CarlyEmail docs

Privacy policy

What CarlyEmail collects, how it is used, and how long it is kept.

Last updated 31 July 2026. CarlyEmail is operated by SWH Labs LLC.

1. What we collect

Email content. Messages you send and receive — headers, subject, body and attachments. Handling mail is the service.

Account data. Owner email address, organization, pods, inboxes and plan.

Credentials. API keys as a hash only. One-time codes salted and hashed. OAuth subject identifiers where you connect an MCP client.

Delivery events. Sends, deliveries, bounces, complaints and suppression entries.

Operational logs. Request method, path, status, timing and request id. We do not log request or response bodies.

2. How we use it

To operate the service: deliver your mail, serve it back through the API, apply suppression, enforce plan limits, and provide support.

3. What we do not do

We do not sell your data, share it for advertising, or use the contents of your mail to train models. We do not read your mail except as required to act on it through the API, investigate abuse, or answer a support request you raise.

4. Retention

Data Kept
Messages, threads, attachments Until deleted or the account closes
Raw inbound MIME Until deleted or the account closes
Daily send counters 40 days
Failed-delivery queue 14 days
Operational logs 14 days
Suppression entries While the account is open
API key records Retained after revocation as an audit record

5. Sub-processors

Provider Purpose
Amazon Web Services Compute, storage, email sending and receiving
WorkOS Authentication for MCP clients
Stripe Payment processing

We use no analytics or advertising trackers on the API.

6. Security

The API is served over HTTPS only. API keys are stored as a hash and cannot be recovered. Access tokens are audience-bound. Inbound mail carries its SPF, DKIM and DMARC verdicts and failing mail is withheld from default listings. Keys can be scoped to a single inbox.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights

You can export or delete your data through the API at any time. For access, correction or deletion requests, contact us.

8. Changes

We will update the date above and notify the owner email of material changes.

9. Contact

support@calbotservice.com