Privacy Policy
Last updated: September 25, 2026
This Privacy Policy describes how Emailens (email preview and email QA software operated at emailens.dev and app.emailens.dev) collects, uses, stores, and shares information when you use our website, web application, API, and related products.
Introduction
Emailens ("we", "us", "our") operates the emailens.dev website and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using Emailens, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Service.
This policy applies to Emailens at emailens.dev (marketing and legal pages) and app.emailens.dev (web application, API, and authenticated features).
Summary of data we collect and why
Emailens is an email preview and QA platform for developers. We collect and process the categories below solely to operate the Service, secure accounts, and improve product functionality. We do not sell personal information.
- Identity & account data (email, name, profile photo, hashed password or OAuth identifiers) — create and secure your account, billing, and support.
- Email source & preview content (HTML, MJML, JSX, templates, prompts) — generate client previews, scores, screenshots, and AI-assisted fixes you request.
- Email Sandbox & staging data (captured MIME payloads, headers, HTML/plain text, attachments, extracted OTPs) — ingested via Direct Inbound MX or authenticated SMTP relay (port 2525) for staging inspection, CI assertion, and rendering simulation; purged after your plan retention window.
- Usage & billing data (preview counts, plan tier, API usage) — enforce plan limits and process subscriptions via Polar.sh.
- Technical & log data (IP address, browser type, timestamps) — security, abuse prevention, and reliability.
- Analytics (page views, feature events; optional via cookie consent) — understand how the product is used and fix bugs.
- Communications (support messages, transactional email delivery metadata) — respond to you and send account-related email.
Where the Service is hosted
The marketing site (emailens.dev) is served from Cloudflare Pages with Cloudflare CDN and TLS at the edge.
The web application and API (app.emailens.dev) run in Docker containers on a Hostinger KVM virtual server in Europe, managed with self-hosted Coolify.
Sign in with Google (Google user data)
If you choose "Sign in with Google" on Emailens, we access information from your Google account through Google's OAuth sign-in. Emailens does not access Gmail, Google Drive, Google Calendar, Google Contacts, or Google Workspace APIs.
Google user data we access
- Your Google account email address
- Your display name
- Your profile picture URL
- A stable Google account ID to link your Google login to your Emailens account
How we use Google user data
- Authenticate you and maintain your Emailens account
- Display your name and photo in the app
- Associate previews, API keys, and subscriptions with your account
- Send service-related email to your Google email address
- Enforce plan limits and prevent abuse
If you accept analytics cookies, we may send your Emailens user ID and the name and email on your profile to our self-hosted OpenPanel instance for product analytics. When cookies are declined, Google profile data is not sent to OpenPanel.
We do not use Google user data for advertising, selling to data brokers, credit decisions, or training generalized AI/ML models.
How we share, transfer, or disclose Google user data
We do not sell Google user data. We disclose it only to service providers that help us operate Emailens, and only for the purposes described above:
- Supabase — account storage (name, email, profile image, Google account linkage)
- Resend — transactional email to your address
- Polar.sh — subscription billing linked to your account email, if you pay for a plan
- OpenPanel (self-hosted) — only if you accept analytics cookies, for product usage analytics
We do not transfer or disclose Google user data for advertising, data brokerage, credit decisions, or training generalized AI or machine learning models.
How we protect Google user data
Google user data is protected with HTTPS/TLS in transit, encrypted database connections, hashed API keys, and secure HTTP-only session cookies. See the "Data security" section below for more detail.
Google user data retention and deletion
We retain Google-derived profile data while your Emailens account is active. When you delete your account, we delete Google-derived fields within approximately 30 days (see "Data retention"). You can revoke Emailens's access to your Google account at any time in Google Account permissions.
Emailens's use of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.
Information we collect
Information you provide
- Account information, when you create an account, you may sign up with your email address and password or sign in with Google or GitHub. If you authenticate via Google or GitHub, we receive your name, email address, and profile picture from the OAuth provider. For email and password accounts, we store your email address and a cryptographically salted and hashed password.
- Email content & templates, when you use our preview, QA, preflight, or AI builder features, you submit HTML, React Email JSX, MJML, or Maizzle source code, design briefs, or email templates. This content is processed to generate previews, compatibility reports, and AI-assisted code fixes. For authenticated users, preview data is stored for 30 days. For unauthenticated users, preview data is processed in-memory and not persisted long-term.
- AI generation prompts, if you use the AI Email Builder or AI Fix features, you submit text prompts, layout instructions, and error diagnostics. These prompts are processed via our AI service provider (Anthropic) solely to generate fixes and layout code. Content processed through these APIs is never used to train foundation AI models.
- Domain monitoring configuration, if you configure deliverability monitoring, we store your domain names to query public DNS records (SPF, DKIM, DMARC, MX) and track email authentication status over time.
- Newsletter subscription, if you subscribe to our newsletter, we collect your email address. This is stored separately from your account and is used only to send you occasional email development tips.
- Payment information, if you subscribe to a paid plan, payment is processed by Polar.sh. We do not store credit card numbers or payment details directly.
Information collected automatically
- Usage data, we track the number of previews and AI actions you generate per day or month to enforce plan limits. This is stored as aggregate counts and billing records.
- Analytics data, we use a self-hosted instance of OpenPanel to understand product usage, monitor features, and improve our service. For signed-in users, we associate your account ID, email address, and subscription tier with analytics sessions so we can assist with support and track account cohorts. Analytics scripts run conditionally and can be declined via our cookie consent banner.
- Log data, Cloudflare (marketing and edge) and Hostinger (application server) may process standard request logs including IP addresses, user agents, and timestamps. Retention follows each provider's policies and our internal log rotation.
Figma Plugin
When you use the Emailens Figma plugin, the following data is collected:
- Design content, the plugin reads the structure, text, images, and styles of the Figma frame you select. This content is sent to the Emailens API for HTML conversion and preview rendering. Design content is not stored persistently unless you create a share link.
- Uploaded images, images extracted from your Figma design are uploaded to Cloudflare R2 for use in the generated email HTML. These images are automatically deleted after 30 days.
- Plugin telemetry, the plugin sends anonymized usage events (e.g., "preview started", "conversion completed") to help us improve the plugin. Telemetry includes frame dimensions, node counts, and error messages but no personally identifiable information and no design content.
- Rate limiting identifier, for anonymous users (without an Emailens account), we use your IP address or Figma user ID solely for rate limiting (15 previews per day from the Figma plugin and the browser extension, 3 from the website). This identifier is not stored long-term.
- API key, if you sign in via the plugin, a plugin-specific API key is generated and stored in Figma's client storage on your device. The key is hashed before storage in our database and can be revoked from your Emailens dashboard at any time.
Chrome Extension
When you use the official Emailens Chrome Extension (Chrome Web Store ID: iklclpegcjniegapiocpdfomplceigij), the following data is processed and collected:
- Email markup content, the extension parses the HTML DOM structure of the email template open in your browser tab (either auto-detected or manually highlighted via Inspect Mode). This code is securely transmitted to the Emailens API servers over TLS/HTTPS to compile preflight compatibility audits. Unauthenticated previews are processed in-memory server-side and never saved in our database.
- Browser context & safety, the extension only accesses tabs where you explicitly trigger a Preflight audit or activate Inspect Mode. We never read passwords, session cookies, bank details, or unrelated browsing history. We run audits locally inside sandbox viewports.
- Extension telemetry, we collect anonymized operational data (e.g. extension versions, total audits completed) to debug features. Telemetry contains no personal identifiers or email contents.
- IP address hashing, for unauthenticated users, we use a hashed representation of your IP address solely to enforce our daily rate limiting guidelines (15 previews per day from the Figma plugin and the browser extension, 3 from the website).
Model Context Protocol (MCP) Server
The Emailens MCP Server operates entirely locally on your machine, integrating with Claude Code, Cursor, or Claude Desktop:
- Local-first processing, core tools such as CSS compatibility audits and syntax checks run locally via the open-source offline engine. No email source code is uploaded to Emailens servers.
- Hosted features (Optional), if you set a local
EMAILENS_API_KEY, the server securely communicates with our hosted API to fetch real browser previews or generate share links. These screenshots and preview structures are stored in our secure Cloudflare R2 bucket and naturally expire after 30 days.
How we use your information
- Provide the Service, process your email source code, generate client previews, and deliver compatibility reports.
- AI generation & code fixing, generate email designs from natural-language prompts and provide automated code fixes for client-specific CSS incompatibilities via Anthropic APIs.
- Deliverability & domain monitoring, query public DNS records (SPF, DKIM, DMARC, MX) to verify email sender authentication and alert you to configuration regressions.
- Authentication, manage your account, maintain your session, and associate previews with your account.
- Usage enforcement, track daily and monthly preview and AI action usage against your plan limits.
- Service improvement, analyze aggregated usage patterns to improve features, fix bugs, and optimize performance.
- Communication, send service-related emails such as account verification, password resets, domain alerts, plan changes, or critical security notices. If you subscribe to our newsletter, we send periodic email development content. We do not send unsolicited marketing emails.
- Security, detect and prevent abuse, fraud, and unauthorized access through rate limiting and monitoring.
How we share your information
We do not sell your personal information. We share data only in the following circumstances:
- Service providers, we use third-party
services to operate Emailens:
- Cloudflare, marketing site (Pages), CDN, TLS, and R2 storage
- Hostinger, EU KVM server hosting app.emailens.dev (via Coolify)
- OpenPanel, self-hosted product analytics
- Supabase, managed database hosting (PostgreSQL) and real-time state synchronization
- Cloudflare R2, secure screenshot and image asset storage
- Browserless, headless browser rendering for email screenshot capture
- Polar.sh, payment processing, checkout, and subscription lifecycle management
- Upstash, Redis-backed rate limiting and quota throttling
- Resend, transactional email delivery (verification emails, password resets, domain alerts, quota notices) and bounce/complaint suppression management
- Anthropic, large language model API provider powering the AI Email Builder and AI Fix features (user data is transmitted securely via API and is not used to train foundation models)
- Inngest, background workflow orchestration and scheduled jobs (handles asynchronous builder runs, deliverability monitoring, and automated data cleanup)
- Share links, if you create a share link for a preview, the preview content (per-client transformed HTML, compatibility scores, dark mode variants, and analysis reports) becomes accessible to anyone with the link. Share links expire based on your plan (24 hours for free, 7 days for Dev, permanent for Pro).
- Legal requirements, we may disclose information if required by law, regulation, legal process, or governmental request.
Data retention
- Preview data, stored for 30 days from creation for authenticated users, then automatically deleted. Unauthenticated preview data is processed server-side in-memory but not persisted in our database. Screenshots generated during any preview are stored in Cloudflare R2 with the same 30-day retention.
- Email Sandbox messages & attachments, staging emails ingested via Direct Inbound MX or authenticated SMTP relay are retained for your plan retention duration (7 to 30 days) and then permanently deleted by automated database pruning jobs. You may also delete individual messages or whole sandbox inboxes at any time with immediate effect.
- SMTP Relay credentials, credentials generated for sandbox SMTP access are stored strictly as SHA-256 cryptographic hashes. Passwords are never stored in plaintext and cannot be recovered. Revoked or rotated credentials are permanently invalidated immediately.
- Account data, retained as long as your account is active. If you delete your account, we delete your personal data, cancel any active Polar subscriptions, and remove your customer records within 30 days.
- Screenshots & assets, stored in Cloudflare R2 and automatically deleted when the associated preview expires (30 days).
- Domain monitoring logs, email check and domain scan histories are retained for 90 days, after which older records are automatically pruned.
- Marketing logs & suppressions, logs of marketing sends are pruned after 14 days (retained solely to enforce our weekly frequency cap). Unsubscribe and suppression records are retained to permanently honor opt-out preferences and prevent accidental sends to bounced or complaining addresses.
- Usage counts, daily usage records are retained for billing and abuse prevention purposes.
- Newsletter emails, retained until you unsubscribe. You can unsubscribe at any time using the one-click unsubscribe link in any email or by contacting us.
Data security
We implement appropriate technical and organizational measures to protect your information, including:
- All data in transit is encrypted via HTTPS/TLS.
- Database connections use encrypted connections to Supabase.
- API keys are hashed before storage and cannot be retrieved in plaintext.
- Session tokens use secure, HTTP-only cookies with SameSite protection.
- Rate limiting and IP-based throttling protect against abuse.
However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Email Sandbox, Staging Ingestion & Synthetic Data
The Emailens Sandbox provides developer testing environments (via Direct Inbound MX and Authenticated SMTP Relay on port 2525) to safely capture staging emails:
- Safe Non-Forwarding Architecture: The SMTP relay operates strictly as a dead-end testing sink. Messages routed to the relay are quarantined in your private sandbox and are never transmitted to external mail transfer agents or public recipient addresses.
- Recommendation for Synthetic Test Data: The Sandbox is engineered for pre-production software development, CI/CD end-to-end testing, and QA validation. Users should use synthetic or mock email addresses and avoid transmitting live production passwords or unconsented sensitive personal data through test mailboxes.
- Tenant Isolation & Access Controls: Captured emails, parsed MIME headers, and extracted authentication tokens are strictly partitioned by account and inbox ID. Other users cannot discover or access your sandbox messages.
- STARTTLS Transport Security: Authenticated SMTP relay connections must establish TLS 1.2+ encryption before transmitting credentials or message content. Unencrypted plain-text authentication attempts are terminated immediately.
Your rights
Depending on your location, you may have the following rights:
- Access, request a copy of the personal data we hold about you.
- Rectification, request correction of inaccurate personal data.
- Erasure, request deletion of your personal data and account.
- Portability, request your data in a structured, machine-readable format.
- Objection, object to processing of your personal data for specific purposes.
- Withdraw consent, where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at support@emailens.dev . We will respond within 30 days.
Children's privacy
Emailens is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete that information promptly. If you believe we may have collected data from a child, please contact us at support@emailens.dev .
International data transfers
Your information may be transferred to and processed in countries other than your country of residence. Our service providers (Cloudflare, Hostinger, Supabase, and other providers listed above) operate globally. When we transfer data, we ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
Contact us
If you have questions about this Privacy Policy or our data practices, contact us at support@emailens.dev .
See also: Terms of Service / Cookie Policy / Security & Trust