Privacy
Last updated October 9, 2026. This page describes what the Mailroom service actually stores and why.
What we store
- Account: your email address and a salted password hash (PBKDF2). Optional signup attribution: the referring domain and UTM tags of the link you came from.
- Mailbox connection: mailbox address, IMAP/SMTP hosts and ports, connection status, and your username and app password, encrypted at rest using envelope encryption (a per-secret data key wrapped by a server master key). The last connection error may be stored to help you fix setup; it never contains message content.
- API keys: a short prefix and a hash of each key, plus when it was last used. The full key is shown once and never stored.
- Usage: for each MCP tool call, the tool name and time. This powers daily limits and your dashboard.
- Sessions: a hashed session token in a secure, HTTP-only cookie that keeps you logged in.
- Site analytics: first-party and cookie-free. For page views we store the path, referring domain, UTM tags, and a daily-rotating salted hash of IP address and browser user agent, so we can count unique visitors without storing IP addresses. No third-party trackers or ad scripts.
What we don't store
Email subjects, bodies, attachments, and contacts. Mail is fetched live from your mail server when your AI client calls a tool and is returned to that client; it isn't written to our database or logs.
Who processes your data
Mailroom runs on our own server, hosted in North America. When your AI client calls a tool, the result goes to that client and its model provider under their terms. We don't sell data or share it with advertisers.
Retention and deletion
Account data is kept until you delete it. From the dashboard you can disconnect your mailbox, revoke API keys, and delete your account. Deleting your account permanently removes your account, stored mailbox credentials, API keys, sessions, and usage history. Aggregate page-view records aren't linked to accounts. Also revoke the app password at your email provider when you leave.
Contact
Questions or requests: launch@usemailroom.app.