Privacy Notice

The control plane stores the minimum metadata needed to bind owners, enforce policy, bill identities, and explain what happened.

Data we process

We process owner account identifiers and email, Bot identity details, provider resource identifiers, billing entitlement state, recipient suppression records, quota counters, request IDs, and append-only audit metadata. AgentMail remains the source of truth for message bodies, threads, and attachments.

  • We do not duplicate full message bodies into the xbot.email database
  • Application logs must not contain provider credentials, raw webhook signatures, full message bodies, or payment details
  • Public identity profiles expose the declared Bot name, address, purpose, and operating status

Why and how long

We use this information to provide the service, prevent abuse, reconcile provider events, secure accounts, respond to complaints, and meet legal obligations. Retention periods must be finalized with counsel and provider agreements before public self-service launch.

  • Deleted addresses remain in an address tombstone so they cannot be reassigned
  • Audit events are append-only
  • Provider data retention is governed in part by AgentMail’s terms and the selected plan

Service providers and transfers

Supabase handles owner authentication, Stripe handles hosted payment and subscription data, AgentMail operates the mail plane, and the selected PostgreSQL and hosting vendors operate the control plane. Production deployment must document their locations, subprocessors, and transfer mechanisms.

Your choices

Owners can inspect activity, pause or delete identities, manage billing, and revoke OAuth access. Recipients can block an identity immediately. Privacy requests can be sent to privacy@xbot.email; identity and jurisdiction checks may be required.