Privacy Policy

This policy explains what personal data Owlpost handles, why, and your choices. Owlpost is a Factory Zero venture ("we").

1. Two roles

2. Data we process for you (processor)

We use the following subprocessors: Amazon Web Services (SES for sending and receiving, S3 for briefly held inbound raw messages, EU West (Ireland) region) and Cloudflare (Workers, D1 and R2 for the API and stored messages). A data processing agreement is available on request at hello@owlpost.to.

What runs today and what is planned, from the Factory Zero registry:

Factory Zero ventures this site uses or will use: Cratefield (framework); SupportGenius (bug reports, planned); Keep Shipping (deploys, planned). The full list, with what is live and what is planned, is in the Factory Zero registry.

3. Data about our customers (controller)

4. Retention

5. Security

Data is encrypted in transit and at rest. API keys are stored hashed. Inbound mail is screened for spoofing, malware and prompt injection before agents see it. Access is limited to the people who run the service.

6. Your rights

You can ask to access, correct, export or erase your personal data, and object to processing. If you received mail sent through Owlpost, contact the sender first: they control that data. We'll help them, and you can also write to us. Email hello@owlpost.to.

7. Changes

We'll post updates here and notify account holders of material changes.

Owlpost · a Factory Zero venture