Privacy Policy
This policy explains what personal data Owlpost handles, why, and your choices. Owlpost is a Factory Zero venture ("we").
1. Two roles
- Controller for our own customer data: account holders, billing contacts and website visitors.
- Processor for the mail you send and receive through Owlpost: recipients' addresses and message content. We process it only to deliver the service, on your instructions.
2. Data we process for you (processor)
- Outbound: recipient addresses, message content and delivery events (sent, delivered, bounced, complained, opened or clicked if you turn tracking on).
- Inbound: messages received by your agent inboxes, including attachments that pass our safety checks.
- Suppression list: addresses that hard-bounced, complained or unsubscribed, so we never mail them again for you. It can be kept as a one-way hash after erasure.
We use the following subprocessors: Amazon Web Services (SES for sending and receiving, S3 for briefly held inbound raw messages, EU West (Ireland) region) and Cloudflare (Workers, D1 and R2 for the API and stored messages). A data processing agreement is available on request at hello@owlpost.to.
What runs today and what is planned, from the Factory Zero registry:
- Amazon SES (inbound email). Receives inbound mail for agents.owlpost.to in production.
- Cloudflare (hosting). The site, Email Routing, and the API Worker with D1 and R2.
- Amazon SES (email) (planned, not in use yet). Outbound sending through SES, once AWS lifts the sandbox on the account.
- Polar (payments) (planned, not in use yet). Paid plans and usage through Polar as Merchant of Record. Nothing is on sale yet.
Factory Zero ventures this site uses or will use: Cratefield (framework); SupportGenius (bug reports, planned); Keep Shipping (deploys, planned). The full list, with what is live and what is planned, is in the Factory Zero registry.
3. Data about our customers (controller)
- Account: name, email, organisation and verified domains.
- Billing: handled by our payment provider. We don't store card numbers.
- Usage and logs: API requests and delivery metrics, used to run, secure and bill the service. Logs never contain message bodies or secrets.
- Website: no third-party analytics or advertising trackers.
4. Retention
- Raw inbound messages in S3: deleted after processing, and at the latest after 7 days.
- Stored messages and events: kept for your plan's retention period, then deleted.
- Account data: kept while your account is open and deleted after closure, except where the law requires us to keep records (for example invoices).
5. Security
Data is encrypted in transit and at rest. API keys are stored hashed. Inbound mail is screened for spoofing, malware and prompt injection before agents see it. Access is limited to the people who run the service.
6. Your rights
You can ask to access, correct, export or erase your personal data, and object to processing. If you received mail sent through Owlpost, contact the sender first: they control that data. We'll help them, and you can also write to us. Email hello@owlpost.to.
7. Changes
We'll post updates here and notify account holders of material changes.