Last updated: 8 December 2025 · Data controller: GPTemail.me (UK‑based). Contact: privacy@gptemail.me.
What we collect
- Account: email, name (if provided), authentication tokens.
- Billing: Stripe customer ID, subscription status, plan usage counts.
- Product data: emails you route to our inboxes (content, headers, metadata), processing results, logs/metrics.
- Technical: IP, user agent, request IDs, event timestamps.
- Support/comms: messages you send us.
Why we process your data (legal bases)
- Provide the service (contract).
- Billing and fraud prevention (legitimate interests/contract).
- Product analytics and reliability (legitimate interests) with IP minimisation and aggregation.
- Legal compliance (records, abuse prevention).
- Marketing emails only if you opt in (consent; you can opt out anytime).
Retention
- Email content/results: 30 days by default; you can request earlier deletion.
- Billing and audit logs: up to 6 years (tax/records).
- Account data: kept while you have an account; deleted 30 days after closure unless law requires longer.
Your rights (UK/EU GDPR)
You can request access, correction, deletion, restriction, objection to processing, and data export. Email privacy@gptemail.me. We respond within 30 days.
Data locations & transfers
Primary hosting is in the UK/US (Google Cloud). Optional EU-only stack (eur3/europe-west4) is available on request; data stays in-region for customers who choose it. International transfers use SCCs and provider safeguard programs. See the EU addendum for lawful bases, transfer safeguards, and retention tables.
Subprocessors
- Google Cloud (hosting, storage, AI).
- OpenAI / Gemini models (content processing).
- Stripe (payments).
- ZeptoMail (outbound email).
- Cloudflare (edge, email ingress).
See the Data Processing Agreement for full list and change notification.
Security
- Transport encryption (HTTPS/TLS).
- Secret Manager for keys; least-privilege service accounts.
- Per-tenant access controls in Firestore; audit logging.
- Automated monthly usage resets and abuse monitoring.
Contact & complaints
Email privacy@gptemail.me. UK residents may complain to the ICO; EU residents to their local DPA.