Privacy policy
Effective from 2 September 2026 — last updated: 8 September 2026
This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (the «GDPR») and describes how personal data is processed for users of themailamber.app website, the Mailamber account and theMailamber application for Windows. It is written to be read, not merely published: if anything is unclear, write toprivacy@mailamber.app.
1. Data controller
The data controller (the «Controller») is:
- Antonio Maraucci — sole proprietorship
- VAT number: IT09286091211
- Registered address: Via Raffaele Gasparri 16, 81100 Caserta (CE), Italy
- Privacy contact: privacy@mailamber.app
- Support: support@mailamber.app
No data protection officer (DPO) has been appointed, as the conditions of Article 37 GDPR do not apply to the scale and nature of the processing carried out. For any matter concerning personal data, the point of contact isprivacy@mailamber.app.
2. Your emails never reach us
Mailamber is built on a local-first architecture. This is not a marketing slogan but a technical constraint we imposed on ourselves, and it is the most important part of this policy:
- The contents of your emails — messages, subjects, bodies, attachments, contacts — stay exclusively on your device. They are never transmitted to, copied to, analysed or processed on the Controller's servers.
- Your email account credentials (IMAP/SMTP) and access tokens are encrypted locally with Windows DPAPI and never leave your device.
- The application communicates directly with your mail provider's servers (IMAP/SMTP), with no intermediary operated by the Controller.
For this data the Controller is neither controller nor processor: it simply never receives it and cannot access it. It is under your exclusive control, and you can delete it at any time by uninstalling the application or removing its data.
3. Data processed, purposes and legal bases
The Controller's servers (api.mailamber.app, hosted by Hetzner in Germany, European Union) process only the minimum data needed to manage your Mailamber account:
- the email address of your Mailamber account;
- a hash of your password (argon2id algorithm — never the password in clear text);
- your display name and preferred language;
- your subscription status (plan, billing cycle, renewal dates);
- identifiers of the devices linked to your license, in hashed form;
- support tickets you submit voluntarily, and their replies;
- technical audit logs (security events, sign-ins, IP addresses).
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and managing your account, authentication, email verification | Email, password hash, name, language | Performance of a contract — Art. 6(1)(b) |
| Managing licenses and linked devices | Active plan, hashed device identifier | Performance of a contract — Art. 6(1)(b) |
| Subscription management, tax and accounting obligations | Subscription status; billing data processed by Paddle | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Assistance and support | Support tickets and their content | Performance of a contract — Art. 6(1)(b) |
| System security, fraud and abuse prevention | Technical audit logs, IP addresses | Legitimate interest — Art. 6(1)(f) |
| Promotional emails and product news (marketing) | Email, name, language | Consent — Art. 6(1)(a), withdrawable at any time |
Providing the contractual data is necessary to create and use your account: without it, the service cannot be provided. Marketing consent is always optional and refusing it does not limit the service in any way.
4. Payments through Paddle
Subscriptions are sold through Paddle.com Market Ltd («Paddle»), acting asmerchant of record: Paddle sells, collects payment, issues receipts and handles VAT. For payment data (card details, billing address, tax data) Paddle acts as anindependent data controller: the Controller never receives or stores full payment details — only your subscription status. Paddle's processing is described in thePaddle privacy policy.
5. Recipients and processors
Account data is never sold or shared with third parties for commercial purposes. It is processed, on behalf of the Controller or as independent controllers, exclusively by the following parties:
| Party | Role | Activity and place of processing |
|---|---|---|
| Hetzner Online GmbH | Processor (Art. 28 GDPR) | Server and backup hosting — Germany, EU |
| Paddle.com Market Ltd | Independent controller | Payments, invoicing and VAT as merchant of record |
| Brevo | Processor (Art. 28 GDPR) | Delivery of transactional and, with consent, promotional email — EU |
| GitHub, Inc. | Processor (Art. 28 GDPR) | Distribution of application updates — United States, under Standard Contractual Clauses (SCCs) |
| AI model providers (currently OpenRouter, Inc.; OpenAI, L.L.C.; Anthropic, PBC; the list may include other providers) | Processors (Art. 28 GDPR) | Processing solely of texts voluntarily submitted to the AI assistant (see section 10) — United States, under Standard Contractual Clauses (SCCs) |
Data may also be disclosed to public authorities where required by law.
6. Transfers outside the EU
Account data resides on servers within the European Union. The only transfer to a third country concerns the distribution of application updates through GitHub, Inc. (United States): on that occasion GitHub may process technical connection data (such as the IP address of the device downloading the update). The transfer relies on the safeguards of Chapter V of the GDPR, in particular the Standard Contractual Clausesapproved by the European Commission (Art. 46(2)(c) GDPR). The Controller carries out no other transfers outside the EU.
7. Retention periods
| Category | Retention |
|---|---|
| Account data (email, name, language, password hash, plan, devices) | Until you delete your account, which you can do yourself from the account area |
| Support tickets | Until account deletion |
| Technical audit logs | 12 months |
| Encrypted backups | 30 days: deleted data leaves the backups permanently within that period |
| Tax and billing records | Kept by Paddle for the periods required by applicable tax law |
8. Transactional and marketing email
Transactional emails — account verification, password reset, receipts and subscription notices — are necessary to provide the service and are sent on a contractual basis (Art. 6(1)(b) GDPR).
Promotional emails (product news, offers) are sentonly with your explicit consent, collected separately and never a condition for using the service. You can withdraw consent at any time, with a single click: via the unsubscribe link in every email or the toggle in your account area. Withdrawal does not affect the lawfulness of processing carried out beforehand.
In-app promotional suggestions (Free and Plus plans). Inside the application, dismissible suggestions may occasionally appear promoting exclusively the features of higher Mailamber plans. Legal basis: the Provider's legitimate interest in promoting its own services (Art. 6(1)(f) GDPR). To select them the app usesone single piece of data: the plan active on your account (Free/Plus/Premium), already processed to deliver the service. No email content is ever read or analysed for promotional purposes, no additional data is collected or sent to our servers, no profiling takes place, and there is no third-party advertising. Every suggestion can be dismissed; the Premium plan shows none at all.
9. Cookies
The website uses only technical cookies (the session cookies of the account area) and the browser's localStorage for language and theme preferences. No profiling cookies, no tracking, no third-party analytics: this is why the site shows no cookie banner. Full details, including the table of cookies used, are in thecookie policy.
10. Artificial intelligence assistant (optional)
The Plus and Premium plans include an artificial intelligence assistant for writing, revising and summarising emails. Using the assistant is entirely your choice: no AI feature is mandatory, no content is ever processed automatically, and the app remains fully usable without ever invoking it. The local-first architecture described in this policy applies to all core functions (sync, reading, search, organisation): the AI assistant is the one exception, active only when you explicitly invoke it.
What is transmitted and when. Only when you press an assistant command (e.g. «Generate», «Revise», «Summarise»), the text you submit — the description of the email to write, your draft, or the text of the email to summarise — is sent to the Controller's servers and forwarded to one or more external AI model providers to generate the response. Nothing else from your mailbox is transmitted: never your archive, never your attachments, never messages you did not explicitly submit.
Model providers. The Controller uses multiple AI model providers, selected and updated over time for quality and reliability: currently OpenRouter, Inc.(which routes requests to models by various third-party producers), OpenAI, L.L.C. and Anthropic, PBC, and the list may include other providers without changing the guarantees described here. Providers are based or run servers mainly in the United States: transfers rely on Standard Contractual Clauses (SCC) and, where applicable, the EU-U.S. Data Privacy Framework.
Retention and logs. By using the assistant you accept that the texts you submit are read by the models and may be temporarily retained in the AI providers' logs (typically for abuse prevention, under their respective policies). The Controller's servers record metadata only — feature used, token counts, cost, outcome — never the content of requests or responses.
Purpose and legal basis. Processing takes place solely to provide the response you requested (performance of the contract, Art. 6(1)(b) GDPR); voluntarily invoking the feature, after the notice shown in-app on first use, constitutes your informed choice to submit that content.
- AI features are clearly labelled in the app and only run on your explicit action, in line with the transparency obligations of Article 50 of Regulation (EU) 2024/1689 (the «AI Act»);
- AI-generated content is offered to you as a suggestion: you always decide whether to insert, edit or discard it;
- no automated decision-making producing legal or similarly significant effects on you (Art. 22 GDPR);
- the Controller does not use your content to train its own models and favours provider configurations that exclude training on submitted data.
11. Your rights and how to exercise them
Under Articles 15-22 GDPR you have the right to obtain from the Controller access to your personal data, rectification, erasure (the «right to be forgotten»), restriction of processing, data portability in a structured, machine-readable format, as well as to object to processing based on legitimate interest and to withdraw any consent at any time.
You can exercise your rights in two ways:
- self-service, from your account area: data export, profile changes, marketing consent management and permanent account deletion;
- by email, writing toprivacy@mailamber.app: we reply without undue delay and in any event within one month (Art. 12 GDPR).
If you believe the processing infringes the GDPR, you also have the right to lodge a complaint with the Italian supervisory authority, theGarante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome —www.garanteprivacy.it) under Article 77 GDPR, or with the supervisory authority of your Member State of residence, without prejudice to any other administrative or judicial remedy.
12. Changes to this policy
This policy is effective from 2 September 2026. We may update it to reflect changes in the service or in the law: material changes will be communicated by email to registered users with reasonable notice, and every version published on this page will state its effective date.