Privacy Policy
Last updated September 21, 2026
1. Who we are
Inceptmail ("Inceptmail", "we", "us") provides private, persistent test inboxes for developers and QA teams through inceptmail.com and the inbox domain inceptmail.dev (the "Service"). This policy explains what information we collect, how we use it, and the choices you have. Questions can be sent to support@inceptmail.com.
2. Information we collect
- Account information. Your email address, name, profile image, and sign-in method (email and password, or a social sign-in provider such as Google, GitHub, or Apple). Authentication is handled by our provider Clerk.
- Workspace data. The projects, inboxes, and members you create, including project titles, slugs, inbox names, prefixes, and the invitations you send to teammates.
- Email delivered to your inboxes. When a message is sent to one of your inbox addresses, we receive and store its sender and recipient addresses, subject, body (text and HTML), headers, and attachments, so you can read it.
- Billing information. Payments are processed by Paddle. We receive your plan, subscription status, and Paddle customer and subscription identifiers. We do not receive or store your full payment card number.
- Technical information. IP address, browser and device details, and server logs, used to keep the Service secure, prevent abuse, and diagnose problems.
3. How we use information
- To provide the Service: receive, store, and display email sent to your inboxes.
- To authenticate you, enforce plan limits, and process subscriptions.
- To send you service emails such as team invitations, account and billing notices, and support replies.
- To secure the Service, investigate abuse, and comply with legal obligations.
- To improve reliability and fix bugs.
We do not sell your personal information and we do not use it for advertising.
4. Test email content
The Service exists to receive test email. The content of messages delivered to your inboxes is sent by you, your applications, or third parties, and you decide what goes into it. We process that content only to provide the Service to you. Please do not route real customer data, payment card data, health information, or other sensitive personal data of other people into test inboxes.
5. Security
The subject, body, sender and recipient details, and headers of received messages are encrypted at rest using AES-256. Attachments are stored in private object storage and are only served to you through short-lived signed links. Data is transmitted over encrypted connections, and every request is scoped so that an account can only access its own projects, inboxes, and messages. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and will notify you of a breach where required by law.
6. Who we share information with
We share information only with service providers that help us run the Service, under agreements that limit their use of it:
- Clerk, for authentication and account management.
- Paddle, our merchant of record, for payments, taxes, and invoicing.
- Cloudflare, for email routing, application hosting, and attachment storage (R2).
- Upstash, for caching and background job processing.
- Google, for website analytics on this marketing site (Google Analytics).
- Our database and infrastructure hosting providers.
We may also disclose information if required by law or to protect the rights, safety, and security of Inceptmail, our users, or others. Inbox members you invite can see the inboxes you grant them access to.
7. Retention and deletion
- Messages and attachments are kept for 7 days on the Free plan and 90 days on the Pro plan, then deleted automatically, or sooner if you delete them or the inbox or project that contains them.
- When you delete a project or inbox, it is scheduled for permanent deletion and can be restored for 24 hours. After that it is permanently deleted, together with its messages and attachments.
- When your account is deleted, your projects, inboxes, messages, and attachments are permanently deleted. To delete your account, email us at support@inceptmail.com.
- Billing records may be retained by us and Paddle for as long as tax and accounting law requires. Copies may remain in backups and logs for a limited period before they are overwritten.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact support@inceptmail.com. We may need to verify your identity first. You also have the right to complain to your local data protection authority.
10. International transfers
Our providers may process information in countries other than your own. Where required, we rely on appropriate safeguards for those transfers.
11. Children
The Service is intended for developers and is not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify you by email or within the Service before they take effect. The date at the top shows when it was last updated.
13. Contact
Inceptmail, support@inceptmail.com.