Privacy Policy
Last updated 6 August 2026
This explains what Inbox Penny does with personal data. It covers two different groups of people, and the distinction matters throughout:
- Customers — people with an Inbox Penny account. We decide how their data is used, so we are the controller.
- Contacts — the people our customers email. The customer decides who to hold and what to send; we act on their instructions, so they are the controller and we are their processor.
If you received an email sent through us and want it to stop, use the unsubscribe link in that email — it works immediately and permanently. If you want your details removed entirely, contact the sender whose name is on the message; they control that data. We will help them if asked.
Customer data we hold
- Your name, email address, organisation name, and password.
- Your brand profile if you fill one in, and your postal address, which appears in the footer of the mail you send because the law requires it.
- Billing records: what you loaded, what you spent, and when.
- Operational records — sessions, which features you used, and AI usage counts for fair-use limits.
Passwords are stored as scrypt hashes. Session tokens and API keys are stored as SHA-256 hashes, never in a readable form — which is also why we can show an API key only once, at the moment you create it.
Contact data we process for you
Whatever you upload: email address, name, phone number, and any custom fields you create. We use it only to run the service for you — to send the mail you ask us to send, to build the segments you define, and to show you the results.
We do not sell data, we do not share it between customers, and we do not use your contacts to market anything of our own.
Where we store an IP address
Signup forms are the one place we keep a raw IP address. When someone submits one of your forms we record the exact wording they agreed to, the time, their IP address and their browser’s user agent. That is the evidence that consent was given, and it is worth nothing without the address, so here the IP is the point.
Everywhere else we deliberately throw the address away. When a recipient opens or clicks, we resolve the country — and for the United States the state — at the moment the event arrives, store only those codes, and discard the IP. Location lookup happens on our own servers against a local database, so the address is not sent anywhere. Our abuse rate limiter counts requests against a one-way hash rather than an address.
Email tracking
Campaigns record when a message was delivered, opened, clicked, bounced or reported as spam, along with the recipient’s email client and country. Opens are measured with a small invisible image and clicks by routing links through click.inboxpenny.com. Many mail apps block or pre-fetch that image, so open counts are indicative rather than exact.
Account emails are not click-tracked. Activation links and form confirmations go out unwrapped, deliberately, so nothing sits between you and a link you need to work.
Who else sees the data
We use a small number of providers, each for one job:
- Amazon Web Services — sends your email and stores the images you upload.
- Railway — hosts the application and the database.
- Cloudflare — serves our domains.
- Stripe — takes payments. Card details go straight to Stripe on their own page; they never touch our servers, and we never see your card number.
- Anthropic — powers Penny’s AI features. Your contacts are never sent to it — only campaign copy, your brand profile, and the names of your lists and custom fields.
We will also disclose data where the law requires it. If the business is ever sold, data would transfer with it and we would tell you first.
One list shared across customers
When an address hard-bounces, we record that the address is undeliverable on a platform-wide list so nobody else wastes a send on it and everyone’s deliverability is protected. That record is only the address. It does not include which customer mailed it, which campaign, or when — deliberately, so it can never be used to learn about another customer’s audience.
Where data is held
On servers in the United States. If you are in the UK or EU, that is a transfer outside your region, made under the providers’ standard contractual clauses.
How long we keep it
- Contacts and campaigns: for as long as your account is open, or until you delete them.
- Unsubscribes, spam complaints and the records behind them are kept even if you delete the campaign, because they are what stops someone being emailed again after they asked not to be. This is also why a campaign that has been sent cannot be deleted.
- Consent records from signup forms: kept while you may need to prove consent.
- Billing records: kept as long as tax and accounting rules require.
Your rights
Depending on where you live you may have the right to see the data we hold about you, correct it, delete it, or take it elsewhere. Write to hello@inboxpenny.com and we will respond within 30 days.
You can export your contacts yourself at any time — every list and segment has a CSV download. If you are a contact rather than a customer, ask the sender who emailed you: they hold the data and we act on their instructions.
Cookies
We set one cookie, to keep you signed in. There is no advertising, no analytics script and no third-party tracker on this site, which is why there is no cookie banner to dismiss.
Children
The service is not for under-16s and we do not knowingly collect their data.
Changes
We will post updates here and email account owners about material ones. See also our Terms of Service.
Contact
Inbox Penny — hello@inboxpenny.com
Questions about either document? hello@inboxpenny.com

