Privacy Policy

Last updated July 19, 2026

This policy explains what Perenmail collects, why, and who else is involved in running the Service. We have written it to match how the app actually works, not to a generic template.

What we collect

  • Account information — your name and email address, and the credentials used to sign in.
  • Email messages — the inbound email delivered to the inboxes you create, including headers, message bodies, and attachments. This is the core of the Service: you create private addresses so you can receive and inspect this mail.
  • Billing data — if you subscribe to Personal+, Paddle acts as our merchant of record: it sells and invoices the subscription, handles the payment, and stores your card data. We only receive a customer/subscription reference and status — never your full card number.
  • Minimal usage data — basic operational logs needed to run the Service securely (such as request and delivery metadata). We do not build advertising profiles.

How we use it

We use this data to authenticate you, deliver and display the mail sent to your inboxes, operate and secure the Service, process your subscription, and respond to support requests. We do not sell your data, and we do not use the contents of your inboxes for advertising.

Third parties and subprocessors

We keep our third-party footprint small. The providers that process data on our behalf are:

  • Cloudflare — hosting (Workers), the D1 database where your account and messages are stored, and Email Routing, which receives inbound mail and forwards it to the Service.
  • Paddle — merchant of record for Personal+ subscriptions; handles checkout, billing, card data, and tax.

Data retention

Perenmail is built on persistence by default: your inboxes and the messages in them stay until you archive or delete them. You are in control of that lifecycle. When you delete a message, inbox, or your account, we remove the associated data from the active Service; residual copies in backups or logs are purged on their normal rotation, within 30 days.

Security

Addresses on Perenmail are private and registered-only — there is no public inbox browsing, so mail is not guessable or exposed to anonymous visitors. HTML email is rendered inside a locked, sandboxed iframe with scripts disabled, which neutralizes stored cross-site-scripting from hostile inbound mail. We take reasonable technical measures to protect your data, but no online service can be guaranteed perfectly secure.

Cookies and sessions

We use a session cookie to keep you signed in. This is strictly-necessary functionality — we do not use third-party advertising or cross-site tracking cookies.

Your rights

You can access and update your account information, delete individual messages and inboxes, and delete your account entirely from within the app. Depending on where you live, you may have additional rights to access, correct, export, or erase your personal data — contact us and we will help. If you are in the EEA or UK, you may also lodge a complaint with your local data-protection authority.

Children

Perenmail is a developer tool and is not directed to children. It is not intended for anyone under 16 (or under 13 where a lower age applies), and we do not knowingly collect data from them.

International transfers

Our providers operate globally, so your data may be processed in countries other than your own. Where required, we rely on our providers’ safeguards for such transfers.

Changes to this policy

We may update this policy as the Service changes. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you.

Contact

Questions about your privacy? Reach us at support@perenmail.com.