Privacy Policy

Last updated 9 September 2026

Campaign previews

Before subscribing, you can create a bounded campaign preview. We store the company details you confirm, public website excerpts, targeting, draft copy and plan preference for 30 days from creation. A first-party, HTTP-only possession cookie links an anonymous preview to your browser; after sign-in it is associated with your workspace. Confirmed details and relevant website text are sent to Anthropic to suggest buyers and draft copy. No contact enrichment or sending occurs in a preview. We store hashed network identifiers temporarily to enforce abuse limits. Expired previews are inaccessible and removed by daily cleanup; deletion requests can be sent to privacy@trymaila.com.

Who we are

Maila is operated by Maila Ltd ("Maila", "we"). This policy explains what we collect when you use trymaila.com and the Maila application, why we collect it, and the choices you have. Contact: privacy@trymaila.com.

What we collect

Account data you give us (name, email, company) through Clerk, our authentication provider. Workspace data you create (campaign websites, research, customer segments, outreach sequences, teammates, jobs, approvals and run logs). Connection tokens for tools you authorise (for example Google), stored encrypted in your workspace vault. Billing data handled by Stripe; we never see full card numbers. Usage and diagnostic data such as request logs and error reports. We record first-party funnel event names and page categories to improve signup and campaign setup; those events do not include your website, email or user ID and respect Do Not Track and Global Privacy Control. On the production site, Meta Pixel and Meta Conversions API may receive page and conversion events, browser identifiers, ad click identifiers, network and device information, and account details when you are signed in. To display a company logo during setup, Google’s favicon service may receive the public company domain and ordinary browser request data. A session-storage draft remembers your entered company website, and first-party cookies preserve your funnel state and advertising attribution.

How we use it

To run the service: executing the jobs you configure, showing you what your teammates did, and billing your plan. To secure the service: detecting abuse and enforcing plan limits. To measure advertising and understand whether campaigns lead to visits, registrations and purchases. To communicate: transactional email about your account and, if you opt in, product updates. We do not sell personal data and we do not train models on your data.

Model providers

When a teammate runs, the content needed for that task is sent to the model provider you configured (for example Anthropic) using your own API key, or to our metered pool using Maila's provider account. Provider terms and retention apply to that transfer. Your credentials are never included in model prompts.

Google user data

If you connect a Google account, Maila requests only the scopes shown on the consent screen. Outbound campaigns need one sensitive scope, gmail.send, which lets Maila send email as you and gives no ability to read your mail. Maila's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We store the refresh token encrypted with a key held outside the database, plus the message and thread identifiers of what we sent and the text of replies you receive through Maila. We do not use Google user data to train models, and we do not sell or transfer it. Disconnecting a Google account deletes its stored tokens immediately and cancels anything that mailbox was about to send. You can also revoke access at myaccount.google.com/permissions.

Sending on your behalf

When a campaign is running, Maila composes each email and Google sends it from your connected account, so the message carries your domain's own authentication and appears in your Sent folder. You remain the sender in law and in the recipient's eyes. Every outreach email carries a one-click unsubscribe link and your business postal address, and anyone who unsubscribes is suppressed across every campaign in your workspace.

Retention and deletion

Workspace data is retained while your account is active. You can delete teammates, connections, jobs and run logs from the app at any time, and you can request full account deletion at privacy@trymaila.com. Deleted data is removed from live systems within 30 days.

Sub-processors

Cloudflare (hosting, storage), Clerk (authentication), Stripe (payments), Anthropic (model inference for the metered pool), Meta (advertising measurement), and Google (favicon retrieval and connected services you authorise).

Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Email privacy@trymaila.com and we will respond within 30 days.

Changes

We will post changes here and, for material changes, email account owners before they take effect.