Privacy Policy

Last updated: October 2026

1. Our commitment

Hatched Mail is built privacy-first. We do not track you, we do not sell your data, and we do not show ads. Your email content lives on your PurelyMail IMAP server — we never store, read, or analyze your email messages on our servers.

2. What we collect

  • Account information: Your name, email address, and password (hashed via Better Auth). Needed to authenticate you.
  • Mail credentials: Your PurelyMail email and app password, encrypted with AES-256-GCM. Used only to connect to your IMAP/SMTP server on your behalf.
  • Audit logs: Records of auth events (login, signup, credential changes) for security and GDPR compliance. Retained for 90 days.
  • Billing information: Your Stripe customer ID and plan status. Payment details are handled entirely by Stripe — we never see your card number.

3. What we do NOT collect

  • Email content, attachments, or metadata — these are fetched live from your IMAP server and never stored
  • Analytics, tracking pixels, or usage telemetry
  • Third-party advertising data
  • Reading patterns or "engagement" metrics

4. Data storage

All data is stored in Neon Postgres (Singapore region, ap-southeast-1). Credentials are encrypted at rest with AES-256-GCM. Sessions expire after 90 days. The database is accessed only by the Hatched Mail application via encrypted connections.

5. Your rights (GDPR)

  • Data export: Download all your data as JSON via Settings → Account → Export
  • Right to erasure: Delete your account and all associated data via Settings → Account → Delete
  • Consent management: View and manage your consent records via Settings
  • Audit trail: All data access events are logged and available for review

6. Third-party services

  • PurelyMail: Your mail host. We connect to your IMAP/SMTP server — your email content stays with PurelyMail.
  • Neon: Database hosting (Singapore). Stores account data, encrypted credentials, sessions.
  • Vercel: Application hosting (serverless functions). No persistent data storage.
  • Stripe: Payment processing. We store only your Stripe customer ID — no card details.
  • SenderKit: Transactional email delivery (verification, password reset, welcome emails).

7. Security

We use industry-standard security measures: AES-256-GCM encryption for credentials, HTTPS for all connections, HSTS enabled, CSP headers on all pages, rate limiting on auth endpoints, and regular security audits. We do not store passwords in plaintext — Better Auth handles hashing with bcrypt.

8. Contact

Questions about privacy? Email us at hello@hatched.digital or reply to any email from us.