Legal

Privacy Policy

Last updated 13 September 2026

Plain version: we collect what we need to send your email and bill you, delete email content after 7 days and delivery logs after 30, never sell your data, don’t track you, and let payments go through Razorpay so we never see your card or UPI details.

1. Who we are

This policy explains how Email4VibeCoder, operated from India, handles personal data when you use our website, dashboard and SMTP email-sending service (the “Service”). Contact us about privacy at our support address.

2. Our two roles

  • Your account data (your name, email, billing records): we decide how it is used, as described here.
  • The emails you send and your recipients’ addresses: we process these only on your instructions, to deliver your email. You are responsible for having a lawful basis — such as consent — to email your recipients, and for telling them how you use their data.

3. What we collect

  • Account details — your name, email address and organization name. Your password is stored only as a one-way hash, never in readable form.
  • Sending setup — the domains you add and their DNS verification status; the DKIM signing key for each domain (stored encrypted); and your SMTP credentials (passwords stored only as hashes).
  • Emails you send — sender, recipient addresses, subject, size, the full message content, delivery status, and responses from recipient mail servers. Addresses that hard-bounce are added to your account’s suppression list so we stop sending to them.
  • Usage — monthly counts of emails accepted, delivered, bounced and failed.
  • Billing — your plan, amounts, currency, dates, and Razorpay order and payment IDs. Payments are handled by Razorpay; we never receive your card, UPI or bank details.
  • Technical data — IP addresses and request details in short-lived server logs, and the IP address of SMTP connections, used to detect and block abuse such as repeated failed logins.

4. How we use it

  • To provide the Service: authenticate you, and sign, deliver and track your email.
  • To keep the Service secure: rate limiting, abuse and spam detection, lockouts.
  • To process payments and keep billing records.
  • To email you about your account — verification links, password resets, and important service or policy notices.
  • To comply with the law and enforce our Terms of Service.

We do not sell your data, use it for advertising, or read the content of your emails except where needed to investigate abuse or a problem you report.

5. Cookies and browser storage

We use one essential, secure cookie to keep you signed in, and your browser’s local storage to hold a short-lived sign-in token. We do not use analytics, advertising or tracking cookies. The website loads the Inter font from Google Fonts, so Google receives your IP address when a page loads.

6. Who we share it with

We share data only with providers that help us run the Service, and only as needed:

  • Razorpay — payment processing.
  • Hetzner — the servers that run the Service, located in Finland.
  • MongoDB Atlas — database hosting.
  • Google Fonts — web fonts, as described above.
  • Recipient mail servers — the emails you send are, by their nature, delivered to your recipients’ email providers.

We may also disclose data when required by law or a valid legal request, or to protect the Service, our users or the public from fraud, abuse or harm. Because our providers operate outside India, your data may be stored and processed in other countries.

7. How long we keep it

  • Email content — deleted automatically 7 days after we accept the message.
  • Email records and delivery logs (what you see in Activity) — deleted automatically after 30 days.
  • Suppression list — kept while your account exists, to protect your sending reputation.
  • Account and sending setup — kept until your account is deleted.
  • Billing records — kept for as long as tax and accounting laws require.
  • Server logs — rotated and overwritten after a short period. Verification and password-reset links expire after 24 hours and 1 hour.

8. How we protect it

We use TLS encryption for the website and for SMTP connections, store passwords only as strong hashes, encrypt DKIM signing keys, and restrict access to production systems. No system is perfectly secure, so please use a strong, unique password and keep your SMTP credentials private.

9. Your rights

Under India’s Digital Personal Data Protection Act, 2023 and other laws that may apply to you, you can ask us to:

  • tell you what personal data we hold about you, and how we use it;
  • correct or update inaccurate data;
  • delete your account and personal data (except records we must keep by law);
  • withdraw consent where we rely on it; and
  • address a grievance about how we handle your data.

Email our support address from your account’s email address. We aim to respond within 30 days. You can update most account and sending settings yourself in the dashboard.

10. If you received an email sent through us

Emails sent through Email4VibeCoder come from our customers, who control their content and mailing lists. To unsubscribe or ask about your data, contact the sender. To report spam or abuse sent through our servers, email our support address with the full message headers.

11. Children

The Service is not intended for anyone under 18, and we do not knowingly collect their data.

12. Changes to this policy

We may update this policy. The “Last updated” date above shows when it last changed; for material changes we will also notify you by email or in the dashboard.

Questions about this page? Email our support address. See also our Terms of Service.