Privacy Policy
1. Introduction
Welcome to MailParse ("we," "our," or "us"), operated at mailparse.ai. MailParse is an AI-powered email parsing service that allows users to upload .eml and .msg files, paste raw email text, and extract structured data into Excel, CSV, and JSON formats. We are committed to protecting your privacy and handling your data — including the email content you upload — with care. This Privacy Policy explains what information we collect, how we use it, how long we retain it, and what rights you have.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Password (stored as a bcrypt hash — never in plaintext)
- Optional profile information (company name, job title)
- Team membership and role information (for team accounts)
2.2 Email Files and Content You Upload
MailParse's core function requires processing the email files and text you provide. We collect and temporarily store:
- .eml and .msg files you upload, including all headers, body content, and attachments
- Raw email text pasted into the paste tab
- Extracted records — the structured data produced by parsing (sender, recipients, dates, body text, custom field values)
- Parse jobs — metadata about each parsing operation (format, field selection, output format, completion time)
We process this content solely to provide the parsing service to you. We do not read, analyze, or use the content of your emails for any purpose other than producing the extracted output you requested. We do not use your email content to train any AI or machine-learning models.
2.3 Usage and Technical Data
- Usage logs: action types, timestamps, session IDs, and usage counts (for enforcing free-tier limits)
- IP address and approximate geolocation (for security monitoring and fraud prevention)
- Browser type, operating system, and referring URL (standard web access logs)
- UTM parameters and referral data (for understanding which marketing channels drive signups)
2.4 Billing Information
For paid plans, billing is handled by Stripe. MailParse does not store your full credit card number, CVV, or bank account details. We receive and store a Stripe customer ID, subscription status, and plan tier from Stripe's API.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the MailParse email parsing service
- Parse the email files and text you submit and return structured extracted data
- Enforce usage limits per plan tier (anonymous: 3 parses/session; Free: 10/day; Starter: 100/month; Plus: 500/month; Pro: unlimited)
- Process subscription payments and manage billing via Stripe
- Send transactional emails: account verification, password reset, subscription receipts, and service notifications
- Respond to support requests and questions
- Detect and prevent fraud, abuse, and security incidents
- Analyze aggregate, anonymized usage patterns to improve the product
- Comply with legal obligations
We do not sell your personal information or the content of your emails to third parties. We do not use your email content for advertising targeting.
4. Data Retention
We retain different categories of data for different periods:
| Data category | Retention period |
|---|---|
| Uploaded email files (.eml/.msg) | 30 days from upload, then auto-deleted |
| Extracted records (parse results) | 30 days from creation, then auto-deleted (Starter/Plus). Pro/Enterprise: configurable. |
| Parse job metadata | 90 days |
| Account information | Until account deletion |
| Usage logs | 12 months rolling window |
| Billing records (Stripe) | As required by law (typically 7 years) |
| Activity / audit logs | 12 months |
Enterprise customers can negotiate custom data retention policies and zero-retention options as part of their agreement.
5. Data Security
We implement appropriate technical and organizational security measures including:
- Transport encryption: TLS 1.3 for all data in transit between your browser and our servers
- Encryption at rest: AES-256 encryption for stored files and database records containing extracted email data
- Access controls: Role-based access within team accounts; production data is access-controlled and logged
- Authentication: Passwords are hashed with bcrypt; email verification is required; rate limiting on login attempts
- Monitoring: Activity logging and anomaly detection for unauthorized access attempts
No method of transmission or storage is 100% secure. If we become aware of a security breach that affects your data, we will notify you as required by applicable law.
6. Third-Party Services
We use the following third-party services to operate MailParse:
- Stripe — payment processing and subscription management. Stripe's privacy policy governs payment data.
- AWS S3 / CloudFront — cloud storage for uploaded email files and export files (production environment).
- Email delivery provider — transactional emails (account verification, password reset). Your email address is shared for delivery only.
We do not share your email file content with AI model providers unless you explicitly enable an AI feature (Plus+ AI field detection) and consent to that processing. Even then, only the specific email body text needed for field suggestions is sent; full attachment data and headers are not sent to third-party AI APIs.
7. Cookies and Tracking
MailParse uses cookies and similar technologies for:
- Session management: keeping you logged in and tracking anonymous usage limits (session cookie)
- CSRF protection: Laravel CSRF tokens to prevent cross-site request forgery
- Preferences: remembering your selected output format and field preferences
- Attribution: first-touch UTM parameter capture for understanding which campaigns drive signups (stored in session, not shared)
We do not use third-party advertising cookies or cross-site tracking pixels.
8. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and associated data. You can delete your account at any time from the profile settings page.
- Portability: Request an export of your extracted records and parse history in a machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Children's Privacy
MailParse is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
10. International Data Transfers
MailParse is operated from servers located in the United States. If you are accessing MailParse from outside the United States — including from the European Economic Area, United Kingdom, or other regions with data protection laws — your data may be transferred to and processed in the United States. We take appropriate measures to ensure such transfers comply with applicable data protection laws, including where required entering into Standard Contractual Clauses. Enterprise customers requiring EU data residency should contact us.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page, updating the "Last Updated" date, and — for significant changes — sending a notification to the email address associated with your account. Your continued use of MailParse after the effective date of the updated policy constitutes acceptance of the changes.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: