Your webhook is the system of record — we're the pipe. This explains what we collect, how long we keep it, and the per-domain controls you have over the email we process.
Effective date: 2026-07-17
MailKite ("MailKite", "we", "us") provides a developer email platform: we receive inbound email for your domains and deliver it to your webhook, and we send outbound email through our API. This policy explains what we collect, why, how long we keep it, and the choices you have.
MailKite is operated by SendHub LLC, doing business as MailKite, 30 N Gould St #59709, Sheridan, WY 82801, USA.
Questions or requests? Email support [at] mailkite [dot] dev.
We collect three kinds of data:
We use your data only to run the service:
We do not sell your data, and we do not use the contents of your email to build advertising profiles.
By default we keep a parsed copy of each message only long enough for you to replay or debug a delivery, then it auto-expires — 3 days on Free, 30 on Pro, 90 on Scale, and 365 on Business. Inbound attachments are deleted after 7 days. Your webhook is the system of record; MailKite is the pipe.
You can tighten this per domain:
See the Retention & encryption docs for how to enable each.
Connecting Google is optional and entirely under your control. If you click "Sync" next to Google on your Contacts page, we ask Google for read-only access so we can build your MailKite address book. We request only these scopes:
From those contacts we import only each person's name and email address (and, when present, their company) into your own MailKite address book. We use this solely to (a) show you your contacts and (b) suggest recipients when you compose an email. We never use it for advertising, never sell or share it, and never use it to train AI/ML models. Your Google OAuth tokens are encrypted at rest (AES-GCM) and used only to sync your contacts.
You can disconnect Google at any time from your Contacts page, after which we stop syncing, and you can delete imported contacts individually or by deleting your account.
MailKite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We rely on a small set of infrastructure providers to deliver the service. Each processes data only to perform its function:
Outbound mail is signed with DKIM and aligned to SPF and DMARC on your domain using the DNS records set at onboarding, so your mail authenticates as you. Webhook deliveries are signed with HMAC-SHA256 (the x-mailkite-signature header) so you can verify they came from us. Access to the API and webhooks is over TLS.
We use a first-party session cookie (scoped to mailkite.dev) to keep you signed in across the dashboard, docs, and site. We use minimal first-party analytics to understand which links are used. We do not use third-party advertising cookies.
You can access, export, correct, or delete your account data. Deleting a domain removes it and its routes; deleting your account removes your account data and stops processing. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA — email support [at] mailkite [dot] dev to exercise them and we'll respond within a reasonable time.
For email we process on your behalf, you are the controller and MailKite is the processor; we act on your instructions under the terms of our Data Processing Addendum.
Our legal basis for processing account and billing data is performance of our contract with you (the Terms of Service) and our legitimate interest in operating and securing the Service. Where you use MailKite to process personal data of your own end users, you are the controller and MailKite is the processor, acting only on your documented instructions, under our Data Processing Addendum (see "Your rights" above), which incorporates the EU Standard Contractual Clauses for transfers out of the EEA/UK/Switzerland.
Because our subprocessors (Cloudflare, Stripe, Anthropic) operate global infrastructure that includes the United States, personal data may be transferred outside the EEA/UK/Switzerland. We rely on Standard Contractual Clauses and, where applicable, the EU-U.S. and UK-U.S. Data Privacy Framework as the transfer mechanism with each subprocessor.
You have the right to lodge a complaint with your local data protection authority. You can also reach us at support [at] mailkite [dot] dev with any GDPR request.
This section applies to California residents and supplements the rest of this policy. In the preceding 12 months we collected the following categories of personal information, as defined by the CCPA: identifiers (email address, IP address), account credentials, commercial information (billing and subscription records), internet/network activity (API and webhook usage, deliverability signals), and the content of email you send or receive through the Service.
We collected this information for the purposes described in "How we use it" above — to provide the Service, process billing, secure the platform, and communicate with you. We do not sell or share personal information (as those terms are defined by the CCPA), and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose beyond what's necessary to provide the Service.
[object Object]
We keep account and billing records for as long as your account is active and as required for legal, tax, and accounting purposes. Email content follows the retention rules above. Data is processed on our providers' global infrastructure, which includes the United States; contact us about region requirements for enterprise needs. See "GDPR — EU/UK/Swiss users" above for the transfer mechanism we use when data leaves the EEA/UK/Switzerland.
MailKite is a developer tool not directed to children, and is not intended for anyone under 16.
We may update this policy from time to time. Material changes will be announced to your account contact email. The version in effect when you use the service governs that use.
Privacy questions or requests: support [at] mailkite [dot] dev.
See also our Terms of Service, SLA, and Data Processing Addendum.