What we collect, and where it lives
Written to be read rather than to be survived. If something here is vague, that is a fault worth reporting, not a legal technique.
Last updated: 5 September 2026
The short version
Mailgi gives AI agents real email addresses. Running that means holding two quite different kinds of data: the account details of the people who sign up, and the mail their agents send and receive. This page separates them, because the answers are different.
Three things worth knowing up front, all of which are true today rather than aspirational:
- Your mail stays in the EU. Mailbox content is stored on a server in Germany, and mail arriving for your agents lands there directly. Outbound mail is relayed through AWS in Ireland. Nothing that holds your mail sits outside the EU.
- Google is the only thing here that sets a cookie, only for advertising measurement, and only if you accept it. Everything else we use is either cookieless or strictly functional.
- Our product analytics sets no cookies at all and is hosted in the EU.
Who we are
This service is operated as Mailgi. For anything in this policy, including full entity and registration details, write to hello@mailgi.xyz — a real inbox, run on Mailgi itself, read by a person.
For the data described below we act as the controller for account data — your user record, your organisation, billing, product analytics and how you found us. For mailbox content, the mail your agents send and receive, we act as a processor on your instructions: it is your data, and we hold it to run the service you asked for.
What we collect
If you create an account
Your email address, your name and avatar URL if your sign-in provider supplies them, which provider you used and its identifier for you, when you signed up, and when you last signed in.
We also store how you arrived: the advertising click identifier if you came from an ad, the campaign parameters on that link, the page you landed on, and the hostname that referred you. This is kept as first-touch only and is not updated if you later click a different ad. It exists so we can tell which advertising works, and it is the reason we can measure a signup without depending on third-party cookies.
Login codes sent by email expire after ten minutes. Session tokens and API keys are stored only as one-way hashes — we cannot recover the originals, which also means we cannot email you a key you have lost.
Mail your agents send and receive
Complete message content: headers, subjects, bodies, and the addresses of everyone in the conversation. This is what a mailbox is. It is stored on the mail server in Germany, separately from the account database.
Mail that arrives for your agent necessarily contains information about the person who sent it, and they did not sign up with us. We treat that content as yours to control, not ours to use: we do not read it, mine it, or train anything on it.
Yours to control means exactly that. If your organisation owns the domain, your organisation can read and manage all mail sent to your agents. That is the same as any company address — writing to support@ at a company has always meant the company can read it. An agent's mailbox is no different, and we would rather say so than let the word "agent" suggest otherwise.
Usage and billing
Daily per-agent counters of messages sent and mailbox size, used to enforce the published rate limits and to spot abuse. For accounts using crypto billing, we store deposit addresses and the on-chain transactions against them.
Analytics
Which pages are viewed, and three deliberate signals: opening the dashboard
link, opening SKILL.md, and opening a question in an FAQ. We do not
record sessions, do not capture every click, and do not record anything you type.
Cookies
These are the cookies this site and the dashboard set. Only the Google ones require your consent, and none of them is set until you give it.
| Cookie | Set by | Purpose | Lifetime |
|---|---|---|---|
| mailgi_consent | Mailgi | Remembers your answer to the cookie banner, so you are not asked again | 12 months |
| session | Mailgi | Keeps you signed in to the dashboard | Session |
| _ga | Analytics — tells Google Analytics one visitor from another | Only after you accept | |
| _ga_5NN3R02PEZ | Analytics — the same, for this specific site | Only after you accept | |
| _gcl_au | Linking ad clicks to signups | Only after you accept |
Our product analytics sets no cookies — it keeps an identifier in your browser tab that is discarded when you close it.
Changing your mind
Declining costs you nothing: the site and the product work identically either way. You can change your answer at any time, here:
That clears the record of your choice and asks again on your next page view. Clearing cookies in your browser has the same effect.
Who else processes it
We use other companies to run this. Each one only receives what it needs for the job named here.
| Processor | What for | Where |
|---|---|---|
| Hetzner | The mail server — all mailbox content | Germany |
| Supabase | Main database — accounts, orgs, usage | EU (Frankfurt) |
| AWS SES | Relaying outbound mail | EU (Ireland) |
| PostHog | Product analytics, cookieless; session replay on this website only (not the dashboard) | EU |
| AWS CloudWatch | Application logs | EU |
| Sentry | Error tracking | EU (Germany) |
| Railway | Hosting the API, dashboard and this site, and the Redis holding rate-limit and usage counters | EU West |
| Advertising measurement — consent only | US | |
| Resend | Sending login-code emails | US |
| AWS S3 | Nightly encrypted off-site backups, including mailbox content | US (us-east-1) |
The table above is the list we maintain, and it is what to rely on — a prose summary of it goes out of date, and this one has, three times. Rather than restate it, here are the two things worth pulling out of it explicitly, because you should not have to infer them.
Day to day, your mail stays in the EU. It is stored in Germany, arrives there directly, and is relayed out through Ireland. The processors that sit outside the EU — advertising measurement, and one login-code service being retired — never hold mail content.
The nightly backup is the exception, and it is in the US. Every night a complete encrypted copy of the mail server, mailbox content included, is written to Amazon S3 in us-east-1. It is encrypted on our own server before it leaves, with a key that is never sent to Amazon, so what Amazon stores is ciphertext it cannot read. That is a real protection and not the same as the data never going there: it is stored in the United States, and we would rather say so than let the summary above imply otherwise. We intend to move this repository to an EU region.
The table above is our sub-processor list. If you need a data processing agreement, ask at hello@mailgi.xyz and we will provide one.
How long we keep it
| Data | How long |
|---|---|
| Mailbox content | While the agent exists. Removed within 30 days of a deletion request. |
| Account records | While the account exists. Removed within 30 days of a deletion request. |
| Email login codes | 10 minutes |
| Sessions | Until you sign out, or the session expires |
| How you found us | Life of the account — recorded once, never updated |
| Product analytics | Up to 12 months |
| Logs and error reports | Short-term, for running and debugging the service |
What "delete" does today, precisely
Deleting an agent, a user or an organisation inside the product marks the record deleted and hides it. It does not erase it. We are saying so rather than letting you assume otherwise: if you want data actually removed, email us and we will do it within 30 days. Making in-product deletion erase properly is work we have scheduled, not work we have done.
Deletion from our live systems does not reach into last night's backup. Those snapshots are kept on a rolling schedule — seven daily and four weekly — so a deleted mailbox ages out of the encrypted backups within about five weeks rather than disappearing the moment it is removed from the running server. We are not going to pretend otherwise; a backup you can selectively edit is not much of a backup.
Two related things worth knowing. Deleting an agent permanently retires its address — that mailbox name can never be registered again, by you or anyone. And if you arrived from an advertisement and we have already reported that click to Google as a conversion, that report has left our systems and we cannot recall it; we can delete our own copy, which we will.
Your rights
Depending on where you live you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to receive a copy, and to object to how it is used. We will not charge you for asking and will not treat you differently for having asked.
To exercise any of them, email hello@mailgi.xyz. We will confirm receipt and complete deletion requests within 30 days. You do not need an account to ask. If you have only ever written to one of these agents, you have the least obvious route in and the same rights as anyone else — ask, and we will answer. Where the mail belongs to a customer's organisation we will tell you who to ask as well.
Changes
When this changes we will update the date at the top. If a change materially affects what we do with your data, we will say so directly rather than relying on you to re-read the page.