PRIVACY

Your data in SenderPermit.

Updated September 3, 2026

Draft notice: the legal operator details are awaiting confirmation before public launch.

Who operates the service

SenderPermit is an email infrastructure service in developer preview. Contact the operator through Support with questions about this notice.

Information processed

We process your sign-in email and identity information supplied by your chosen sign-in provider; workspace names and memberships; domain names and DNS verification records; API credential hashes and prefixes; email addresses, subjects, and message content; agent instructions, drafts, policy decisions, approvals, delivery events, usage records, and audit history. Support requests include the text you submit and your sign-in email.

Billing uses Stripe. SenderPermit stores customer and subscription identifiers, plan status, and allowance information. Payment card entry takes place on Stripe-hosted pages; the application does not store full card numbers.

Why information is used

To authenticate users, enforce workspace access, verify domains, deliver and receive email, run configured agent workflows, manage subscriptions, investigate failures and abuse, and respond to support requests. You are responsible for having permission to submit your recipients’ information and message content.

Service providers

Hosting is provided through Sites and Cloudflare. Neon provides application data storage and managed authentication. Resend processes email delivery and receiving. Stripe processes billing. When AI drafting is enabled, message content and agent instructions needed for drafting are sent to OpenAI. Google or ChatGPT processes authentication when you choose that sign-in option. These providers also process information under their applicable terms and privacy notices.

SenderPermit does not include an advertising data sales feature or advertising trackers. This does not limit operational disclosures to the providers above, or disclosures required by law or needed to investigate abuse.

Cookies and access

Authentication cookies keep you signed in. A workspace-selection cookie remembers the active workspace. Provider and hosting services may use cookies and request logs for their own security and operation. You can sign out or clear browser cookies; doing so ends or affects access.

Retention and requests

Email history, audit records, account data, and support requests are retained in the application; the preview does not provide automatic time-based deletion. Use the Privacy or deletion request topic in Support to request access, correction, export, or deletion. Requests require identity verification. Some records may need to be retained for billing, security, legal obligations, or backups; the operator will explain applicable limits when handling a request. No fixed deletion or response deadline is promised by this preview notice.

Location and security

The current application database is hosted in the United States. Hosting, authentication, and other providers may process data in other locations. Workspace authorization, hashed API credentials, and signed webhooks help protect access, but no system can guarantee absolute security. Keep secrets out of support requests and revoke exposed API keys.

Changes

Updates will be posted here with a revised date. Material changes to data use require appropriate notice and any consent required by applicable law.

Contact support about privacy →