/legal
Privacy Policy
01Who we are
JustSMTP Inc., Wilmington, DE, is the controller of the data described here. Reach us at privacy@justsmtp.com.
02Account data
We store the email address you sign in with, the domains you add for sending, and metadata about each SMTP credential pair — its label, when it was created and when it was last used. Credential secrets are stored only as a one-way hash; we cannot recover one for you.
Sign-in is by login link, so we hold no password of yours at all.
03Message data
A message you relay exists in memory for as long as it takes to hand it to our upstream provider. The body is not written to disk and is not retained afterwards.
What we do keep, per message, is the envelope sender and recipient, the subject line, the size, the timestamp, the delivery outcome and the upstream SMTP response. That is what the activity log shows you, and it is what lets either of us answer "what happened to this message".
04Retention
Activity log entries are kept for the window your plan carries — 7, 30 or 90 days — and are then deleted. Account data is kept while the account exists. Delete the account and we remove the account record and its remaining log entries; backups age out on their own schedule within 35 days.
05Processors
Amazon Web Services (SES, and hosting) processes message data as our upstream delivery provider. Our identity provider handles the login-link flow and sees only your email address. We add no analytics, no advertising network and no third-party script to this site — the pages you are reading load nothing from another origin.
06Your rights
Depending on where you live you may have rights of access, correction, deletion, portability and objection. Write to privacy@justsmtp.com and we will answer within 30 days. You do not need an account with us to ask whether we hold data about you.
If you are a recipient rather than a customer, we hold data about you only as our customer's processor; we will pass your request to them and tell you we have done so.
07Security
Transport is TLS throughout: STARTTLS on the relay, HTTPS on this site and on the dashboard. Credential secrets and login tokens are stored hashed. Access to production data is limited to the people who operate the service and is logged.
08Changes
We may update this policy with 30 days' notice by email to your account address. Material changes to what we collect or how long we keep it will always be notified, not merely posted.