What we keep, and what we don't.
Postboi ("we") is a messaging service operated from the United Kingdom. This policy explains what we collect when you use postboi.app, the dashboard, the sending API and hosted form endpoints, and what we do with it.
The manifest
What we collect
- Account details. Your name and email address, used to sign you in (we send magic links; there are no passwords) and to contact you about your account.
- Product news. Now and then we email customers about what's new in Postboi. You can say no when you sign up, and every one of these emails has an unsubscribe link; you can also switch them off or on under Account. We keep your answer, and when and where you gave it. These are separate from sign-in links, invites and the notifications you choose, which you get either way.
- Session data. IP address and browser user agent for active sign-in sessions, used for security.
- Send log. For every email sent through the service we log the sender address, recipient addresses, subject line, delivery status (sent, bounced, complained) and the message body. The body is stored to power the message preview in your dashboard; it stays inside your account's log, is never used for anything else, and is deleted with your account.
- Form submissions. Messages posted to your hosted form endpoints are processed the same way as sent email: rendered, delivered to the team member you chose, and stored in your send log. Submissions are spam-checked (and rate-limited) before anything is stored or sent.
- API keys. Stored as one-way hashes; we cannot read them back.
- Usage and billing. Monthly send counts, your plan, and Stripe customer and subscription identifiers. Card details go directly to Stripe and never touch our servers.
- Custom domains. Domain names and DNS verification records you add for sending.
On your behalf
Your recipients' data
When you send email through Postboi, you are responsible for having a lawful basis to contact your recipients. We process their email addresses and your subject lines on your behalf, solely to deliver mail and to track delivery status and abuse (bounces and complaints).
The jar
Cookies
We use a session cookie to keep you signed in (strictly necessary), a cookie on the sign-in page that remembers your answer about product news until your account is created, and, only with your consent, Google Analytics cookies to understand how the site is used. You can decline these in the cookie banner and the site works identically.
How long we hold it
Retention
We keep your data while your account is active. Send metadata is retained to power your message log and to prevent abuse. If you delete your account, we remove your personal data, keeping only what we must for legal, billing or anti-abuse reasons.
Return to sender
Your rights
Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, or object to how we use it. Email support@postboi.app and we'll sort it out. You can also complain to the ICO (ico.org.uk).
Revisions
Changes
If this policy changes materially we'll note it here and update the date above. Questions? support@postboi.app.
ALSO The rest of the small print
- PB-02 Conditions of carriage. The rules of sending through Postboi, and what happens when they're broken. Terms of service
- PB-03 Chain of custody. Where your data lives, how it's sealed, and the whole subprocessor list. Security & data
- PB-04 Every lane is open. Live checks against the real dependencies, every time the page loads. Service status
- PB-05 Rates of postage. Every plan and what a month costs at your volume, in plain figures. Pricing
- PB-06 Postboi or Resend? Setup, price at every volume, and what comes in the box, side by side. Comparison
- PB-07 Time in transit. How fast our mail reaches each inbox provider, and our uptime, from our own figures. Delivery record