Privacy Policy
Mailgent gives AI agents a real inbox, credential vault, calendar, and verifiable identity. This policy explains what data we collect to run those services, how we use and protect it, who we share it with, and how long we keep it.
This Privacy Policy describes how Mailgent (“Mailgent,” “we,” “us”) handles information in connection with the Mailgent website, console, API, and Model Context Protocol (MCP) connectors (together, the “Services”).
Mailgent is infrastructure operated on behalf of a customer — the human or organization that creates an account and configures the AI agents that use it. If you interact with an agent built on Mailgent, that customer is the controller of your data and their own privacy policy also applies.
Who this policy covers
We process two broad groups of information: data about account holders (people who sign up, log in to the console, and hold API keys), and data that flows through the Services because an agent acts on a customer's behalf — for example the contents of an email an agent sends or receives.
- Account holders — the customer that provisions identities, configures connectors, and is billed.
- Agent-mediated data — information that passes through email, vault, calendar, Slack, social, and payment features while an agent operates under a customer's credentials.
Information we collect
- Account & identity data — name, email address, organization, authentication identifiers, API keys, OAuth client registrations, and the agent identities you create.
- Email data — messages, threads, headers, attachments, labels, and routing rules that agents send or receive through a Mailgent inbox.
- Vault data — credentials you choose to store: secrets, API keys, payment card details, shipping addresses, and TOTP/2FA seeds. Vault contents are encrypted at rest; we do not process payments and do not use card data except to return it to the authorized agent.
- Calendar data — events, attendees, and availability managed through the calendar tools.
- Connected-service data — access tokens and metadata for integrations you connect, such as Slack workspaces and social accounts, plus the content of messages or posts sent through them.
- Wallet & payment activity — blockchain wallet addresses, mandates, and a record of payment activity initiated through the Services.
- Usage & technical data — logs, tool-call records, IP address, device/browser information, and timestamps used to operate, secure, and debug the Services.
How we use information
- To provide the Services and execute the actions an agent is authorized to take.
- To authenticate users and agents, issue and verify OAuth tokens, and enforce scopes and permissions.
- To secure the platform — detect abuse, prevent fraud, and investigate incidents.
- To operate billing and account management.
- To provide support and respond to your requests.
- To meet legal and regulatory obligations.
We do not sell personal information, and we do not use the content of your email, vault, or connected services to train machine-learning models.
How we protect data
- Data is encrypted in transit (TLS/HTTPS) and vault secrets are encrypted at rest.
- Access is scoped: OAuth tokens are bound to a single identity and limited to granted scopes; API keys are segmented for identity vs. platform operations.
- Tools are annotated as read-only or destructive so clients can require confirmation before high-impact actions.
- We apply least-privilege access controls and audit logging for sensitive operations.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you and the relevant authorities as required by law.
Data retention
We keep information for as long as your account is active or as needed to provide the Services. After that, we retain data only as long as necessary for the purposes described here — to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce agreements.
- Email, vault, calendar content — retained until you delete it or close your account; deletion through the Services removes it from active systems.
- Operational logs — retained for a limited period for security and debugging, then deleted or anonymized.
- Billing records — retained as required by tax and accounting law.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise many of these directly in the console, or by contacting us.
- Access and review the data tied to your account and agents.
- Delete messages, vault entries, calendar events, and identities through the Services.
- Revoke API keys and OAuth client authorizations at any time.
- Request export or deletion of your account data by emailing us.
If you are an end user whose data was handled by an agent operated by one of our customers, please contact that customer first; we will support their handling of your request.
International data transfers
Mailgent is operated by an entity based in Singapore, and we handle personal data in line with Singapore's Personal Data Protection Act (PDPA). We may process and store data in Singapore and in other countries where we or our service providers operate.
Where data is transferred across borders, we use appropriate safeguards — such as contractual protections — so that it receives a comparable standard of protection.
Children's privacy
The Services are intended for businesses and developers and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the Services evolve or the law changes. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Continued use of the Services after changes take effect constitutes acceptance.
Contact us
Questions, requests, or privacy concerns: email privacy@mailgent.dev. For general inquiries, hello@mailgent.dev.
Questions about this policy? Email privacy@mailgent.dev or see the Terms of Service.