Privacy Policy
Last updated: November 4, 2024
1. What We Collect
- Account data: email address, and plan information, when you sign up.
- Domain data: domains you add for monitoring, DNS records we look up publicly (SPF, DKIM, DMARC, MX), and optional custom DKIM selectors you provide.
- DMARC aggregate reports: if you configure your DMARC record to send reports to us, we parse and store only aggregated statistics (message counts, pass/fail counts, source IPs); we never store raw report XML.
- Usage data: IP address (used for free-scan rate limiting), timestamps of scans, and basic analytics.
- Billing data: handled entirely by Dodo Payments, our payment processor and Merchant of Record; we do not store card numbers.
2. How We Use It
We use collected data to:
- Provide scan results, scoring, and fix recommendations.
- Run scheduled monitoring and send you alert emails about record changes.
- Prevent abuse of the free scanning tool via IP-based rate limiting.
- Improve the Service and communicate important account or billing updates.
3. Public DNS Data
SPF, DKIM, DMARC, and MX records are public DNS information by design -- anyone can query them for any domain. Our free scanner only reads this publicly available data and does not access private systems.
4. Data Sharing
We do not sell your personal data. We share data only with service providers necessary to operate MailPosture: Supabase (database & authentication), Resend (transactional email), Dodo Payments (payments), and Vercel/GitHub Actions (hosting & scheduled jobs).
5. Data Retention
Free-tool scan results are cached for 24 hours and not tied to an account. Account data and monitored domain history are retained for as long as your account is active, and deleted within 30 days of account deletion.
6. Your Rights
You may access, correct, export, or delete your account data at any time from Account Settings, or by emailing privacy@getmailposture.com. Depending on your location, you may have additional rights under GDPR, CCPA, or similar regulations.
7. Security
We use industry-standard security practices, including encrypted connections (TLS), Row Level Security on our database so users can only access their own data, and secret-protected internal endpoints for scheduled jobs.
8. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or an in-product notice.
9. Contact
Privacy questions can be sent to privacy@getmailposture.com.