1. Two different roles, and which one applies to you
SentientMail handles personal data in two distinct capacities, and almost every question about privacy here depends on which one is in play.
We are the controller of account data
When you sign up, sign in, pay us, or write to support, we decide how that data is used. This policy governs it, and sections 2, 3, and 9 are the ones you want.
We are a processor of your contact data
The contacts you import, the campaigns you send, and the engagement they generate are yours. You decide what to collect and why. We only act on your instructions, and we never mine your contact data, sell it, rent it, use it to build profiles, or use it to train AI models. Our obligations there are set by the Data Processing Addendum, which takes precedence over this policy on anything to do with that data.
2. What we collect as controller
You give us
- Account details: name, email address, password (stored only as a hash), company name, and phone number where you use phone verification.
- Billing details: billing name, address, and tax identifiers. We never see or store your full card number; our payment processor handles the card and returns only a token and the last four digits.
- Support correspondence: what you write to us and what we write back.
- Marketing opt-in: your email address, if you ask for our product updates.
We generate or observe
- Usage and audit records: which features you used, what changed in your account, and who changed it, including the actor and timestamp for security-relevant actions.
- Technical logs: IP address, browser and device information, request timestamps, and error diagnostics.
- Deliverability signals: aggregate bounce and complaint rates for your account, which we are obliged to monitor.
We do not buy personal data about you, and we do not track you across other websites. The marketing site runs no analytics and no advertising trackers.
3. Why we use it, and our lawful basis
| Purpose | Data | Lawful basis (GDPR) |
|---|---|---|
| Provide the Service | Account details, usage records | Performance of a contract |
| Bill you | Billing details, plan usage | Performance of a contract |
| Support you | Correspondence, account details | Performance of a contract |
| Keep the platform secure and prevent abuse | Technical logs, deliverability signals, audit records | Legitimate interests, and legal obligation where anti-spam law applies |
| Send you product updates | Email address | Consent, withdrawable at any time |
| Send service notices you cannot opt out of | Email address | Performance of a contract |
| Meet tax, accounting, and legal obligations | Billing records | Legal obligation |
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other US state privacy laws. We have never done so.
We do not use your data to train AI models. Where you use the platform AI assists included with your plan, the prompt goes to our AI provider to generate a response and is not used by them to train their models under our agreement with them. Where you configure your own provider key, that traffic is governed by your agreement with that provider.
4. If you received an email sent through SentientMail
You are almost certainly looking for the sender, not for us. They chose to contact you, they hold your data, and they are the controller of it. We only carried the message.
- To stop the mail: use the unsubscribe link in the message. It works without a login and takes effect at once. That is faster than any request to us.
- To access or delete your data: ask the sender, whose identity and postal address are in the footer of every message.
- If the sender will not act, or you never opted in, or the mail looks like phishing: write to abuse@sentientmail.com. We will route the request to the sender, and we act on senders who mail people without permission.
You can also write to privacy@sentientmail.com and we will help you reach the right party.
6. International transfers
We are based in the United States and our infrastructure runs there, with one exception: the mail server that sends your messages runs on a machine we operate in France, so recipient addresses and message content are processed there while a message is being sent. If you are in the European Economic Area, the United Kingdom, or Switzerland, using the Service means your personal data is transferred to the United States.
For those transfers we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with supplementary technical measures including encryption in transit and at rest. The clauses are incorporated into our Data Processing Addendum, which you can execute without negotiating with us.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account. After closure: 30 days to export, deleted from active systems within a further 30 days, and from backups within 90 days. |
| Customer contact data | For as long as you keep it, on your instructions. Contacts in a terminal state are purged after 90 days, though suppression of the address is kept permanently so it can never be re-mailed by mistake. |
| Billing records | Seven years, as required by tax and accounting law. |
| Technical logs | Up to 90 days, then deleted or aggregated beyond identifiability. |
| Abuse and suspension records | Up to two years, so a suspended account cannot simply be recreated. |
| Support correspondence | Three years from the last message in the thread. |
| Inactive free accounts | Deleted after 12 consecutive months of inactivity, following notice. |
8. Security
We protect personal data with measures including:
- Database-enforced tenant isolation. Row-level security in the database keeps each customer's data separated at the storage layer rather than relying only on application code to get it right.
- Encryption in transit (TLS) and at rest, with provider API keys encrypted separately.
- Passwords stored only as salted hashes, never in a form we can read.
- Two-factor authentication and idle-session timeouts on accounts.
- Audit records of security-relevant actions, showing who did what and when.
- Least-privilege access for our own staff, granted only where needed to operate the Service or answer your support request.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority within the timeframes the law requires, which under the GDPR is 72 hours from becoming aware of it.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and get a copy.
- Correct data that is wrong or incomplete.
- Delete your data, subject to what we must keep by law.
- Port your data to another provider in a machine-readable format.
- Object to or restrict processing based on legitimate interests.
- Withdraw consent at any time, without affecting processing already carried out.
- Not be discriminated against for exercising any of these rights. Our prices and service do not change because you made a request.
Write to privacy@sentientmail.com. We respond within 30 days, or sooner where the law requires, and we may need to verify your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.
You may also complain to your data protection authority. In the EEA that is the authority for your country of residence; in the UK it is the Information Commissioner's Office. We would rather you came to us first, but that is your right, not a precondition.
11. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@sentientmail.com and we will delete it.
12. Changes to this policy
We may update this policy. For a material change we will give at least 30 days' notice by email to account owners and update the "last updated" date above. Previous versions are available on request.
13. Contact us
Privacy questions and rights requests:
privacy@sentientmail.com
Abuse reports: abuse@sentientmail.com
Formal legal notices: legal@sentientmail.com
SentientMail, Inc.
16192 Coastal Highway
Lewes, DE 19958
United States
