1. Introduction
This Privacy Policy explains what information MailCutover ("the Service") collects, how we use it, and the choices you have — including in relation to the highly sensitive server and mailbox credentials the Service necessarily handles to do its job. It should be read alongside our Terms of Service.
2. Information We Collect
We collect the following categories of information:
- Account information — your name and email address, managed through our authentication provider, Clerk;
- Workspace and organization membership — which personal or team workspace your projects belong to, and your role within it;
- Migration credentials — the source and destination hostnames, usernames, and passwords you submit to configure a migration project, and the migration password used to authenticate the destination mailbox;
- Usage and migration logs — account status, message counts, transfer speed, error logs, and imapsync output generated while a migration runs;
- Billing information — your plan and subscription status. Payment card details are collected and processed entirely by Stripe via Clerk Billing; we never see or store your full card number.
3. How We Use It
We use this information to operate the Service: to authenticate you, run the migrations you configure, show you progress and reports, enforce plan limits, send transactional emails (such as a notification when a migration finishes), and provide customer support. We do not use your migration credentials or mail content for any purpose other than performing the migration you requested.
4. Subprocessors
We share the minimum data necessary with a small number of vendors who help us operate the Service:
- Clerk — authentication, organization membership, and billing subscription state;
- Stripe (via Clerk's billing integration) — payment processing; we never receive your card number;
- Resend — delivery of transactional emails, such as migration-complete notifications.
We do not sell your data, or your customers' data, to anyone.
5. How Credentials Are Protected
Because migrating mail requires it, the Service necessarily stores highly sensitive credentials on your behalf — including root SSH passwords for destination servers and cPanel/Plesk account passwords — for as long as a migration project exists. These are encrypted at rest using AES-256-GCM before being written to our PostgreSQL database, and are only ever decrypted in memory, transiently, to perform the specific operation (an SSH command, an imapsync run) that needs them. API keys are stored differently: only a one-way SHA-256 hash of the key is kept, so a key itself cannot be recovered from our database even by us.
We strongly recommend rotating any credential submitted to the Service once your migration is complete.
6. Retention & Deletion
Migration credentials and logs are retained for as long as the associated project exists in your workspace. Deleting a project deletes its accounts, logs, and credentials from our database. Deleting your account removes your profile information subject to any residual billing or legal record-keeping obligations.
7. Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can delete individual projects and accounts directly from the dashboard at any time; for a full account deletion or data export request, contact us using the details below.
8. No Sale of Data
We do not sell, rent, or trade your personal information or your migration data to third parties for their own marketing purposes.
9. International Transfers
Our infrastructure and subprocessors may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.
10. Children's Privacy
The Service is intended for business and technical users and is not directed at children. We do not knowingly collect personal information from anyone under 18.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new "Last updated" date, and for material changes we will make reasonable efforts to notify you.
12. Contact
Questions about this Privacy Policy, or requests relating to your data, can be sent to hello@mailcutover.io.