Security & data handling
Email is sensitive. Here is exactly what we store, what we never store, and who touches your data.
What we never keep
- Message bodies are deleted from our servers the moment your notification is delivered. The dashboard never displays content — it can’t, we don’t have it.
- Outgoing reply bodies are not stored at all.
Encryption
- Mailbox passwords and API tokens are encrypted at rest with AES-256-GCM; they are never returned by any API and never logged.
- All traffic runs over TLS; sending uses authenticated SMTP/OAuth or provider APIs.
- Replying by email is double-gated: your registered address and a passing SPF/DKIM check — a forged “From” is not enough.
Your rights (GDPR)
- Export: download everything we hold as JSON — Settings → Your data, one click.
- Deletion: delete your account in-app; it removes your data and the Cloudflare rules we created. No support ticket needed.
Subprocessors
Vercel (hosting), Supabase (database), Cloudflare (email routing), Resend (notification delivery), Clerk (authentication), Polar (payments — merchant of record), OpenRouter (AI features; message text is processed transiently for Pro AI features and not used for training by our configuration).
Reporting
Found a vulnerability? Email support@allyourinboxes.com — a human reads it, fast.
All your email. One place.
Connect any inbox. Send from the right address automatically. Free plan forever, paid from $6.99/mo, and it never touches how your mailboxes are set up.
Try it free