Privacy Policy
Last updated: July 31, 2026
1. Information We Collect
We collect the following types of information:
- Account information: Email address, name, job title, organization name, and optional profile details such as phone number and timezone
- Billing information: Billing name and address (including country and postal code) and, where applicable, a business tax / VAT ID, collected for payment processing and tax compliance. Card details are entered directly with our payment processor (Stripe); we never receive full card numbers.
- Email content: HTML email source code, copy deck files, brand-guide files, and any personalization test values you upload for analysis (these may contain personal data such as recipient names or email addresses)
- Analysis reports: QA results generated from your uploaded content, including comments and audit-log entries created by your team
- Usage data: How you interact with the Service, including features used and analysis frequency
2. How We Use Your Information
We use your information to:
- Provide and improve the email QA analysis service
- Generate quality reports for your uploaded email content
- Authenticate your account and manage your profile
- Send important service notifications (account, security, updates)
- Deliver collaboration notifications you or your teammates trigger — @mentions, round-status briefs, and shared dev-brief links — by email and, if you configure it, to your Slack workspace
- Process payments and calculate applicable taxes through our payment processor
- Improve the accuracy and coverage of our automated checks
3. Data Storage & Security
Your data is stored securely using industry-standard encryption. We use Supabase for data storage with row-level security policies. Email content and analysis reports are associated with your account and are not accessible by other users. We implement appropriate technical and organizational measures to protect your data.
Headless rendering: Some analysis features (Layer 2 style extraction, design comparisons) render your email HTML in a sandboxed Chromium browser running on our infrastructure. The browser is locked down with SSRF protections that block requests to private / loopback / metadata endpoints. We follow external HTTP(S) requests only to load images your email itself references (e.g. CDN-hosted hero images), and we do not retain rendered pixel buffers beyond the lifetime of the analysis.
AI features:The AI Second-Reviewer and Brand Voice features send the email’s HTML plus rule findings to Anthropic’s Claude API. Anthropic processes the data per its own privacy commitments; we do not allow it to be used for model training. Token-counts are recorded for billing; the prompts themselves are not retained server-side after the response is written back to your report.
4. Data Retention
We retain your account information for as long as your account is active. Analysis reports are retained to allow you to review past results. Soft-deleted reports are permanently purged 30 days after deletion by our nightly cleanup job.
Delete-my-data: You can request full account deletion at any time from your profile page, or by emailing admin@sendlint.com. Upon confirmed account deletion, your auth record, profile, and all associated reports, brand rules, and rendered images are removed within 30 days. Email logs (audit trail) are retained per our service-provider’s policy.
Audit trail: For each QA workflow we keep an immutable audit log of who-did-what (status changes, manual findings, sign-offs, dev-brief shares). This trail is visible only to members of your organization and is exported alongside the compliance PDF. We retain the audit log for the life of the report and purge it together with the report on deletion.
Backups: Our database provider retains automated point-in-time backups (24 hours on free tier, 7 days on Pro). Deleted data may be recoverable inside that window; beyond it, recovery is not guaranteed. Customers with stricter recovery-time requirements should contact us to discuss higher-tier backup configurations.
For European customers requiring a Data Processing Agreement, see our DPA page.
5. Data Sharing
We do not sell your personal information. We may share data with:
- Service providers (sub-processors): Third-party services that help us operate the platform — hosting, authentication, payments, transactional email, error reporting, product analytics, and optional AI analysis. The current list is in our DPA.
- Team members: Within your organization, data may be shared with team members you have authorized
- Public share links: You can generate revocable, tokenized public links (30-day expiry by default, configurable) to share a report or round brief with people outside your organization. Anyone holding an active link can view the shared content without signing in, so you control who receives it; you can revoke a link at any time from the report.
- Slack (optional): If you configure a Slack incoming webhook, notification content — round-status updates, @mention comment previews, and the email addresses of mentioned teammates — is sent to the Slack channel you designate. That is your own workspace and destination, which you control, rather than a SendLint sub-processor.
- Legal requirements: When required by law or to protect our rights
6. Cookies & Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising trackers. We use PostHog, a product-analytics tool, to record how the Service is used (feature usage, navigation, and performance events) so we can improve it — this is product analytics, not advertising. PostHog is listed as a sub-processor in our DPA.
7. Your Rights
You have the right to:
- Access and download your personal data
- Correct inaccurate information in your profile
- Request deletion of your account and associated data
- Opt out of non-essential communications
- Export your analysis reports
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top reflects the most recent revision.
9. Contact
For privacy-related inquiries, please contact us at privacy@sendlint.com.