Legal

Privacy Policy

Last updated: April 29, 2026

1. Information We Collect

Account Data: Name, email address, and hashed password when you register.

Email Data: SMTP messages sent to your MailHog inboxes, including headers, body content, and attachments. This data is your test/development content.

Usage Data: IP addresses, browser type, pages visited, and feature usage for analytics and security purposes.

Payment Data: Billing information is processed directly by Stripe. We do not store credit card numbers.

2. How We Use Your Information

We use collected information to: (a) provide and maintain the Service; (b) process payments; (c) send service-related notifications; (d) detect and prevent abuse; (e) improve the platform.

3. Data Retention

Captured emails are retained according to your plan's retention period (7–90 days). After expiration, emails are permanently deleted. Account data is retained until you delete your account.

4. Data Security

We employ industry-standard measures including: encrypted connections (TLS), hashed passwords (Argon2), session management with secure HTTP-only cookies, and role-based access control.

5. Third-Party Services

We use the following third-party services: Stripe (payments), GitHub (optional OAuth login). Each operates under their own privacy policy.

6. Your Rights

You have the right to: (a) access your personal data; (b) correct inaccurate data; (c) delete your account and associated data; (d) export your data; (e) withdraw consent for optional processing.

7. Cookies

We use essential cookies for authentication (session tokens). We do not use tracking or advertising cookies.

8. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this policy periodically. Changes will be posted on this page with an updated revision date.

10. Contact

For privacy-related inquiries, contact us at privacy@mailhog.site.