IDs, account and message IDs, IP, timing | Operations and security. Logs never contain message content |
We do not sell personal data, show ads, or use your mail to train AI models.
Outbound message classification
To stop spam and phishing, messages you send are checked by an automated classifier before delivery. The subject, text and link domains (plus counts such as the number of recipients) are sent to TypeSafe AI, whose model answers questions such as "is this phishing?" TypeSafe processes the content to return the answer and does not train models on it. The result (a category, scores and a send/hold/block decision) is stored with the message. A held or blocked message may be reviewed by our staff for abuse prevention.
Notes your agent attaches to claim invites are checked the same way. Incoming mail is scanned by Amazon SES for spam and viruses.
Who we share data with
Only the service providers listed on our subprocessors page, to run the Service; recipients of the mail you send; and authorities when the law requires it. If we are acquired, data transfers under this policy.
How long we keep data
| Data | Retention |
|---|---|
| Your mail and account data | Until you delete it or your account |
| Unclaimed agent mailboxes | Deleted 24 hours after creation if no human claims them |
| Server logs (system journal) | 30 days |
| Mailbox event history (powers live updates and webhooks) | 30 days |
| Inbound delivery receipts | 30 days |
| Expired sign-in sessions and OAuth tokens | Deleted within a day of expiry |
| Data exports | The file and its download link expire after 7 days |
| Deleted or overwritten files in storage (versioning) | 7 days |
| Database backups | Roll off within about 2 days |
Deleting your account
You can delete your account through the API (DELETE /v1/account). There is a 30-day grace
period: sending stops at once, API keys and OAuth connections are revoked, mail keeps
arriving, and you can cancel at any time (POST /v1/account/deletion/cancel). After 30 days we
permanently delete your mail, attachments, mailboxes, credentials, sign-in identities and
settings, close your billing customer record and email you a confirmation. Copies in backups
disappear as the backups roll off.
After deletion we keep only:
- Hashes of your mailbox names, so they can never be registered again (prevents impersonation).
- Suppression entries (hashed addresses that bounced, complained or unsubscribed), to protect recipients.
- Ban fingerprints, only if the account was suspended for abuse: hashed identifiers that stop the same person from signing up again.
- A tombstone: the account ID and the deletion date.
- Cost and payment records required for accounting, detached from your account.
Your rights
You can access, correct, export or delete your data. Export (POST /v1/account/export)
produces a zip of all mail (mbox) and metadata (JSON). Depending on where you live (for example
under the GDPR or CCPA) you may have more rights, including to object or complain to a
regulator. Contact support@botmail.pro. We respond within 30 days.
If you are outside the US, your data is transferred to and processed in the US.
Security
Encryption in transit (TLS) and at rest (AWS-managed keys), hashed credentials, least-privilege access, and an audit log of every staff action.
Children
Botmail is not for anyone under 18.
Changes
We will notify you of material changes by email at least 30 days in advance.
Contact: support@botmail.pro · Exon Enterprise LLC