We collect what we need to run an email service and nothing for advertising. For email our customers send, we act on their instructions.
Legal
Privacy Policy
Last updated:
01Who we are
AgentSend ("AgentSend", "we", "us") runs agentsend.co and the AgentSend dashboard, REST API, MCP server, and CLI (the "Service"). This policy explains what personal data we handle, why, who we share it with, and the choices you have. Contact us at hello@agentsend.co.
02Our role
- Controller for account data. We decide how to use the data of people who sign up, use the dashboard, pay for a plan, or visit our website.
- Processor for customer email data. When a customer sends email through AgentSend, we process the messages and the recipient and contact data in them on that customer's behalf and on their instructions, to deliver mail and report what happened to it. The customer decides who to email and why.
03If you received email sent through AgentSend
The business that emailed you controls your data. Use the unsubscribe link in its email, or contact it directly to access or delete your data. If you can't reach the sender, email hello@agentsend.co: we will pass your request to them, and we can add your address to that sender's suppression list. To report unwanted or malicious email, write to abuse@agentsend.co.
04What we collect
- Account data. Your email address and password (stored by our sign-in provider as a salted hash, never in plain text), sign-in session cookies, and, if you request live sending, your company name, website, use case, expected volume, sending domain, and the date and version of the Terms and Acceptable Use Policy you accepted.
- Billing data. Stripe collects your payment details directly. We store your Stripe customer ID, billing email, plan, and subscription status, never your full card number.
- API and usage data. API key names, prefixes, and permissions (keys are stored only as SHA-256 hashes after we show them to you once), send counts, budgets, guardrail results, and your account's events. Our hosting provider records request logs that include IP address, user agent, and the requested path.
- Customer email data, processed on our customers' behalf: sender and recipient addresses (to, cc, bcc, and reply-to), subject lines, HTML and text bodies, custom headers, and tags; attachment file names, types, and sizes (the files themselves are passed to Amazon SES at send time and not kept in email logs); audiences and contacts (email address, first and last name, subscription status); delivery events (delivered, bounced, complained, opened, clicked, unsubscribed); suppression lists; and webhook endpoints and deliveries. To report opens and clicks on live mail, Amazon SES adds a small tracking image to HTML email and routes links through a redirect that records the click.
- Website analytics. On the production site, agentsend.co, Google Analytics 4 loads only after you accept analytics cookies in our cookie banner; if you reject them or have not chosen, it does not load. Once you accept, it collects page views, referrers, device and browser details, and approximate location derived from IP address, using its own cookies, and we record product milestones (such as an API key created, a domain added, a first email sent, a broadcast sent, or a live-sending request) without names, email addresses, domains, or message content. Preview and local builds do not load Google Analytics.
- Messages to us. When you email us for support or to report abuse, we keep the conversation.
05How we use it
- To provide the Service: sign you in, send and deliver email, deliver webhooks, and enforce plan limits.
- To run guardrails: automated checks on content, duplicates and loops, budgets, and suppression before each send.
- To prevent abuse and enforce the Acceptable Use Policy: review live-sending requests, monitor bounce and complaint rates, and investigate reports.
- To bill you, provide support, and tell you about security, billing, and policy changes.
- To understand how the website and product are used, in aggregate, and improve them.
- To comply with the law.
Where the GDPR applies, we rely on performance of our contract with you, our legitimate interests in running a secure, abuse-free service and improving it, compliance with legal obligations, and, for analytics cookies, your consent.
We do not sell personal data or share it for cross-context behavioral advertising. We do not use customer email data for advertising or to train machine-learning models. People at AgentSend look at customer email content only when needed to investigate abuse, answer a support request you make, or comply with the law.
06Sub-processors
We use these providers to run the Service:
| Provider | Purpose | Data |
|---|---|---|
| Amazon Web Services | Email delivery (Amazon SES) and delivery-event notifications (Amazon SNS), in us-east-1 (N. Virginia, United States) | Customer email data |
| Supabase | Database and sign-in | Account data, usage data, customer email data |
| Vercel | Website and API hosting, request logs | All data the Service handles, including request logs |
| Stripe | Payments, subscriptions, and invoices | Billing data and account email |
| Google Analytics | Website analytics on agentsend.co | Website analytics data |
We update this list before a new provider starts processing customer email data. We also share data when the law requires it, to protect the Service and its users from abuse (including with Amazon Web Services when that is needed to protect the delivery infrastructure), and with a successor if AgentSend is reorganized, including into a newly formed legal entity, or acquired.
07Retention
- Email content (message bodies, headers, and attachments) and delivery events: your plan's log retention period, which is 1 day on Free, 30 days on Pro, and 90 days on Scale, or as agreed for Enterprise.
- Email delivery records (recipient addresses, subject, status, timestamps, and provider message IDs): for the life of the account, because we need them for billing, usage limits, suppression, and abuse investigations. They are deleted when the account is closed.
- Suppression lists: for the life of the account, so suppressed recipients stay suppressed.
- Audiences, contacts, domains, and webhooks: until the customer deletes them or closes the account.
- Account data: while the account is open, and deleted within 30 days of closing it, except billing records and records we must keep by law, to resolve disputes, or to enforce our terms (such as records of abuse).
- Request logs and analytics data: for the retention periods set by our hosting and analytics providers.
08Your rights and deletion requests
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict how we use it. To make a request, including a request to delete your account and its data, email hello@agentsend.co from your account's sign-in address. We verify the request and respond within 30 days. You can also delete your account yourself in the dashboard under Settings → Account.
If you are in the EU, the UK, or Switzerland, you can also complain to your data protection authority. California residents have the rights to know, delete, and correct their personal information and will not be treated differently for using them. You can withdraw your analytics consent at any time with Cookie settings at the bottom of any page on agentsend.co, or stop Google Analytics everywhere with Google's opt-out browser add-on.
10Security
Data travels over TLS. Our database and delivery providers encrypt it at rest. Every query is scoped to the account that owns the data, Postgres row-level security limits signed-in users to their own rows, API keys are stored only as hashes, webhook payloads are signed with HMAC-SHA256, and live mail is DKIM-signed for the customer's domain. Access to production data is limited to the people who operate the Service.
No system is perfectly secure. Report security issues to hello@agentsend.co.
11International transfers
AgentSend is based in the United States. Amazon SES processes email in us-east-1, in the United States, and our other providers process data in the United States and in other countries where they operate. When we transfer personal data from the European Economic Area, the UK, or Switzerland, we rely on the Standard Contractual Clauses or another lawful transfer mechanism offered by our providers.
12Children
The Service is for businesses and developers and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email hello@agentsend.co and we will delete it.
13Changes to this policy
We may update this policy. The date at the top of this page shows the latest version, and we announce material changes by email or in the dashboard before they take effect.
14Contact
Privacy questions and requests: hello@agentsend.co. Abuse reports: abuse@agentsend.co.
Also see: Terms of Service · Acceptable Use Policy