Draft — to be reviewed by counsel before publication

Privacy policy

This draft describes the transactional email API. It is not a notice to publish. Counsel fills the remaining entity details and the legal bases before publication.

Controller for account and billing data: MB Tobuli, company code [Company code], [Registered address], VAT [VAT number], [Contact email].

For the content of a customer's messages, the customer is the controller and MB Tobuli is the processor. That split is to confirm by counsel. Processor terms are in the Data processing agreement.

Data we process

The current database stores:

The worker builds raw MIME and sends it to the email provider. The binary does not write that MIME to object storage. Terraform defines a private bucket sendtier-<environment>-raw-mime with a 30-day expiry. Treat that bucket as unused until a writer exists. To confirm.

The product database stores organization members: user id, auth_subject, email, and membership role. auth_subject is the sign-in subject on the users table. Dashboard sign-in is implemented. Its session store is separate from these message tables. Session cookies are in the Cookie policy. When the sign-in bot check is configured, the dashboard loads a Cloudflare Turnstile challenge and submits the challenge token to Cloudflare. The Turnstile Privacy Addendum (accessed 2026-10-07) says Turnstile processes the client IP address, TLS fingerprint, User-Agent, site key, and the site key's origin. Cloudflare is the processor for providing the check and the controller for improving detection. The addendum does not name a cookie.

Why we process it

We process message data to send the message, to record delivery, bounce, and complaint, and to suppress addresses that hard-bounced or complained. We process account data to authenticate API keys. Legal bases are to confirm by counsel. Do not publish a basis until counsel names it.

Where

The product decision is EU-only processing in eu-central-1. Queue, notification topic, configuration set, and the raw-MIME bucket are defined in that Region.

The worker stores a tenant id in a Valkey send-admission key. The key has no message content and no address. Terraform defines ElastiCache Serverless Valkey in eu-central-1. See ADR-0016 (docs/adr/0016-send-rate-limiting.md).

Terraform also defines production compute and the production database in eu-central-1. Applying that configuration to a live account is to confirm at launch. See Subprocessors.

How long

Idempotency rows last 24 hours. Cron then deletes a row whose created_at is older than 24 hours.

Message rows, event rows, webhook delivery rows, and webhook delivery attempt rows sit in daily partitions. Cron drops a UTC day older than SENDTIER_RETENTION_DAYS. The minimum is 4 days. The default is 30 days. The cutoff day is kept. The drop applies to every tenant. It is not a delete for one account.

Suppression rows are kept until removed. The API can delete a suppression. A global suppression also exists for the same address. Removing the tenant row does not remove the global row.

The raw-MIME bucket lifecycle is 30 days. The binary does not write that bucket.

CloudWatch log groups for the service roles, and the database-url log group, keep logs for 30 days.

A dashboard owner can export the organization's retained data and can schedule deletion. purge_at is 720 hours (30 days of 24 hours) after the first deletion request. Restore is available strictly before that time. After the window, cron deletes that tenant's rows. The time is the earliest purge, not a completion guarantee. Other requests still go to [Contact email]. The response time is to confirm by counsel. Periods for messages, events, webhook deliveries, idempotency keys, logs, and account deletion are on the Data retention page.

Cookies

The API uses Authorization: Bearer and does not set a browser cookie for the key. The marketing site and the dashboard session are described in the Cookie policy. Optional analytics and advertising tags on public marketing and documentation pages load only after the matching consent.

Recipients

Subprocessors are listed in Subprocessors. Stripe, when billing is enabled, is a separate controller or processor for payment data. Its transfer mechanism is to confirm by counsel. Billing is not integrated.

Your requests

Email [Contact email] to access, correct, delete, or export personal data, or to object. A dashboard owner can also export that organization and schedule its deletion. Counsel confirms which other requests we must honor for controller data and which we pass to the customer for message data.

Changes

Counsel publishes the final notice with a date. This file has no effective date.