Privacy Policy
Last updated: July 31, 2026
1. Introduction and scope
This Privacy Policy explains how CatchTheMail ("we", "us", or "the Service") collects, uses, shares, and protects your information. It applies to everyone who visits our website, creates an account, or forwards emails to a private CatchTheMail address, whether you forward each message yourself or through a forwarding rule you have set up in your own mailbox. By using the Service, you agree to the practices described in this policy. If you do not agree with it, please do not use the Service.
We have deliberately written this policy in plain language. Your emails are among the most personal data you have, and we believe you should be able to understand exactly what we store, why we store it, and who else is involved, without needing a legal background. If anything remains unclear after reading it, you can always write to us at hello@catchthemail.com and we will explain it directly.
Before the details, our commitments at a glance:
- We never sell your personal data and never share it for advertising purposes.
- Your emails are never used to train AI models, neither by us nor by the AI provider we work with.
- We never connect to your mailbox. We hold no passwords, tokens, or permissions that would make that possible; we only ever receive the emails you choose to send us.
- You can delete your account and every stored email yourself, at any time, without asking us for approval.
The rest of this policy explains in detail how we live up to these commitments.
2. Information we collect
We collect only the information we need to operate the Service. It falls into four categories:
- Account information. When you sign up, we collect your first name, last name, email address, phone number, and a password. The password is stored only in hashed form; we never see or store your plaintext password, and we could not read it even if we wanted to. If you sign in with Google instead, we receive your name and email address from Google and no password is created with us at all.
- Forwarded email content. When an email reaches your private CatchTheMail address, we store its sender, subject, and body so that our AI can analyze it and the results can appear in your dashboard and in the summary email we send you. Exceptionally long messages may be shortened before they are passed to AI analysis. We only ever receive emails that you explicitly forward or that your own forwarding rule sends to us. We never connect to or read your mailbox, and we hold no credentials or permissions that would make that possible.
- Usage data. We keep basic records of how the Service is used, such as how many emails you analyze each month. We use these records to enforce plan quotas fairly and to understand, in aggregate, how the product is performing. We also store your current subscription status as reported by our payment provider.
- Cookies and browser storage. We use strictly necessary cookies to keep you signed in, and one small preference cookie that remembers your language choice (English or Turkish). If you tick "Remember me" on the login page, your email address is saved in your own browser's storage, on your device, not on our servers. We do not use advertising cookies, cross-site tracking, or analytics trackers that follow you around the web.
Just as important is what we do not collect. We never receive or store your card details (payments are handled entirely by our payment provider), we never hold your mailbox password or any permission to access your inbox, and we do not collect your browsing history.
3. How we use your information
Every piece of information we collect serves a specific purpose. We use your information to:
- Provide the core service: analyzing the emails you forward and returning prioritized results, summaries, and suggested replies to your inbox and dashboard;
- Create and manage your account, authenticate you securely, and keep your session protected;
- Track plan usage against your monthly quota and process subscription payments through our payment provider;
- Send you essential service communications, such as analysis results, quota notices, and account or billing messages. These are operational emails, not marketing;
- Maintain the security of the Service, detect abuse, and protect our users and infrastructure;
- Improve the product based on aggregate, non-identifying usage patterns.
To state it once more, clearly: your emails are never used to train AI models, we never sell your personal data, and we never share it for advertising purposes. Your data is used to serve you, not to monetize you.
4. Legal bases for processing
Where data protection law requires a legal basis for processing, we rely on the following:
- Performance of a contract. Analyzing the emails you forward, maintaining your account, delivering results, and processing your subscription are all necessary to provide the Service you signed up for. Without this processing, the Service simply could not function.
- Legitimate interests. We process limited data to keep the Service secure, prevent abuse, and understand aggregate usage. Whenever we rely on this basis, we balance our interest against your rights and reasonable expectations, and we choose the least intrusive approach available.
- Legal obligations. Some records, such as billing and tax information, must be kept for as long as tax and accounting law requires.
- Consent. Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before it.
5. How we share your information: our data processors
We do not have advertising partners, data brokers, or "selected third parties". We share data only with the infrastructure providers required to run the Service, only to the extent necessary, and each of them is bound by contractual commitments to process your data solely on our behalf. Here is the complete list, together with what each provider receives and why:
- Anthropic (AI analysis). When an email is analyzed, its sender, subject, and body are sent to Anthropic's API to generate the priority assessment, summary, and suggested reply. Anthropic processes this content as a service provider and, under the commercial terms we use, does not use it to train AI models. Anthropic does not receive your account details, your identity as a CatchTheMail customer, or any payment information.
- Postmark (email delivery). Postmark receives the emails sent to your private forwarding address on our behalf and delivers our result and account emails back to you. As our email delivery provider it necessarily handles email content in transit. It does not receive your password or any payment information.
- Lemon Squeezy (payments). Lemon Squeezy acts as our merchant of record and runs the entire checkout. It collects your billing name, email address, country, and payment details directly on its own systems. What we receive back is limited to your subscription status and a customer reference; your card details never reach our servers, and we could not see them if we tried.
- Supabase (database and authentication). Supabase hosts our database and manages account authentication. It stores your account record, your analyzed emails, and your usage counters. Passwords are stored hashed, and database access rules are configured so that each account can only ever read its own rows.
- Google (optional sign-in). Only if you choose "Sign in with Google", Google shares your name and email address with us so we can create your account. We receive nothing else from your Google account, and signing in with Google grants us no access whatsoever to your Gmail mailbox.
- Vercel (hosting). Our website and application run on Vercel's infrastructure. Vercel processes the network requests needed to serve you the site, including standard technical logs (such as IP address and request metadata) that are required to operate and secure the Service.
This list is exhaustive: there is no one else. If we ever add or replace a provider, we will update this policy accordingly. We may also disclose information if required by law, regulation, or a valid legal process, and only to the extent legally required. None of the providers above is permitted to use your data for its own purposes.
6. International data transfers
The providers listed above may store and process data on servers located outside your own country, including in the United States and the European Union. This is a practical reality of using world-class infrastructure, and we treat it with care: wherever your data travels, it remains protected by this policy and by the contractual safeguards we have in place with each provider. We deliberately choose established providers with published security and privacy commitments, precisely so that the level of protection your data receives does not depend on where a particular server happens to stand. If applicable law requires additional safeguards for a transfer, we rely on the mechanisms our providers offer for that purpose, such as standard contractual clauses.
7. Data retention
We retain your account information and analyzed emails for as long as your account is active, so that you can revisit past analyses in your dashboard whenever you need them. We do not keep data "just in case", and we do not repurpose stored emails for anything other than showing them to you.
Deleting your account is a single action available in your settings: it removes your account and every stored email together, including system entries and messages that were filtered without analysis. After deletion, your personal data and stored emails are permanently removed from our systems within 30 days. The only exception is data we are legally required to keep for longer, such as billing records retained under tax and accounting law; those are kept only for the legally required period and for no other purpose.
8. Your rights
Depending on where you live, data protection law may grant you some or all of the following rights regarding your personal data:
- The right to access a copy of the personal data we hold about you;
- The right to correct inaccurate or incomplete data;
- The right to request deletion of your data (the "right to be forgotten");
- The right to object to or restrict certain processing;
- The right to data portability, that is, to receive your data in a usable format;
- The right to lodge a complaint with your local data protection authority.
We want exercising these rights to be genuinely easy, so here is how it works in practice. For deletion, you do not need to contact us at all: you can delete your account and all stored data yourself, at any time, from the settings page. If you have an active paid subscription, deleting your account also cancels it automatically. In the rare case that our payment provider cannot be reached, we do not delete the account; instead we show you exactly how to cancel the subscription yourself from the billing page first, so you are never left paying for an account you can no longer reach, and you still never need to write to us to complete the deletion. For access, correction, portability, or any other request, write to us at hello@catchthemail.com, preferably from the email address registered to your account so that we can verify the request belongs to you. If we cannot verify it that way, we may ask you to confirm the request from that address; this protects your data from being handed to someone else. We respond to every request, free of charge, within 30 days at the latest, and sooner whenever we can. Exercising your rights never affects the quality of service you receive from us.
9. Data security
We take the security of your data seriously, and we treat it as an ongoing discipline rather than a checkbox. The measures we apply include:
- Encryption in transit. All traffic between your browser and the Service is encrypted with TLS (HTTPS), without exception.
- Encryption at rest. Stored data is encrypted at rest by our infrastructure providers.
- Hashed passwords. Passwords are stored only in hashed form and are never recoverable as plaintext.
- Strict access isolation. Database access rules are configured so that each account can only read its own data; this isolation is enforced at the database level, not merely in application code.
- Operator access, and the record we keep of it. A very small number of operators, at present the founder alone, can reach account records and analysed email content through an internal administration tool. That tool exists so that we can answer a support request you have made, investigate abuse of the Service, or meet a legal obligation. It is used for nothing else. Every action taken through it, including simply opening an account, is written to a permanent audit record.
- Authenticated integrations. Every automated channel into the Service, such as the endpoints that receive forwarded emails and payment notifications, requires authentication and cryptographic signature verification before anything is processed.
- Hardened application. The Service enforces modern browser security headers, including a content security policy, and access to production systems is limited to what is strictly necessary to operate the Service.
- Regular review. We regularly review our code and infrastructure for security issues and fix findings promptly.
No method of transmission or storage is 100% secure, and we will not pretend otherwise. What we promise is that we apply industry-standard practices, keep improving them, and act quickly if an issue is found. If you believe you have discovered a security vulnerability in the Service, please report it to hello@catchthemail.com; we investigate every report.
10. Children's privacy
The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe a child has provided us with personal information, please contact us at hello@catchthemail.com. We will verify the situation and delete the information promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time, for example when we add a feature, change a provider, or when the law changes. If we make material changes, we will notify you by email or through a clear notice in the Service before the changes take effect, so that you are never surprised by a policy you did not have a chance to read. The "Last updated" date at the top of this page shows when the policy was most recently revised, and we encourage you to review it occasionally.
12. Contact
CatchTheMail is the controller responsible for the personal data described in this policy. For any privacy-related question, concern, or request, reach us at hello@catchthemail.com. Privacy messages are read by a person, not routed into a ticket void; we read every message and aim to reply promptly.