Account data: your email address, authentication/session records, plan, billing status, and support correspondence. Submitted emails: the full content and headers of emails you send to your Presend address — which may include personal data of your own recipients if you send a real campaign copy. For paid real-client Preview, this also includes temporary copies in dedicated capture mailboxes and on hosted dedicated desktop or private physical-device runners. Service data: audit state, generic notification delivery status, security/abuse records, and bounded operational logs. Presend does not collect product-analytics events at launch; PostHog is disabled and no analytics key is loaded. Sentry is also disabled in current production; both production DSNs were removed. A future launch deployment may enable scrubbed error reporting only after its no-body/header/query/replay controls are verified.
Paid Preview delivers the exact submitted message to dedicated Gmail or IMAP capture accounts and opens it in the named Gmail, Apple Mail, or classic Outlook client on a hosted dedicated desktop or private physical phone operated for Presend. A real client may request external images, including tracking pixels. The remote image host may therefore receive identifiers already embedded in its URL together with a Presend capture IP address, client information, and time, and may record an open. Do not submit a production-recipient copy if you do not want that request to occur.
Primary email content and audit results are stored in the EU: database in Frankfurt (Supabase) and raw message and capture-artifact storage on Cloudflare R2 with EU jurisdiction. The web app runs on Vercel; the audit worker and capture controller run on Railway. During paid Preview, temporary mailbox and device copies are processed through the selected capture-mailbox and hosted-runner providers. Those temporary copies and provider operational records are not part of the Frankfurt storage claim. Paid Preview will not open until we have selected those providers, recorded their countries/regions, reviewed their retention and access controls, and updated this policy and the production sub-processor list with any applicable international-transfer safeguards.
Some current service providers may process limited data outside the EEA depending on the service and account region. Before paid beta, the production processor record must confirm each location and the applicable transfer basis, such as an adequacy decision or Standard Contractual Clauses, together with any required supplementary measures.
Current sub-processors are Cloudflare (email receipt, storage, and DNS), Supabase (database and authentication), Vercel (web hosting), Railway (audit worker), Anthropic (AI analysis under its API/business data terms), Stripe (payments), Resend (authentication and generic audit-ready email), and Intercom/Fin when the support widget is configured and you explicitly click Support; its script is not loaded passively on page view. PostHog is not active and is not a launch processor. Railway’s capture controller, Google Workspace, an isolated IMAP provider, Microsoft account/software services, and selected hosted dedicated/private-device execution providers will process paid Preview only after deployment/selection, contract/DPA and transfer review, and disclosure of their identity and processing region here. Google AI is planned work, not a current processor.
Performing our contract with you (running the audits, your account, billing); our legitimate interests (security, abuse prevention, service reliability, and support); your consent (optional communications and the opt-in, anonymized benchmark corpus); and legal obligations (accounting records).
Anonymous check emails and reports become eligible for automatic deletion after 7 days. Presend deletes raw object storage first and retains the relational row until every object deletion succeeds, so a temporary storage failure can be retried instead of being falsely reported as purged. Account content is kept while your account exists; an owner can delete a completed test version in the product, or request account deletion at support@presend.email. Capture Desk removes its transient hosted-runner source and uploaded frames after completion; the operator removes the exact mailbox item, exported screenshot, device Photos/Recently Deleted item, and transient workspace during closeout. R2 capture artifacts are deleted with the owning test. Owner deletion inventories the complete capture-request storage prefix, including abandoned uploads without an artifact row, before deleting relational state. Any selected provider’s cache, access-log, or remote-session recording window must be reviewed and disclosed before paid Preview opens. Account-deletion requests are completed within 30 days, and backups roll off on the provider’s documented schedule; billing records may be retained where law requires.
For an account-owned audit, Presend may send one generic completion email through Resend. It contains a private report link but not the submitted subject, score, findings, or email content. Anonymous audits are not emailed. We keep bounded delivery state and the provider message identifier so retries are idempotent; a notification failure does not change the audit result.
We never sell your data, never share submitted email content except with the processors needed to provide the service, never use your content to train Presend or Optiversion models, and never send email to your recipients. Processor terms for submitted content must prohibit use for training general models.
The inbound Email Worker accepts only Presend audit addresses. Unrelated and reply mail is rejected before its body is retained; the audit pipeline is not a support mailbox.
Under the GDPR you can request access, correction, deletion, restriction, or portability of your personal data; object to processing based on legitimate interests; withdraw consent where consent is the basis; and lodge a complaint with a supervisory authority (in Norway: Datatilsynet). Requests: support@presend.email.
We use strictly necessary cookies for login sessions. We do not use analytics or advertising cookies at launch. PostHog is disabled; if analytics is introduced later, we will update this policy and any consent controls before collection begins. Loading it would require both an explicit enable flag and a key; neither is active at launch.