Privacy Policy
We're an email forwarding service, so the most important thing to say up front is what we don't keep: your email. This page explains everything we do collect and why.
Last updated Jul 29, 2026
1.The short version
2.Who we are
SendMailAs is operated by Mohit Gaddam, and is the data controller for the information described here. For any privacy question or request, email support@sendmailas.com.
3.What we collect
Account information. When you sign in with Google we receive your name, email address and profile picture. We store the forwarding address you nominate, and your subscription status and customer reference from our payment provider.
Domain and routing data. The domains you add, the aliases you create, and the destination addresses they forward to. DKIM keys and the SMTP credentials issued for your domain are stored encrypted.
Delivery metadata. For outbound mail: the from-address, message ID and timestamp. For mail that bounces: the recipient address, the error code and the message returned by the receiving server. We use this for sending limits, bounce protection and support.
Technical and signup data. Your IP address at signup, and the approximate country and city derived from it. How you arrived at the site — referrer, campaign parameters and landing page. Session records including IP address and browser user agent.
Support conversations. Messages you send us through in-app support, including any attachments.
4.What we don't collect
- The subject or body of your email. Messages pass through our relay and are not written to storage.
- Your card details. Payments go directly to Polar; we only ever see a customer reference and subscription status.
- Your Google password. Sign-in happens on Google's side; we receive a token, never a password.
5.Google user data
If you connect a Google mailbox, you grant access to specific Gmail scopes so we can configure the “send mail as” alias on your behalf. We use that access only to perform the setup you asked for.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, and we do not sell it or transfer it to others except as needed to provide the service. You can revoke access at any time from your Google account's security settings.
6.Why we're allowed to hold it
Where the UK or EU GDPR applies, we rely on: performance of our contract with you, for account, domain and delivery data; our legitimate interests in keeping the platform secure, preventing abuse and protecting deliverability, for technical and delivery metadata; and your consent, for optional analytics.
7.Who else processes it
We use the following providers to run the service. Each processes data on our instructions only.
We do not sell your personal information, and we do not share it for advertising. We may disclose information where the law requires it.
8.Where your data goes
Our providers operate in several countries, so your information may be processed outside the country you live in — including in the United States, the European Union and India. Where data leaves the UK or EEA, we rely on the transfer mechanisms our providers have in place, such as Standard Contractual Clauses.
9.How long we keep it
- Account, domain and alias data: until you delete the domain or your account.
- Delivery and bounce metadata: retained while the account is active, because sending limits and bounce protection depend on recent history.
- Support conversations: retained so we have context if you write in again.
- Deleting your account removes your account record, domains, aliases and routing configuration from our systems.
10.Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, object to or restrict how we use it, receive it in a portable format, or withdraw consent. Residents of California, the EU, the UK, Australia and India have specific rights under their local law.
Email support@sendmailas.com and we'll action it. You can delete most of your data yourself from your account settings. If you think we've handled your data badly, you can complain to your local data protection authority.
11.Cookies
We set a session cookie to keep you signed in — the product does not work without it. We also use privacy-friendly traffic analytics to understand which pages people find useful. We do not use advertising or cross-site tracking cookies.
12.Security
Traffic is encrypted in transit. SMTP credentials and DKIM private keys are encrypted at rest. Access to production systems is limited to the operator of the service. No system is perfectly secure, but if a breach affects your data we'll tell you promptly.
13.Children
SendMailAs isn't intended for anyone under 16, and we don't knowingly collect their information. If you believe a child has created an account, email us and we'll remove it.
14.Changes
If we make a material change to this policy, we'll email account holders before it takes effect. The date at the top of this page always reflects the latest version. See also our Terms of Service.