Privacy policy
What CarlyEmail collects, how it is used, and how long it is kept.
Last updated 31 July 2026. CarlyEmail is operated by SWH Labs LLC.
1. What we collect
Email content. Messages you send and receive — headers, subject, body and attachments. Handling mail is the service.
Account data. Owner email address, organization, pods, inboxes and plan.
Credentials. API keys as a hash only. One-time codes salted and hashed. OAuth subject identifiers where you connect an MCP client.
Delivery events. Sends, deliveries, bounces, complaints and suppression entries.
Operational logs. Request method, path, status, timing and request id. We do not log request or response bodies.
2. How we use it
To operate the service: deliver your mail, serve it back through the API, apply suppression, enforce plan limits, and provide support.
3. What we do not do
We do not sell your data, share it for advertising, or use the contents of your mail to train models. We do not read your mail except as required to act on it through the API, investigate abuse, or answer a support request you raise.
4. Retention
| Data | Kept |
|---|---|
| Messages, threads, attachments | Until deleted or the account closes |
| Raw inbound MIME | Until deleted or the account closes |
| Daily send counters | 40 days |
| Failed-delivery queue | 14 days |
| Operational logs | 14 days |
| Suppression entries | While the account is open |
| API key records | Retained after revocation as an audit record |
5. Sub-processors
| Provider | Purpose |
|---|---|
| Amazon Web Services | Compute, storage, email sending and receiving |
| WorkOS | Authentication for MCP clients |
| Stripe | Payment processing |
We use no analytics or advertising trackers on the API.
6. Security
The API is served over HTTPS only. API keys are stored as a hash and cannot be recovered. Access tokens are audience-bound. Inbound mail carries its SPF, DKIM and DMARC verdicts and failing mail is withheld from default listings. Keys can be scoped to a single inbox.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights
You can export or delete your data through the API at any time. For access, correction or deletion requests, contact us.
8. Changes
We will update the date above and notify the owner email of material changes.
9. Contact
support@calbotservice.com