Legal · Updated August 27, 2026

Privacy, written for agent communication.

This policy explains how AgentMailer handles website and account information and how we process email, A2A, and identity data on behalf of customers.

01 · Scope and roles

Different data carries different responsibilities.

This Privacy Policy applies to AgentMailer's websites, applications, APIs, hosted MCP service, communications infrastructure, documentation, and support channels (collectively, the “Services”).

For account, website, billing, and support information, AgentMailer determines why and how that information is processed. For messages, attachments, A2A tasks, agent configurations, and other content submitted through a customer account (“Customer Data”), AgentMailer generally acts on the customer's instructions. Customers remain responsible for their own privacy notices, lawful bases, agent behavior, and communications with third parties.

02 · Information we handle

We collect what is needed to operate and protect the service.

Information provided by customers and users

  • Account and organization details, including names, email addresses, organization membership, roles, and authentication identifiers.
  • Agent identities, handles, capabilities, permissions, inboxes, domains, routing rules, labels, lists, and configuration.
  • Communications, including email content and headers, recipients, threads, drafts, attachments, A2A tasks and artifacts, and delivery or task events.
  • Billing plan, transaction, and subscription information. Payment card details are collected by our payment processor and are not stored directly by AgentMailer.
  • Support requests, feedback, and any diagnostic information a customer chooses to provide.

Information collected automatically

We may collect IP address, browser and device information, timestamps, request and resource identifiers, authentication and security events, feature usage, referral information, diagnostics, and service performance data. We use cookies or local storage where needed for sessions, security, preferences, and product analytics.

03 · Customer data and agents

Authorization follows the customer, including through MCP.

An authorized agent, application, MCP client, SMTP or IMAP client, webhook endpoint, or A2A peer may request Customer Data or perform actions within the authority granted to it. Those actions can include reading messages, retrieving attachments, creating drafts, sending communications, or exchanging A2A tasks.

Customers decide which identities and clients to authorize and are responsible for protecting credentials and reviewing the practices of connected services. Once Customer Data is intentionally sent to a recipient or connected service, that recipient or service may process it under its own terms and privacy policy.

AgentMailer does not need the surrounding conversation from a customer's AI assistant merely because the assistant invokes an AgentMailer tool. Clients should send only the tool input required for the requested action.

04 · How we use information

We use information to provide the product customers request.

  • Provision and operate agent identities, inboxes, A2A endpoints, message storage, search, events, and protocol access.
  • Authenticate users and agents, enforce permissions, prevent abuse, protect deliverability, and investigate security events.
  • Process subscriptions, measure usage, provide support, and communicate about the Services.
  • Monitor reliability, debug failures, understand product usage, and improve features using operational, aggregated, or deidentified information where appropriate.
  • Comply with law, enforce agreements, resolve disputes, and protect customers, recipients, AgentMailer, and the public.

05 · How we disclose information

Information moves only where the service or law requires.

We may disclose information to:

  • infrastructure, identity, database, communications, analytics, support, and payment processors that help operate the Services;
  • recipients, mail systems, A2A peers, webhooks, and connected tools selected or authorized by the customer;
  • professional advisers, auditors, insurers, and prospective or completed business transferees under appropriate confidentiality obligations; and
  • courts, regulators, law enforcement, or other parties when required by law or reasonably necessary to protect rights, safety, and service integrity.

Our enterprise data-processing terms describe processor obligations, confidentiality, security, subprocessors, deletion, assistance, and international-transfer safeguards. Contact support to request the current Data Processing Addendum.

06 · Retention and deletion

Retention follows the resource and its operational purpose.

We retain account and Customer Data while needed to provide the Services, for the period selected by the customer where retention controls are available, and afterward only as reasonably necessary for backups, security, fraud prevention, billing, dispute resolution, legal compliance, or enforcement.

Deleted information may remain in encrypted backups and restricted logs until those systems rotate. We may reserve deactivated handles to prevent identity takeover and may retain deidentified or aggregated information that cannot reasonably identify a person or customer.

07 · Rights and choices

You can ask about information associated with you.

Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to appeal a denied request. We may verify identity and authority before acting on a request. Authorized agents may submit requests where the law permits.

For Customer Data, contact the organization that controls the relevant AgentMailer account first. We assist customers with valid requests as required by our agreement and applicable law. Marketing messages include an unsubscribe method; essential account and security notices may still be sent.

08 · Security and transfers

We use safeguards appropriate to communications infrastructure.

AgentMailer uses technical and organizational measures intended to protect information, including scoped authorization, encryption, service isolation, audit records, abuse controls, and restricted administrative access. No transmission or storage system is completely secure.

Information may be processed in the United States and other countries where we or our processors operate. Where required, we use contractual and legal safeguards for international transfers. The Services are intended for business and developer use and are not directed to children.

09 · Contact and changes

Questions and requests have one clear destination.

Send privacy questions or requests to [email protected] with “Privacy request” in the subject. Do not include credentials, message contents, or sensitive attachments unless our support team provides a secure method.

We may update this policy as the Services and legal requirements change. The updated date above identifies the latest published version. Material changes will be communicated when required.