◇ Legal

Privacy Policy

What we collect, why, who else sees it, and how to get it back or have it deleted.

1. Two different roles, and which one applies to you

SentientMail handles personal data in two distinct capacities, and almost every question about privacy here depends on which one is in play.

We are the controller of account data

When you sign up, sign in, pay us, or write to support, we decide how that data is used. This policy governs it, and sections 2, 3, and 9 are the ones you want.

We are a processor of your contact data

The contacts you import, the campaigns you send, and the engagement they generate are yours. You decide what to collect and why. We only act on your instructions, and we never mine your contact data, sell it, rent it, use it to build profiles, or use it to train AI models. Our obligations there are set by the Data Processing Addendum, which takes precedence over this policy on anything to do with that data.

Received a marketing email sent through SentientMail? The sender chose to contact you, not us, and they control your data. Section 4 explains what to do.

2. What we collect as controller

You give us

  • Account details: name, email address, password (stored only as a hash), company name, and phone number where you use phone verification.
  • Billing details: billing name, address, and tax identifiers. We never see or store your full card number; our payment processor handles the card and returns only a token and the last four digits.
  • Support correspondence: what you write to us and what we write back.
  • Marketing opt-in: your email address, if you ask for our product updates.

We generate or observe

  • Usage and audit records: which features you used, what changed in your account, and who changed it, including the actor and timestamp for security-relevant actions.
  • Technical logs: IP address, browser and device information, request timestamps, and error diagnostics.
  • Deliverability signals: aggregate bounce and complaint rates for your account, which we are obliged to monitor.

We do not buy personal data about you, and we do not track you across other websites. The marketing site runs no analytics and no advertising trackers.

3. Why we use it, and our lawful basis

We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other US state privacy laws. We have never done so.

We do not use your data to train AI models. Where you use the platform AI assists included with your plan, the prompt goes to our AI provider to generate a response and is not used by them to train their models under our agreement with them. Where you configure your own provider key, that traffic is governed by your agreement with that provider.

4. If you received an email sent through SentientMail

You are almost certainly looking for the sender, not for us. They chose to contact you, they hold your data, and they are the controller of it. We only carried the message.

  • To stop the mail: use the unsubscribe link in the message. It works without a login and takes effect at once. That is faster than any request to us.
  • To access or delete your data: ask the sender, whose identity and postal address are in the footer of every message.
  • If the sender will not act, or you never opted in, or the mail looks like phishing: write to abuse@sentientmail.com. We will route the request to the sender, and we act on senders who mail people without permission.

You can also write to privacy@sentientmail.com and we will help you reach the right party.

5. Who we share it with

We share personal data with service providers who help us run the platform. Each is bound by contract to process it only on our instructions and to protect it. The current list, with what each one does and where it operates, is published at sentientmail.com/subprocessors.

We also disclose personal data where we must:

  • to comply with a law, a court order, or a valid legal request, after checking that the request is valid and narrowing our response to what it actually requires;
  • to protect the rights, safety, or property of SentientMail, our customers, or the public;
  • to a professional adviser under a duty of confidentiality; or
  • to an acquirer in a merger, acquisition, or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.

Where the law allows, we will tell you before responding to a government or law enforcement request for your data, so that you can challenge it.

6. International transfers

We are based in the United States and our infrastructure runs there, with one exception: the mail server that sends your messages runs on a machine we operate in France, so recipient addresses and message content are processed there while a message is being sent. If you are in the European Economic Area, the United Kingdom, or Switzerland, using the Service means your personal data is transferred to the United States.

For those transfers we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with supplementary technical measures including encryption in transit and at rest. The clauses are incorporated into our Data Processing Addendum, which you can execute without negotiating with us.

7. How long we keep it

8. Security

We protect personal data with measures including:

  • Database-enforced tenant isolation. Row-level security in the database keeps each customer's data separated at the storage layer rather than relying only on application code to get it right.
  • Encryption in transit (TLS) and at rest, with provider API keys encrypted separately.
  • Passwords stored only as salted hashes, never in a form we can read.
  • Two-factor authentication and idle-session timeouts on accounts.
  • Audit records of security-relevant actions, showing who did what and when.
  • Least-privilege access for our own staff, granted only where needed to operate the Service or answer your support request.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority within the timeframes the law requires, which under the GDPR is 72 hours from becoming aware of it.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you, and get a copy.
  • Correct data that is wrong or incomplete.
  • Delete your data, subject to what we must keep by law.
  • Port your data to another provider in a machine-readable format.
  • Object to or restrict processing based on legitimate interests.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Not be discriminated against for exercising any of these rights. Our prices and service do not change because you made a request.

Write to privacy@sentientmail.com. We respond within 30 days, or sooner where the law requires, and we may need to verify your identity first. Exercising these rights is free unless a request is manifestly unfounded or excessive.

You may also complain to your data protection authority. In the EEA that is the authority for your country of residence; in the UK it is the Information Commissioner's Office. We would rather you came to us first, but that is your right, not a precondition.

10. Cookies

The marketing site sets two kinds of cookies, both optional. sm_consent remembers your answer to the cookie choice for six months. Google Analytics, only after you have allowed it, sets _ga and one _ga_… cookie so that a later page view can be counted as the same browser; they last up to two years and are removed when you answer no. We use it to count visits and see which pages get read. The IP address is truncated, and nothing you type on this site is part of it. No advertising pixels, no session recording, no other third-party trackers.

In Europe, the UK and Switzerland nothing optional is set until you say yes. Elsewhere the statistics run by default and you can turn them off at any time. A browser that sends the Global Privacy Control signal is treated as a standing no. The Cookie settings link in every footer shows your current answer and lets you change it.

The application at app.sentientmail.com sets a small number of strictly necessary cookies to keep you signed in, protect against cross-site request forgery, and remember which business unit you are working in. They carry no advertising or cross-site tracking function and cannot be disabled without breaking sign-in.

Marketing emails sent by our customers may contain open and click tracking, which the sender configures and controls. That is their decision under their own privacy policy, not ours.

11. Children

The Service is for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@sentientmail.com and we will delete it.

12. Changes to this policy

We may update this policy. For a material change we will give at least 30 days' notice by email to account owners and update the "last updated" date above. Previous versions are available on request.

13. Contact us

Privacy questions and rights requests: privacy@sentientmail.com
Abuse reports: abuse@sentientmail.com
Formal legal notices: legal@sentientmail.com

SentientMail, Inc.
16192 Coastal Highway
Lewes, DE 19958
United States