Get Started
Back to home
Trust & Infrastructure

Security & Trust

Last updated: September 7, 2026 · Built with official compliance standards & radical technical transparency

Anthropic
Anthropic Commercial Terms

Zero AI Model Training

Your email HTML, templates, and prompts processed via AI Fix and AI Builder are never used to train foundation models.

Polar
Polar.sh Merchant of Record

PCI-DSS Level 1 Payments

All transactions run through Polar.sh and Stripe. Payment card details never touch or pass through Emailens servers.

In-Memory Parsing

Ephemeral by Default

Unsaved previews process in-memory. Authenticated previews and screenshots auto-expire and purge after 30 days.

Cloudflare
TLS 1.3 · AES-256

Encryption in Transit & Rest

Every HTTP connection is strictly encrypted via Cloudflare TLS 1.3. Databases and object storage are encrypted at rest with AES-256.

European Union (GDPR)
EU Standard Contractual Clauses

GDPR & Data Rights

Instant JSON account export and one-click account deletion. Standard Data Processing Addendum (DPA) available.

GitHub
MIT Licensed

Open Source Engine

Our core CSS compatibility matrix and parser are public code. Anyone can audit our rendering rules and sanitization.

Our Security Philosophy

Email developers trust Emailens with pre-release transactional templates, product launch announcements, and critical design assets. Instead of burying our security practices behind opaque marketing claims or paid audit logos, we believe in radical technical transparency: providing clear, verifiable information on how your data moves through our infrastructure, where it is stored, and when it is destroyed.

Anthropic

Generative AI & Zero Model Training Guarantee

Emailens offers optional AI-powered features, including AI Fix (which automatically patches unsupported CSS properties for target email clients) and the AI Builder (natural language template scaffolding and styling).

Anthropic

Anthropic Commercial API Terms

All AI requests are routed directly to Anthropic's commercial Claude API. Under Anthropic's commercial agreements, no customer inputs (prompts, HTML, or CSS) or generated outputs are ever used to train Anthropic's AI or machine learning models. Your proprietary template markup and email designs remain exclusively yours.

Inputs sent to AI endpoints are processed in-flight. We do not maintain any secondary vector databases, fine-tuning corpora, or offline training datasets of user emails.

Data Lifecycle & Ephemeral Previews

Emailens is built around a principle of data minimization: we store only what is strictly necessary to provide you with preview results and account functionality.

  • Unauthenticated Previews: Processed 100% in-memory in serverless edge functions. Raw HTML code is parsed against our CSS compatibility matrix, rendered, and discarded immediately after the HTTP response closes. No record is written to PostgreSQL.
  • Authenticated Previews & Screenshots: When signed in, preview records and high-resolution screenshot renders (stored in Cloudflare R2) are retained to allow you to review historical checks. These assets are subject to a strict 30-day automatic deletion policy.
  • Domain Health Checks: SPF, DKIM, and DMARC inspection records are automatically pruned after 90 days.
  • Test Sends: Inbound test emails routed through our preview inbox are automatically purged from our database within 14 days.
Polar Stripe

Payment Isolation & PCI-DSS Compliance

Emailens uses Polar.sh as our Merchant of Record (MoR) for all paid subscriptions and transactions, backed by Stripe infrastructure.

Zero Financial Data Exposure · PCI-DSS Level 1 Isolation

Credit card numbers, bank account details, and billing credentials are typed directly into Polar's hosted PCI-DSS Level 1 certified checkout environment. Emailens servers, databases, and logs never see, transmit, or store payment card numbers or CVCs. Polar handles sales tax, EU VAT collection, and statutory invoice generation on our behalf.

Cloudflare Supabase Vercel

Infrastructure & Encryption

Emailens is hosted on modern, resilient cloud infrastructure providers adhering to ISO 27001, SOC 2 Type II, and GDPR standards:

Cloudflare

Data in Transit (Cloudflare)

Forced HTTPS with TLS 1.3 encryption across all web interfaces, REST APIs, and webhook endpoints. Strict HSTS headers prevent downgrade attacks.

Supabase

Data at Rest (Supabase & R2)

Primary relational database (Supabase PostgreSQL) and media storage (Cloudflare R2) are encrypted at rest using industry-standard AES-256 encryption.

Vercel

Hosting & Compute (Vercel)

Frontend applications and serverless compute run on Vercel's global edge network with automated DDoS mitigation, web application firewalls, and isolated runtime containers.

GitHub

Authentication Security

Powered by Better Auth with cryptographically salted and hashed passwords (Argon2id / bcrypt), secure HTTP-only cookies, and OAuth 2.0 PKCE verification for Google and GitHub.

European Union (GDPR)

GDPR Compliance & Data Rights

We fully comply with the European Union General Data Protection Regulation (GDPR) and UK GDPR. We provide self-serve tools so you can exercise your privacy rights at any time:

  • Right to Access & Portability: You can download a complete machine-readable JSON export of your user profile, saved templates, test histories, and API key metadata at any time via our self-serve endpoint at /api/user/export.
  • Right to Erasure ("Right to be Forgotten"): You can permanently delete your account from your account settings. Deletion triggers an immediate cascading purge of all associated database records, active sessions, API keys, and Cloudflare R2 screenshots.
  • Data Processing Addendum (DPA): If your organization requires a formal DPA incorporating Standard Contractual Clauses (SCCs) for enterprise compliance, we provide our standard template upon request. Email [email protected] .
GitHub

Open Source Verification

Trust is earned through inspectability. The core rule engine behind Emailens, which evaluates CSS compatibility against 21 major desktop, mobile, and web email clients, is open source under the MIT license:

GitHub github.com/emailens/engine ↗

Anyone can inspect our parser logic, review our client compatibility datasets, or verify that our CSS parsing routines are deterministic and completely free of tracking code or covert analytics.

Vulnerability Disclosure & Bug Bounty

We take the security of our platform and users seriously. If you discover a security vulnerability in Emailens, please report it to us responsibly before any public disclosure:

Security Team Contact

[email protected]

We commit to acknowledging your report within 48 business hours and will not pursue legal action against security researchers acting in good faith.

See also: Privacy Policy / Terms of Service / Cookie Policy