Privacy Policy
Last updated: September 24, 2026
Mailsnail prints and mails physical letters and postcards on behalf of users and AI agents acting under their accounts. To do that we have to handle a small set of personal data. This policy is written to be short and unambiguous.
What we collect
- Account data: sign-in identifiers, display name, email address when available, API-key hashes, account membership, and billing references. Card details are collected by Stripe; we store payment references and limited details such as card brand and last four digits.
- Mail content: the text or imagery your agent sends, plus the recipient address you supply.
- Operational logs: request metadata (timestamps, IPs, error codes) for security and debugging.
What we do with it
- Print, fold, and post your mail via USPS.
- Operate and secure the service, investigate abuse, and help resolve problems with mail or payments.
- Show your account history (mail you have sent and its delivery status).
- Bill you for production mail.
- Comply with legal obligations.
What we don't do
- We don't sell your data.
- We don't use mail content to train AI models.
- We share data with service providers as needed to host and operate MailSnail, process payments, and print and deliver your mail.
Retention
We retain information needed to fulfill mail, operate your account, provide support, reconcile payments, prevent duplicate sends and investigate abuse. We do not currently operate an automatic 90-day purge of all mail-related records. Deletion requests are reviewed individually; financial, transaction, security and delivery records may need to be retained. We explain any retained categories when handling your request. Our print and delivery providers may also retain records under their own applicable policies.
Sign-in and connected assistants
WorkOS handles existing and company sign-in. Where Facebook sign-in is offered, Meta supplies an app-specific identifier and public profile name. MailSnail does not require your Facebook email address and does not request access to friends or posts. We store the identity mapping, sessions, connected-app permissions and protected credentials needed to maintain your approved connection. We do not combine Facebook and company accounts by matching email addresses.
Signing out of a browser does not necessarily disconnect an assistant. Where available, use Disconnect all assistants in your MailSnail account, or remove MailSnail from Facebook's connected apps. Disconnecting removes that connection's authority; it does not delete your account, change separate API-key or WorkOS access, change automatic billing settings, or cancel mail already accepted for sending.
Request access, correction or deletion
Email hello@mailsnail.dev with the subject "MailSnail data request". Tell us whether you want access, a correction, deletion, or account closure. Include an account identifier or an order reference if you have one. If you signed in with Facebook and do not know an account email, say so. Never email a password, full API key, access token or card number.
We verify control of the affected account before acting. An email address alone does not prove ownership of a Facebook identity or authority over a company account. We review outstanding mail, payments and any records that need to be retained, and explain the outcome. Removing the Facebook connection alone is not a request to delete all MailSnail data. You can use the same contact address for privacy questions and requests under applicable privacy laws.
Sub-processors
We rely on a small number of vendors to operate the service: Railway for the API and database, Vercel for the website and web analytics, Stripe for payments, WorkOS for existing/company sign-in, and Click2Mail and USPS for hosted mail fulfillment. Meta is involved when you choose Facebook sign-in. Your AI assistant and any self-hosted mail provider also process data you give them under their own policies.
Changes
We'll update this page when the policy changes and post the new effective date above.