This page is a good-faith starting draft, written to reflect MailCutover's actual technical and data practices as accurately as possible. It has not been reviewed by a licensed attorney and should not be relied upon as legal advice or a binding agreement until a qualified lawyer has reviewed and approved it for your jurisdiction and business.

1. Introduction

This Privacy Policy explains what information MailCutover ("the Service") collects, how we use it, and the choices you have — including in relation to the highly sensitive server and mailbox credentials the Service necessarily handles to do its job. It should be read alongside our Terms of Service.

2. Information We Collect

We collect the following categories of information:

3. How We Use It

We use this information to operate the Service: to authenticate you, run the migrations you configure, show you progress and reports, enforce plan limits, send transactional emails (such as a notification when a migration finishes), and provide customer support. We do not use your migration credentials or mail content for any purpose other than performing the migration you requested.

4. Subprocessors

We share the minimum data necessary with a small number of vendors who help us operate the Service:

We do not sell your data, or your customers' data, to anyone.

5. How Credentials Are Protected

Because migrating mail requires it, the Service necessarily stores highly sensitive credentials on your behalf — including root SSH passwords for destination servers and cPanel/Plesk account passwords — for as long as a migration project exists. These are encrypted at rest using AES-256-GCM before being written to our PostgreSQL database, and are only ever decrypted in memory, transiently, to perform the specific operation (an SSH command, an imapsync run) that needs them. API keys are stored differently: only a one-way SHA-256 hash of the key is kept, so a key itself cannot be recovered from our database even by us.

We strongly recommend rotating any credential submitted to the Service once your migration is complete.

6. Retention & Deletion

Migration credentials and logs are retained for as long as the associated project exists in your workspace. Deleting a project deletes its accounts, logs, and credentials from our database. Deleting your account removes your profile information subject to any residual billing or legal record-keeping obligations.

7. Your Rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can delete individual projects and accounts directly from the dashboard at any time; for a full account deletion or data export request, contact us using the details below.

8. No Sale of Data

We do not sell, rent, or trade your personal information or your migration data to third parties for their own marketing purposes.

9. International Transfers

Our infrastructure and subprocessors may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.

10. Children's Privacy

The Service is intended for business and technical users and is not directed at children. We do not knowingly collect personal information from anyone under 18.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date, and for material changes we will make reasonable efforts to notify you.

12. Contact

Questions about this Privacy Policy, or requests relating to your data, can be sent to hello@mailcutover.io.