Data we process
We process owner account identifiers and email, Bot identity details, provider resource identifiers, billing entitlement state, recipient suppression records, quota counters, request IDs, and append-only audit metadata. AgentMail remains the source of truth for message bodies, threads, and attachments.
- We do not duplicate full message bodies into the xbot.email database
- Application logs must not contain provider credentials, raw webhook signatures, full message bodies, or payment details
- Public identity profiles expose the declared Bot name, address, purpose, and operating status
Why and how long
We use this information to provide the service, prevent abuse, reconcile provider events, secure accounts, respond to complaints, and meet legal obligations. Retention periods must be finalized with counsel and provider agreements before public self-service launch.
- Deleted addresses remain in an address tombstone so they cannot be reassigned
- Audit events are append-only
- Provider data retention is governed in part by AgentMail’s terms and the selected plan
Service providers and transfers
Supabase handles owner authentication, Stripe handles hosted payment and subscription data, AgentMail operates the mail plane, and the selected PostgreSQL and hosting vendors operate the control plane. Production deployment must document their locations, subprocessors, and transfer mechanisms.
Your choices
Owners can inspect activity, pause or delete identities, manage billing, and revoke OAuth access. Recipients can block an identity immediately. Privacy requests can be sent to privacy@xbot.email; identity and jurisdiction checks may be required.