1. Introduction
Welcome to MailViewr ("we", "our", or "us"). We operate the website mailviewr.com(the "Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.
2. Information We Collect
We collect the following types of information:
- Account information: When you register, we collect your name, email address, and a hashed password. If you sign in via Google or GitHub OAuth, we receive your name and email address from those providers.
- Usage data: We may collect anonymised usage data such as pages visited, features used, and browser/device type to improve the Service.
- Email HTML content: HTML you submit through the anonymous preview tool (without signing in) is processed server-side to apply compatibility transformations and render your preview. This content is not stored.
- Saved projects and templates: When you build or edit an email in the Email Builder while signed in, we store your design — including its structured layout data, rendered HTML, and version snapshots — associated with your account's workspace, so you can return to and continue your work. If you save a design as a template, the template is stored the same way. Stored content is not shared with third parties.
- Uploaded images and assets: Images and other media you upload to your asset library are stored, associated with your account's workspace, using Cloudflare R2 object storage (see Section 4). If you use the background-removal tool, the image you submit is sent to our image-processing service to generate the edited result and is not retained beyond producing that result.
- Shared preview links: If you generate a shareable preview link for a project, the associated design snapshot becomes viewable by anyone with the link — without signing in — until the link expires (48 hours after creation) or you disable it. We log the number of views and the requesting IP address for each link access, to prevent abuse.
- Anonymous identifier: To recognise returning visitors and understand how frequently the tool is used without requiring an account, we set a randomly generated identifier in a first-party, HttpOnly cookie when you interact with certain features. This identifier is not linked to your name or email and cannot itself be used to identify you as an individual. It expires after 365 days, or sooner if you clear cookies in your browser settings.
- Canva design data: If you connect your Canva account, we temporarily access your Canva design metadata (design names, thumbnails) and export the HTML content of designs you explicitly select. We do not permanently store your Canva design content beyond what you choose to save as a template.
You are responsible for the HTML, images, and other content you upload or submit. We may remove content that creates security, legal, or abuse risks.
3. How We Use Your Information
- To create and manage your account.
- To provide the Email Builder, including saving, rendering, and letting you return to your projects, templates, and uploaded assets.
- To send transactional emails (email verification, password reset).
- To improve and maintain the Service.
- To respond to support requests.
- To comply with legal obligations.
- To send you product updates, new feature announcements, and critical service notifications. You may opt out of non-critical communications at any time by clicking the unsubscribe link in any such email.
We do not sell or rent your personal data. We share it only with the service providers listed in Section 4, to the extent needed to operate, secure, and improve the Service — never for third-party advertising or marketing.
4. Third-Party Services
We use the following third-party services that may process your data:
- Google OAuth / GitHub OAuth: Used for social login. Their privacy policies apply when you choose to sign in via these providers.
- Vercel:Our frontend hosting provider. Your requests to the Service pass through Vercel's infrastructure. We also use Vercel Analytics to collect anonymised usage data (pages visited, browser/device type). No personally identifiable information is shared with Vercel Analytics.
- Railway: Our backend hosting and database infrastructure provider. Account data is stored on their servers.
- Cloudflare R2:Object storage for images and other media you upload to your asset library. Uploaded files are stored on Cloudflare's infrastructure.
- Image-processing service: Background-removal and other automated image edits are performed by an in-house service we operate ourselves. Images you submit for editing stay within our own infrastructure, are used only to produce the result you save, and are not sent to any external party.
- Google Analytics (GA4) and Microsoft Clarity: These are optional analytics services we may use to understand how visitors use the Service — pages visited, feature usage, and session behaviour such as clicks and scrolling — so we can improve it. Where consent is required (such as in the EEA/UK), we only enable them after you consent, and you can change or withdraw that consent at any time via the Cookie Preferences link in the footer. When active, they may set their own cookies to distinguish visitors and sessions; their respective privacy policies apply.
- Brevo: Used to send transactional emails (verification, password reset) to your address via their SMTP relay infrastructure.
- Zoho Mail:Used to manage support communications sent to [email protected]. If you email us for support, your message is processed through Zoho's servers.
- Canva: Users may optionally connect their Canva account via OAuth to import email designs into MailViewr. When connected, we request access to read your Canva design metadata and content solely to enable this import feature. We store your Canva OAuth access token and refresh token to maintain your connection. These tokens are encrypted at rest and are never shared with third parties. You can disconnect your Canva account at any time from your dashboard, which immediately revokes and deletes your stored tokens.
- Google Gmail API (Save to Gmail Draft):If you choose to connect your Gmail account, we request Google's
gmail.compose scope solely to create a draft message in your own Gmail account when you click Save to Gmail Draft in the Email Builder. We use this access only to create a new draft pre-filled with the email you built, so you can review and send it yourself from Gmail. We do not read your existing emails, search or view any other mailbox content, or send anything on your behalf. Your Gmail OAuth access and refresh tokens are encrypted at rest and are stored only for as long as your Gmail connection stays active; disconnecting your Gmail account (available anytime from your dashboard) immediately deletes them. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Cookies
We use an HttpOnly cookie to maintain your authenticated session; it does not track you across other websites and is strictly necessary for the Service to function. We also set a second, first-party HttpOnly cookie containing the anonymous identifier described in Section 2, used to recognise returning visitors without requiring an account; it expires after 365 days. Google Analytics and Microsoft Clarity (see Section 4) are optional and, where required by law (such as in the EEA/UK), are only enabled after you consent — you can change or withdraw this at any time via the Cookie Preferences link in the footer. No advertising cookies are used.
6. Data Retention
Account data is retained as long as your account is active. You may request deletion of your account at any time by contacting us at [email protected]. We will delete your personal data within 30 days of a valid request.
Specific retention periods:
- Uploaded assets and saved projects: kept until you delete them or delete your account, subject to routine backup retention.
- Shared preview link access logs: retained for 30 days.
- Support emails: retained for 12 months.
- Anonymised analytics data: may be retained longer, since it cannot be tied back to you.
7. Security
Passwords are stored as bcrypt hashes and never in plain text. Authentication tokens are transmitted via HttpOnly cookies over HTTPS. We apply reasonable technical and organisational measures to protect your data, but no method of transmission over the internet is 100% secure.
8. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately.
9. Your Data Protection Rights
If you are a resident of India, you have the following rights under the Digital Personal Data Protection Act, 2023 (DPDP Act):
- Right to access information about the personal data we hold about you.
- Right to correction of inaccurate or incomplete personal data.
- Right to erasure of your personal data where it is no longer necessary for the purpose it was collected.
- Right to grievance redressal — you may raise a complaint with us before approaching the Data Protection Board of India.
If you are located in the European Economic Area, you have additional rights under the GDPR including the right to data portability and the right to object to processing.
To exercise any of these rights, contact us at [email protected]. We will respond within a reasonable timeframe.
10. International Data Transfers
Your data may be processed in countries other than your own, wherever our service providers operate. We take reasonable steps to protect transferred data and to comply with applicable data-protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects when the policy was last revised. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at [email protected].