Legal
Privacy Policy
Kleevee carries mail, so we necessarily hold the contents of your mailboxes. This explains what we store, why, for how long, and who else ever sees it.
Last updated 7 September 2026
01Who is responsible for what
For your account details — your name, your email address, your billing information — we are the data controller.
For the contents of your mailboxes, we are a data processor acting on your instructions. You decide who your agents write to and what they say. If the people your agents contact are in the EU or UK, you are the controller for their data and the obligations that come with that are yours.
02What we store
Account data. Your name, email address, hashed password, chosen subdomain, plan, and API key fingerprints. We never store an API key or a password in a form we can read back.
Mail content. The full MIME body of every message sent and received through your inboxes, including headers, attachments and calendar invitations. This is the service; we cannot deliver mail without holding it.
Delivery metadata. Recipients, timestamps, SMTP responses, the receiving server, whether the connection was encrypted, and bounce or complaint reports from receiving providers.
Operational logs. API requests, IP addresses and error traces, kept for security and debugging.
03Why we hold it
To deliver, receive, thread and store your mail; to enforce quotas and the Acceptable Use Policy; to maintain the suppression list that protects deliverability; to investigate abuse and security incidents; and to bill you.
We do not sell your data. We do not use the contents of your mailboxes for advertising. We do not train machine learning models on your mail.
04Who can see your mail
Access to stored message content is restricted to the small number of staff who need it to operate the service, and is exercised only to investigate a fault you have reported, to respond to a security or abuse incident, or where the law requires it.
We use subprocessors to run the service: cloud hosting and managed database (Google Cloud), and outbound mail relay (Amazon Web Services). They process data on our instructions under their own contractual commitments. Mail necessarily also passes to the receiving provider of whoever your agent writes to — that is what sending an email means.
If we are compelled by legal process to disclose data, we will tell you unless we are prohibited from doing so.
05How long we keep it
Message content is retained for your plan’s retention window, after which it is deleted. Delivery metadata and suppression entries are kept longer, because a suppression list only works if it remembers.
Delete your account and we remove your mailboxes and their contents within 30 days, except where we must keep records for legal or accounting reasons.
06Security
Passwords are hashed. API keys are stored hashed and shown once. Traffic to our API is TLS-only. Outbound mail is relayed over authenticated TLS and DKIM-signed before it leaves. Databases and stored message bodies are encrypted at rest by our infrastructure providers.
Mail delivered to a receiving server that does not support TLS travels unencrypted on that final hop — this is a property of email itself, not of Kleevee. Our delivery records show you which messages were affected.
07Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. Write to privacy@kleevee.com and we will respond within 30 days.
If a recipient of mail sent through your account asks us to exercise their rights, we will refer them to you, since you are the controller of that relationship.
08Contact
Privacy questions: privacy@kleevee.com. The rules about what may be sent through Kleevee are in our Acceptable Use Policy.