Legal
Privacy Policy
How MailBeacon collects, uses, stores, and deletes information when you use our website, dashboard, and email validation API.
Effective and last updated: July 19, 2026
1. Scope and roles
This Privacy Policy explains how MailBeacon (“MailBeacon,” “we,” “us,” or “our”) handles information in connection with mailbeacon.co, our customer dashboard, and our validation API (together, the “Service”).
For account, billing, website, and support information about you as a customer or visitor, MailBeacon acts as the organization deciding how that information is used.
For email addresses and files you submit so we can validate them (“Customer Data”), you control the list and the legal basis for processing it. MailBeacon processes Customer Data only to provide the Service you request, as described in our Terms of Service and this Policy. You are responsible for having the rights and notices needed to submit those addresses to us.
2. Information we collect
Account and profile information. When you create an account or sign in with Google, we collect details such as your name, email address, authentication identifiers, email-verification status, and password hash (if you use a password). We also store API key metadata (for example key id, name, and prefix) needed to operate your account.
Billing information. Payments are processed by Stripe. We receive and store Stripe customer and purchase identifiers, plan or token amounts, and payment status. We do not store full payment-card numbers on MailBeacon systems.
Customer Data submitted for validation. This includes email addresses you send to the real-time API, addresses in bulk uploads (CSV, TXT, or spreadsheet files), and related job metadata such as filename, row counts, and validation results.
Usage and service data. We record which endpoints were used, tokens consumed, timestamps, job status, and similar operational metrics. We design usage logs so they track account and API activity rather than the content of each validated address.
Website, dashboard, and communications data. If you contact us, we receive the information you send (such as name, email, company, and message). Our sites may also collect device and analytics data through cookies or similar technologies, including page views and product events, as described in Section 7.
3. How we handle emails submitted for validation
This is the core of how MailBeacon treats the addresses you ask us to check.
Real-time (single) validation. When you validate an address through the API or dashboard, we process it in memory to run syntax, domain, disposable, catch-all, SMTP, and related checks, then return the result. We do not write that address into our product database as a stored validation history. Usage accounting records that a validation occurred and how many tokens were used, not the address itself.
Bulk validation. When you upload a list, we temporarily store the file and the addresses associated with the job so our workers can process them. After the job finishes, we delete the original upload and the per-address working records. We keep the downloadable result file available for 7 days, then expire the job and delete that result file. Job summary metadata (such as status and counts) may remain for account history and support.
Checks that contact third parties. Some validation steps necessarily disclose information outside MailBeacon:
- SMTP mailbox checks may send the full address to the destination domain's mail servers (for example via
RCPT TO) so we can observe whether the mailbox is accepted. - Domain and reputation checks may query blocklist or DNS services using domain or mail-server information derived from the address.
Those disclosures are part of performing the validation you requested. MailBeacon does not use Customer Data to email the people on your list, build a marketing database, sell lists, or enrich a public contact graph.
Operational logs. Application logs may include domains, error context, or other technical details needed to run and debug the Service. We aim to avoid logging full validated addresses in ordinary request logs. Infrastructure providers may retain transient request logs according to their own systems.
4. How we use information
We use information to:
- provide, secure, and improve the Service;
- authenticate users, manage API keys, and enforce rate limits;
- process payments, token balances, and refunds;
- send account emails such as verification and password reset;
- respond to support and contact requests;
- monitor abuse, prevent fraud, and comply with law or lawful requests; and
- understand product usage through aggregated or account-level analytics.
We may use aggregated or de-identified metrics that cannot reasonably identify you or an individual on your list.
5. How we share information
We do not sell Customer Data or your account information. We share information only as needed to operate the Service, including with:
- Infrastructure providers that host our application, database, and bulk-file storage;
- Stripe for payments and billing portal features;
- API-key infrastructure used to issue and verify keys;
- Transactional email providers used to send account and support-related messages;
- Google if you choose Google sign-in;
- Analytics providers that help us understand how the website and dashboard are used;
- Bot-protection providers on signup or similar forms; and
- Destination mail servers and DNS/reputation services as part of performing validations you request.
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality protections.
6. Retention and deletion
We retain information only as long as needed for the purposes above:
- Real-time validation addresses: not retained in our product database after the request completes.
- Bulk input files: deleted after processing (or earlier if a job is cancelled or fails in a way that triggers cleanup).
- Bulk result files: available for 7 days, then deleted.
- Account, billing, and usage records: kept while your account is active and as needed for security, accounting, dispute resolution, and legal compliance.
You can delete your account from the dashboard settings. Account deletion removes your MailBeacon account data needed to use the Service, including API keys, usage records, and associated bulk job files (subject to cascading deletes). We do not keep a separate archive of deleted account profiles. Product analytics may retain a non-identifying deletion event (for example that an account was closed and high-level purchase totals). Payment processors such as Stripe may retain their own billing records independently of MailBeacon.
If you need help deleting a bulk result before it expires, or have another privacy request, contact us at support@mailbeacon.co.
7. Cookies and analytics
We use cookies and similar technologies for authentication (such as a secure session cookie for the dashboard), preferences, and product analytics. Analytics tools may set cookies across MailBeacon subdomains and record events such as page views, sign-ups, and validation actions. On the dashboard, analytics may associate events with your account identifiers, including email address, so we can understand product usage.
You can control cookies through your browser settings. Blocking certain cookies may limit dashboard or analytics functionality.
8. Security
We use administrative, technical, and organizational measures appropriate to the nature of the Service, including encrypted transport (HTTPS/TLS), access controls, hashed passwords, and isolation of secrets. No method of transmission or storage is completely secure. If you believe your account or an API key has been compromised, contact us immediately.
9. International transfers
MailBeacon is operated from the United States. If you access the Service from another country, your information may be processed in the United States and other locations where our providers operate. Those locations may have data-protection laws different from the laws where you live.
10. Your choices and rights
Depending on where you live, you may have rights to:
- access or correct account information;
- delete your account or request deletion of certain data;
- export information we hold about your account; and
- object to or restrict certain processing where applicable law allows.
Many account controls are available in the dashboard. For other requests, email support@mailbeacon.co. We may need to verify your identity before fulfilling a request. These rights may be limited where payment processors or applicable law require retention of billing records, or where the request concerns Customer Data you control as the list owner.
11. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided information to us, contact us and we will take appropriate steps.
12. Changes to this Policy
We may update this Privacy Policy to reflect product, legal, or operational changes. We will revise the date above and, when changes are material, provide additional notice when practical. Continued use of the Service after an update means the updated Policy applies going forward.
13. Contact
Privacy questions or requests can be sent to support@mailbeacon.co. Related terms appear in our Terms of Service and Refund Policy.