Privacy Policy

Last updated: August 19, 2026

1. Information We Collect

We collect the following types of information when you use the Service:
  • Account information: email address, display name, and password hash.
  • API usage data: API keys (stored as hashes), email send logs (recipients, subjects, timestamps, delivery status).
  • Device and browser information: user agent strings and IP addresses for authentication and abuse prevention.

2. How We Use Information

We use collected information to:
  • Provide and maintain the Service
  • Authenticate users and manage API keys
  • Enforce rate limits and prevent abuse
  • Track email delivery status and maintain logs
  • Communicate with you about your account
  • Improve and optimize the Service

3. API Key Security

API keys are never stored in plaintext. We use one-way cryptographic hashes so that your raw key cannot be recovered from our database. Only the key prefix (first 8 characters) is stored alongside the hash for identification. You are responsible for storing your raw API key securely. We cannot recover a lost key.

4. Cookies

The Service uses essential session cookies to maintain your authentication state. These cookies are strictly necessary for the Service to function and are not used for tracking or advertising purposes. No third-party cookies are set.

5. Data Retention

Account data is retained for as long as your account is active. Email send logs are retained for up to 90 days. API key metadata is retained for the lifetime of the key. When you delete your account, we delete your personal data within 30 days, except where retention is required by law.

6. Third-Party Services

We use the following third-party services that process data on our behalf:
  • Resend: email delivery. Email content, recipient addresses, and sender information are transmitted to Resend for delivery.
  • MongoDB Atlas: database hosting. User accounts, API key metadata, email logs, and audit logs are stored on MongoDB Atlas infrastructure.
Both services operate under their own privacy policies and are used solely to provide the core functionality of the Service.

7. Data Security

We implement industry-standard security measures including encrypted transit (TLS), hashed API keys, session-based authentication, and audit logging. However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Your Rights

You have the right to:
  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your data in a portable format
  • Object to processing of your data
To exercise these rights, contact us at support@selfiam.site.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the Service after changes are posted constitutes acceptance of the revised policy.

10. Contact

For questions about this Privacy Policy, please contact us at support@selfiam.site.