Who this covers
This notice covers mailysend.com — the marketing and documentation site you are reading — and the hosted sign-up at /sign-up, both operated by [legal entity] of [registered address].
It does not cover a MailySend instance you deploy. That software runs in your Cloudflare account, under your own privacy notice, and we have no access to it.
What the website collects
- Request logs. Cloudflare records the usual edge log for every request — IP address, user agent, URL, timestamp, response status — to serve the page and to stop abuse. We keep no separate copy.
- Nothing else by default. There is no analytics script, no advertising pixel, no session replay, and no third-party embed on the marketing or documentation pages.
- What you type into a form. If you sign in or claim a hosted instance at
/setup, we process the email address you give us so we can send you a one-time code and associate your deployment with you.
Self-hosted instances: your data, your account
When you deploy MailySend, every piece of email data lives in Cloudflare resources you own: messages and events in D1, suppressions and keys in KV, attachments and exports in R2, aggregates in Analytics Engine, and per-mailbox state in Durable Objects. It is created by your Worker, in the region you chose, under your Cloudflare account.
In data-protection terms that makes you the controller and Cloudflare your processor. We are neither. We ship no telemetry on message content, hold no production credentials for your deployment, and could not produce your data if we were asked for it. The data processing terms set out the roles in full.
The hosted offering
If you use the hosted offering rather than deploying yourself, we process the personal data your instance holds — contact records, message metadata and delivery events — solely to run the service on your instructions. We are your processor for that data, and the same deletion and export routes described below apply.
Legal basis and retention
- Legitimate interests for edge request logs (serving the site and preventing abuse), retained for as long as Cloudflare's edge logging retains them.
- Contract for the account email address and session cookie, retained while your account exists and deleted within 30 days of you closing it.
- Retention inside a MailySend instance is a configuration value you set at deploy, not a plan feature we control.
Your rights
Depending on where you live you may have rights of access, correction, deletion, portability, restriction and objection. For data we hold, write to [privacy contact address] and we will answer within one month. For data inside a self-hosted instance, the request belongs to whoever operates that instance — deleting a contact there cascades through D1, KV suppressions, R2 attachments and the event stream.
If you are unhappy with our answer you may complain to your supervisory authority in [jurisdiction].
Changes
Changes are published here with a new date at the top, and material changes are noted in the changelog.