Legal
Privacy Policy
Last updated August 21, 2026
BobtailMail (“we,” “us”) is a transactional email API operated by Ayudh Inc., a federal Canadian corporation based in British Columbia, Canada. This page explains what we collect, why, and what we do with it — for the operators who sign in to our console, and for the customers who send email through our API.
The short version
We collect what the service needs to authenticate you, send your email, and show you a record of what happened. We don’t run analytics or advertising trackers, we don’t sell data, and we don’t share it beyond the infrastructure providers that host the service and deliver the mail.
What we collect
Account data. When you sign in to the operator console, we store your email address, name, and a hashed password (we never store your password itself). Your browser holds a session cookie that authenticates you to the console; we do not use it for anything else, and we do not use any other cookie, tracking pixel, or analytics script on this site.
API credentials. When you mint an API key, we store a one-way hash of it, not the key itself — the plaintext key is shown to you exactly once, at creation.
Message content. When you send email through our API, we store the message you submitted — sender, recipients, subject, and body — along with its delivery status and a full event trail (accepted, sent, delivered, bounced, and so on). This is the core of the service: a durable record of every message you sent and what happened to it. It is retained for as long as your account is active.
Delivery and abuse signals. When a message you sent permanently bounces or a recipient marks it as spam, we record that recipient address against your account so we can refuse to send to it again. This protects your sending reputation and everyone else who shares our sending infrastructure.
Connection metadata. Like any web service, our infrastructure logs connection metadata (such as IP address) for security and abuse prevention.
Billing data. If you subscribe, your payment is handled entirely by a third-party payment processor — your card details go directly to them and never touch our servers. We store only opaque reference ids for your subscription and the plan status derived from them (active, past due, and so on), not your card number, name, or billing address.
Who else sees it
We use third-party cloud infrastructure providers to host the service, run our database, deliver email, and process payment on our behalf. They process data only as needed to provide that to us, under their own security commitments — we do not permit them to use your data for any purpose of their own. We do not sell your data, and we do not share it with advertisers, data brokers, or anyone else, under any circumstance.
We disclose data if legally required to — for example, in response to a valid court order — and only to the extent the law requires.
Your recipients
If you use our API to send email, the people you send it to are not our customers — they’re yours. You are responsible for having a lawful basis to email them (see our Terms of Service). We process their address and message content solely to deliver your message and to maintain the delivery record described above.
Retention and deletion
We keep account and message data for as long as your account is active, since the message record is the product. If you want your account or its data deleted, contact us and we will delete or anonymize it, except where we’re required to keep something for a legitimate legal or security reason.
Changes to this policy
If this policy changes in a way that matters, we’ll update the date at the top of this page. We don’t send policy-update emails to test our own product on you.
Contact
Questions about this policy, or a request about your data: write to operator@bobtailmail.com.