Privacy Policy
Last updated: August 9, 2026
Data We Collect
When you create an account, we store:
- Email address — for authentication (magic link login)
- IP address at registration — for anti-abuse (max 3 accounts per IP)
- API keys — stored as a SHA-256 hash only (we cannot read your keys), with their label and usage counters
- Credit balance and purchase history
Email Verification
API verification — addresses sent to /api/v1/verify are processed in real time and are not stored after the request completes. Each verification is fresh; no result is ever cached or reused for a later request.
Batch verification — a list pasted or uploaded in your account is held only for as long as the job needs it. A batch can take hours, so the addresses and their results are written to our database while it runs, and stay downloadable for 24 hours after the batch finishes. They are then permanently deleted — addresses, results and the uploaded file. Deletion is automatic and applies to the whole batch; there is nothing to request. Nothing is kept beyond that window, resold, or used to build a list.
Operational Metrics
To monitor service quality (latency, error rates, deliverability patterns per recipient domain), we retain aggregated technical logs for up to 90 days. These logs never contain submitted email addresses, only the recipient domain (e.g. gmail.com), the result code (deliverable / undeliverable / catch-all / unknown), the response time, and technical status codes. This data is used exclusively for internal monitoring and has no commercial purpose.
Cookies
We use a single httpOnly session cookie (mp_session) for authentication. No tracking cookies, no analytics, no third-party cookies.
Third-Party Services
- Stripe — payment processing. Stripe handles all card data. We never see or store your card number. See Stripe's privacy policy.
- Brevo — transactional emails (magic links, payment confirmations).
We do not use Google Analytics, advertising pixels, or any tracking service.
Data Retention
- Account data: kept as long as your account exists
- API verification data: not stored, processed in real time only
- Batch lists and results: deleted 24 hours after the batch finishes
- Operational metrics: aggregated technical logs (no email addresses), up to 90 days
- Server logs: standard web server logs, not shared or exploited
Your Rights (GDPR)
You have the right to access, rectify, or delete your personal data.
Rectification is self-service: Settings → Email address in your account. We send a confirmation link to the new address, and nothing changes until you open it. The previous address is notified once the change is done.
Deletion is self-service and immediate: Settings → Delete account in your account. It removes the account, its sessions, every API key, and every batch with its results. Remaining credits are lost and are not refundable.
Your invoices remain with Stripe: they are accounting records and the law requires them to be kept. The identity attached to them is anonymised at deletion, so they can no longer be linked back to you.
For anything else, contact us at contact@mailprobe.dev.
Data Controller
Iris Digital, SIREN 524 317 872, France