Security & Trust
Last updated: September 7, 2026 · Built with official compliance standards & radical technical transparency
Zero AI Model Training
Your email HTML, templates, and prompts processed via AI Fix and AI Builder are never used to train foundation models.
PCI-DSS Level 1 Payments
All transactions run through Polar.sh and Stripe. Payment card details never touch or pass through Emailens servers.
Ephemeral by Default
Unsaved previews process in-memory. Authenticated previews and screenshots auto-expire and purge after 30 days.
Encryption in Transit & Rest
Every HTTP connection is strictly encrypted via Cloudflare TLS 1.3. Databases and object storage are encrypted at rest with AES-256.
GDPR & Data Rights
Instant JSON account export and one-click account deletion. Standard Data Processing Addendum (DPA) available.
Open Source Engine
Our core CSS compatibility matrix and parser are public code. Anyone can audit our rendering rules and sanitization.
Our Security Philosophy
Email developers trust Emailens with pre-release transactional templates, product launch announcements, and critical design assets. Instead of burying our security practices behind opaque marketing claims or paid audit logos, we believe in radical technical transparency: providing clear, verifiable information on how your data moves through our infrastructure, where it is stored, and when it is destroyed.
Generative AI & Zero Model Training Guarantee
Emailens offers optional AI-powered features, including AI Fix (which automatically patches unsupported CSS properties for target email clients) and the AI Builder (natural language template scaffolding and styling).
Anthropic Commercial API Terms
All AI requests are routed directly to Anthropic's commercial Claude API. Under Anthropic's commercial agreements, no customer inputs (prompts, HTML, or CSS) or generated outputs are ever used to train Anthropic's AI or machine learning models. Your proprietary template markup and email designs remain exclusively yours.
Inputs sent to AI endpoints are processed in-flight. We do not maintain any secondary vector databases, fine-tuning corpora, or offline training datasets of user emails.
Data Lifecycle & Ephemeral Previews
Emailens is built around a principle of data minimization: we store only what is strictly necessary to provide you with preview results and account functionality.
- Unauthenticated Previews: Processed 100% in-memory in serverless edge functions. Raw HTML code is parsed against our CSS compatibility matrix, rendered, and discarded immediately after the HTTP response closes. No record is written to PostgreSQL.
- Authenticated Previews & Screenshots: When signed in, preview records and high-resolution screenshot renders (stored in Cloudflare R2) are retained to allow you to review historical checks. These assets are subject to a strict 30-day automatic deletion policy.
- Domain Health Checks: SPF, DKIM, and DMARC inspection records are automatically pruned after 90 days.
- Test Sends: Inbound test emails routed through our preview inbox are automatically purged from our database within 14 days.
Payment Isolation & PCI-DSS Compliance
Emailens uses Polar.sh as our Merchant of Record (MoR) for all paid subscriptions and transactions, backed by Stripe infrastructure.
Zero Financial Data Exposure · PCI-DSS Level 1 Isolation
Credit card numbers, bank account details, and billing credentials are typed directly into Polar's hosted PCI-DSS Level 1 certified checkout environment. Emailens servers, databases, and logs never see, transmit, or store payment card numbers or CVCs. Polar handles sales tax, EU VAT collection, and statutory invoice generation on our behalf.
Infrastructure & Encryption
Emailens is hosted on modern, resilient cloud infrastructure providers adhering to ISO 27001, SOC 2 Type II, and GDPR standards:
Data in Transit (Cloudflare)
Forced HTTPS with TLS 1.3 encryption across all web interfaces, REST APIs, and webhook endpoints. Strict HSTS headers prevent downgrade attacks.
Data at Rest (Supabase & R2)
Primary relational database (Supabase PostgreSQL) and media storage (Cloudflare R2) are encrypted at rest using industry-standard AES-256 encryption.
Hosting & Compute (Vercel)
Frontend applications and serverless compute run on Vercel's global edge network with automated DDoS mitigation, web application firewalls, and isolated runtime containers.
Authentication Security
Powered by Better Auth with cryptographically salted and hashed passwords (Argon2id / bcrypt), secure HTTP-only cookies, and OAuth 2.0 PKCE verification for Google and GitHub.
GDPR Compliance & Data Rights
We fully comply with the European Union General Data Protection Regulation (GDPR) and UK GDPR. We provide self-serve tools so you can exercise your privacy rights at any time:
- Right to Access & Portability: You can download a complete machine-readable
JSON export of your user profile, saved templates, test histories, and API key metadata at
any time via our self-serve endpoint at
/api/user/export. - Right to Erasure ("Right to be Forgotten"): You can permanently delete your account from your account settings. Deletion triggers an immediate cascading purge of all associated database records, active sessions, API keys, and Cloudflare R2 screenshots.
- Data Processing Addendum (DPA): If your organization requires a formal DPA incorporating Standard Contractual Clauses (SCCs) for enterprise compliance, we provide our standard template upon request. Email [email protected] .
Open Source Verification
Trust is earned through inspectability. The core rule engine behind Emailens, which evaluates CSS compatibility against 21 major desktop, mobile, and web email clients, is open source under the MIT license:
Anyone can inspect our parser logic, review our client compatibility datasets, or verify that our CSS parsing routines are deterministic and completely free of tracking code or covert analytics.
Vulnerability Disclosure & Bug Bounty
We take the security of our platform and users seriously. If you discover a security vulnerability in Emailens, please report it to us responsibly before any public disclosure:
Security Team Contact
[email protected]We commit to acknowledging your report within 48 business hours and will not pursue legal action against security researchers acting in good faith.
See also: Privacy Policy / Terms of Service / Cookie Policy