EmailFleet legal
Privacy Policy
Last updated August 27, 2026
EmailFleet is operated by Main Street AI Team ("we"). This policy describes what we collect, why, and what we do with it. The short version: we host your mailboxes, which means we necessarily store your mail; we treat that as the most sensitive thing we hold, and we do not sell or mine it.
Information We Collect
- Account information: name, email address, and a password hash for each user in a workspace.
- Mail data: messages sent and received through managed mailboxes, including headers, bodies, and attachments, synced from the mail server so the console can display and search them.
- Mailbox and infrastructure credentials: mailbox passwords, API tokens for connected services, and webhook secrets, all encrypted at rest with AES-256-GCM.
- Operational records: audit log entries (who did what, when), DNS and deliverability check results, and DMARC aggregate reports for your domains.
- Request-access submissions on the marketing site: the name, email, company, and fleet description you choose to send us.
How We Use It
To provide the service: displaying your unified inbox, sending mail you compose, monitoring deliverability, alerting on DNS drift, and keeping the audit trail your plan includes. We also use aggregate, non-content operational data (counts, error rates) to run and improve the platform. We do not use your mail content for advertising, do not train machine-learning models on it, and do not sell any of your data to anyone.
Who Can See Your Data
Workspaces are isolated: users see only their own workspace, and role permissions inside a workspace gate credential access. Our platform staff can access customer data only for support and abuse investigation, and credential reveals are recorded in the audit log.
Subprocessors
The service runs on Vercel (application hosting), Neon (database), MXroute (mail infrastructure), and Cloudflare (DNS). Each holds only what its role requires. Mail necessarily transits the mail infrastructure provider; that is what mail hosting is.
Retention and Deletion
Mail and mailbox data persist while the mailbox is active, within the history window of your plan. Retiring a mailbox follows the schedule you choose (forwarding window, then deletion). Trashed messages are removed after 30 days. A workspace owner can export the whole workspace and delete it from Settings; deletion removes every mailbox at the mail provider first, then erases the workspace, its domains, messages, keys, and audit trail from the live database and discards the encryption key for its secrets. Point-in-time history at the database provider ages out within its retention window (currently up to seven days). You can also request deletion of your account and data at hello@emailfleet.io.
Security
Credentials and secrets are encrypted at rest, transport is TLS everywhere, sessions use secure cookies, and sensitive actions are permission-gated and audited. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
Contact
Privacy questions and requests: hello@emailfleet.io. We answer these ourselves.
Questions about this document or your account: hello@emailfleet.io.