Privacy Policy

SMTP Labs, Inc. (the "Company") is committed to maintaining robust privacy protections for its users. Our Privacy Policy ("Privacy Policy") is designed to help you understand how we collect, use and safeguard the information you provide to us and to assist you in making informed decisions when using our Service.

For purposes of this Privacy Policy, "Site" refers to the Company's website, which can be accessed at smtp.dev.

"Service" refers to the Company's services accessed via the Site, in which users can receive, test, and manage email through inbound SMTP, IMAP, POP3, email account hosting, domain management, and related APIs. The Service does not support sending outbound email to external recipients.

The terms "we," "us," and "our" refer to the Company.

"You" refers to you, as a user of our Site or our Service.

By accessing our Site or our Service, you acknowledge that you have read and understood this Privacy Policy and our Terms of Service. Our processing of your Personal Information is based on the legal bases described in Section III below.

I. Information We Collect

We collect "Automatically Collected Data" and "Personal Information." Automatically Collected Data includes information collected through your use of the Site, such as anonymous usage data, general demographic information, referring/exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit, and number of clicks. Some Automatically Collected Data, such as IP addresses and device identifiers, may be considered personal data under certain privacy laws and will be treated accordingly. Personal Information includes your email address and name, which you provide to us through the registration process at the Site via our third-party authentication provider.

1. Information collected via Technology

To activate the Service you do not need to submit any Personal Information other than your email address. To use the Service thereafter, you do not need to submit further Personal Information. However, in an effort to improve the quality of the Service, we track information provided to us by your browser or by our software application when you view or use the Service, such as the website you came from (known as the "referring URL"), the type of browser you use, the device from which you connected to the Service, the time and date of access, and other information that does not personally identify you. We track this information using cookies, or small text files which include an anonymous unique identifier. Cookies are sent to a user's browser from our servers and are stored on the user's computer hard drive. Sending a cookie to a user's browser enables us to collect Automatically Collected Data about that user and keep a record of the user's preferences when utilizing our services, both on an individual and aggregate basis.

The Company may use both persistent and session cookies; persistent cookies remain on your computer after you close your session and until you delete them, while session cookies expire when you close your browser.

2. Information you provide us by registering for an account

In addition to the information provided automatically by your browser when you visit the Site, to become a subscriber to the Service you will need to create an account. You can create an account by registering with the Service through our third-party authentication provider. By registering, you are authorizing us to collect, store and use your email address and profile information in accordance with this Privacy Policy.

3. Children's Privacy

The Site and the Service are not directed to anyone under the age of 13. The Site does not knowingly collect or solicit information from anyone under the age of 13, or allow anyone under the age of 13 to sign up for the Service. In the event that we learn that we have gathered personal information from anyone under the age of 13 without the consent of a parent or guardian, we will delete that information as soon as possible. If you believe we have collected such information, please contact us at legal@smtp.dev.

II. How We Use and Share Information

Personal Information

Except as otherwise stated in this Privacy Policy, we do not sell, trade, rent or otherwise share for marketing purposes your Personal Information with third parties without your consent. We do share Personal Information with vendors who are performing services for the Company, such as cloud hosting, authentication, and payment processing providers. Those vendors use your Personal Information only at our direction and in accordance with our Privacy Policy.

In general, the Personal Information you provide to us is used to help us communicate with you. For example, we use Personal Information to contact users in response to questions, provide technical support, and deliver service-related notices through the Site.

We may share Personal Information with outside parties if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable legal process or enforceable governmental request; to enforce applicable Terms of Service, including investigation of potential violations; address fraud, security or technical concerns; or to protect against harm to the rights, property, or safety of our users or the public as required or permitted by law.

Automatically Collected Data

In general, we use Automatically Collected Data to help us improve the Service and customize the user experience. We also aggregate Automatically Collected Data in order to track trends and analyze use patterns on the Site. We may use and disclose Automatically Collected Data in aggregate and anonymized form (where no individual can be identified) at our discretion. Where Automatically Collected Data constitutes personal data under applicable law, we process it in accordance with the legal bases described in Section III.

In the event we undergo a business transaction such as a merger, acquisition by another company, or sale of all or a portion of our assets, your Personal Information may be among the assets transferred. You acknowledge that such transfers may occur and are permitted by this Privacy Policy, and that any acquirer of our assets may continue to process your Personal Information as set forth in this Privacy Policy. If our information practices change at any time in the future, we will post the policy changes to the Site so that you may opt out of the new information practices. We suggest that you check the Site periodically if you are concerned about how your information is used.

If you are located in the EEA or United Kingdom, we process your Personal Information under the following legal bases:

  • Contract performance — Processing necessary to provide the Service to you, including account registration, email processing, and email account hosting.
  • Legitimate interests — Processing necessary for our legitimate interests, such as fraud prevention, abuse detection, service security, and improving the Service, where those interests are not overridden by your rights.
  • Legal obligation — Processing necessary to comply with applicable laws, such as retaining records for anti-abuse and regulatory purposes.
  • Consent — In limited cases where we request your explicit consent to process your Personal Information for a specific purpose. You may withdraw consent at any time by contacting us at legal@smtp.dev.

IV. How We Protect Information

We implement security measures designed to protect your information from unauthorized access. Your account is protected through our third-party authentication provider, and we urge you to take steps to keep your account secure by logging out after each use. We further protect your information from potential security breaches by implementing certain technological security measures including encryption, firewalls and secure socket layer technology. However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security. Nothing in this section limits any rights you may have under applicable data protection law, including GDPR.

V. Your Rights Regarding the Use of Your Personal Information

We do not send marketing or promotional emails. All communications from us are service-related and delivered through the Site.

If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdiction with similar data protection laws, you have additional rights under applicable law, including:

  • Right of access — You may request a copy of the Personal Information we hold about you.
  • Right to rectification — You may request that we correct inaccurate or incomplete Personal Information.
  • Right to erasure — You may request deletion of your Personal Information, subject to the retention requirements described in Section X.
  • Right to data portability — You may request an export of your Personal Information in a structured, commonly used, and machine-readable format.
  • Right to restrict processing — You may request that we limit the processing of your Personal Information under certain circumstances.
  • Right to object — You may object to processing of your Personal Information where we rely on legitimate interests as the legal basis.
  • Right to withdraw consent — Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.

To exercise any of these rights, please contact us at legal@smtp.dev. We will respond to your request within 30 days.

VI. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your Personal Information:

  • Right to know — You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to delete — You may request deletion of your Personal Information. We may retain certain records where permitted by CCPA exemptions, including for detecting security incidents, exercising legal rights, and complying with legal obligations, as described in Section X.
  • Right to opt-out of sale — We do not sell your Personal Information to third parties.
  • Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights.

To exercise these rights, please contact us at legal@smtp.dev. We will verify your identity before processing your request and respond within 45 days.

VII. Email Data

The Service receives and processes inbound email messages on your behalf. We store email metadata (sender, recipient, subject, timestamps), message content, and attachments as necessary to provide the Service. The Service does not send outbound emails to external recipients. We do not read, analyze, or use the content of your emails for advertising or any purpose unrelated to service delivery.

VIII. Third-Party Sender Data

When third parties send email to email accounts hosted on the Service, we receive and store data about those senders, including their email addresses, IP addresses, email content, and message metadata. This data is collected as a necessary part of providing the Service to our users who have configured email accounts to receive such email.

We process third-party sender data on the basis of legitimate interests — specifically, to deliver the email service that our users have requested. We do not use sender data for marketing, profiling, or any purpose unrelated to email delivery and service operation. Sender data is subject to the same security measures and retention policies described in this Privacy Policy.

If you are a third-party sender and wish to inquire about your data, request access, or request deletion, please contact us at legal@smtp.dev.

IX. Sub-processors and Hosting

We use third-party service providers ("sub-processors") to help us operate and deliver the Service, including cloud hosting, authentication, payment processing, and analytics. These sub-processors may process your Personal Information only as necessary to perform their functions and are contractually obligated to protect your data in accordance with this Privacy Policy.

Your data, including email content and account information, is primarily stored and processed in the United States. If you are accessing the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our sub-processors operate. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws, including Standard Contractual Clauses where required.

X. Account Deactivation and Data Retention

You may request to deactivate your account at any time by contacting us at legal@smtp.dev. Upon deactivation, we will remove your personal profile information (name, email address) within 30 days. However, we retain certain operational records — including email logs, IP addresses, account activity history, and transaction records — for abuse prevention and internal compliance purposes. These records may be retained indefinitely in anonymized or pseudonymized form. Full account deletion is not available due to anti-abuse obligations.

XI. Data Breach Notification

In the event of a data breach that compromises your Personal Information, we will notify the relevant supervisory authorities within 72 hours of becoming aware of the breach where required by GDPR, and notify affected users without undue delay as required by applicable law. We will also place a prominent notice on our Site. The notification will describe the nature of the breach, the types of data affected, the measures we are taking in response, and steps you can take to protect yourself.

As part of the Service, we may provide links to or compatibility with other websites or applications. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain. This Privacy Policy applies solely to information collected by us through the Site and the Service. Therefore, this Privacy Policy does not apply to your use of a third party website accessed by selecting a link on our Site or via our Service. To the extent that you access or use the Service through or on another website or application, then the privacy policy of that other website or application will apply to your access or use of that site or application. We encourage our users to read the privacy statements of other websites before proceeding to use them.

XIII. Changes to Our Privacy Policy

The Company reserves the right to change this policy and our Terms of Service at any time. We will notify you of significant changes to our Privacy Policy by placing a prominent notice on our Site. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. You should periodically check the Site and this privacy page for updates.

XIV. Our Role and Data Processing

With respect to the Personal Information and email data we collect and process through the Service, we act as a data controller. We determine the purposes and means of processing your data in order to provide, secure, and improve the Service. If your use of the Service requires a Data Processing Agreement (DPA) for compliance purposes, please contact us at legal@smtp.dev.

XV. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to conflict of law principles. For users in the EEA or United Kingdom, nothing in this Privacy Policy affects your rights under GDPR or the UK Data Protection Act.

XVI. Contact Us

If you have any questions regarding this Privacy Policy or the practices of this Site, please contact us by sending an email to legal@smtp.dev.