Privacy Policy

Information pursuant to Articles 13 and 14 GDPR. Last updated: 5 October 2026.

1. Controller

The controller for personal data processed on this website and in connection with user accounts is Max Tissen, Otto-Dill-Straße 9, 66901 Schönenberg-Kübelberg, Germany, email kontakt@mailthy.com.

No data protection officer has been appointed. The threshold of § 38 BDSG (at least 20 people permanently engaged in automated processing) is not met.

Important distinction: Mailthy processes data in two separate roles. For the website and your user account we are the controller (Part A). For the emails inside the mailbox you connect, we act solely as a processor and your company remains the controller (Part B).

Part A – Website and user account

2. Visiting the website, server log files

When you open the website, our hosting provider automatically processes data transmitted by your browser: IP address, date and time of the request, the address requested, volume of data transferred, status code, referrer, and information about your browser and operating system.

  • The portal is hosted by Vercel Inc., a company based in the USA. Page requests are processed in its data centre in Frankfurt, Germany (region fra1), which is also where the server log files are created.
  • Static files such as scripts, fonts and images are served through Vercel's global network from the location nearest to you. Visitors from Europe are normally served from Europe. Your IP address is processed here as well, because delivery is not technically possible without it.
  • Because Vercel is a US company, access from the USA, for example by its support staff or under US law, cannot be ruled out entirely. The legal safeguards are set out in section 11.
  • Once you are signed in, your browser also connects directly to our database at Supabase in Frankfurt, Germany. Your IP address is processed there for sign-in and security.
  • No IP addresses of visitors or users are passed to n8n, and to OpenAI only when the dictation feature is used (section 9).
Purpose
Delivering the page, operational security, detecting and preventing abuse, troubleshooting
Legal basis
Art. 6(1)(f) GDPR. Legitimate interest in secure, technically sound operation
Retention
Deleted after 30 days at the latest, unless a security incident requires longer retention
Provision
Technically unavoidable. Without this data the page cannot be delivered

3. User account and sign-in

An account is required to use the dashboard. We set it up on behalf of your company; you sign in with company code, username and password. At your first sign-in you choose your own password, which invalidates the starter password. We process your username, an internal account address or your email address, a password stored only as a hash, your name where provided, company membership, role and permissions, language preference, account creation and sign-in timestamps, and the days on which you used Mailthy.

Purpose
Providing access, assigning you to the correct company, managing permissions, preventing unauthorised access; the days of use for supporting our customers (is Mailthy actually being used, does anyone need help?)
Legal basis
Art. 6(1)(b) GDPR. Performance of the contract and pre-contractual steps; for the days of use Art. 6(1)(f) GDPR, legitimate interest in supporting our customers
Retention
For the life of the account. Deleted within 30 days of termination unless statutory retention obligations apply. Days of use: 12 months
Provision
Required. Without this data no account can be provided

4. Concluding the data processing agreement

When the owner of a customer company concludes the data processing agreement in Mailthy, we store the name, position and company address they enter, together with the time, IP address and browser identifier of the declaration, the version of the agreement and a checksum of its text.

Purpose
Proof of who concluded the agreement for which company and when
Legal basis
Art. 6(1)(c) GDPR in conjunction with Art. 5(2) and Art. 28(9) GDPR (accountability) and Art. 6(1)(b) GDPR
Retention
For the term of the contract and three years thereafter (standard limitation period)

5. Storage on your device

Mailthy uses no advertising, analytics or tracking cookies. There is no audience measurement, no embedded third-party content, and no data is passed to advertising networks. This is why you see no consent banner.

We store only what is strictly necessary to provide the service you explicitly requested (§ 25(2) no. 2 TDDDG):

NameTypePurposeDuration
Sign-in token (Supabase session)Browser local storageKeeps you signed in without re-entering your password on every pageUntil sign-out or session expiry
smc_localeCookieRemembers your chosen interface language1 year
mailthy.firmenkuerzelBrowser local storageRemembers the company code last used, so it need not be typed again at sign-inUntil browser data is cleared
Sidebar stateCookieRemembers whether the sidebar was expanded or collapsed7 days
mailthy.aktivitaet_gemeldetBrowser local storageRemembers when Mailthy last reported that you are using it, so this happens at most every 10 minutesUntil browser data is cleared
smc_chunk_reloadBrowser session storagePrevents the page from reloading in a loop after an updateUntil the tab is closed

Should analytics or marketing tools ever be introduced, consent will be obtained beforehand and this policy updated accordingly.

6. Contacting us

If you email us, we process your details in order to handle your enquiry. Our mailbox is hosted by Microsoft 365 (section 10). The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR based on our legitimate interest in responding. Data is deleted once the enquiry has been dealt with and no retention obligations apply.

You can book a call on the “Book a call” page. For this we process your name, company, email address, optionally your phone number and message, the chosen time and, if you come from the pricing page, the selection made there. The details are stored in our database at Supabase in Frankfurt am Main. We are notified of the booking by email and you receive a confirmation at the address you provided. Both emails are sent via Resend (section 10).

Purpose
Arranging and holding the call
Legal basis
Art. 6(1)(b) GDPR (steps prior to entering into a contract at your request)
Retention
At most six months after the call, then the details are deleted automatically. If a contract is concluded, the periods in section 3 apply

7. Business outreach by email

We contact selected companies by email to introduce Mailthy. For this we process the company name, the general business email address (such as info@ or sales@) and, where applicable, the name of a contact person, as published on the company's website. The source is therefore publicly accessible websites. We record when we wrote and whether the message could be delivered. If it contains a demo link, we can see whether the link was opened (section 8).

Purpose
Introducing our offering to businesses
Legal basis
Art. 6(1)(f) GDPR. Legitimate interest in direct marketing to businesses (Recital 47 GDPR). We only contact businesses in countries where this is permitted
Retention
Until you object, otherwise no longer than 24 months after the last contact
Objection
At any time and without giving reasons; a short reply to our message is enough. We will then not write to you again and keep only a suppression note so that it stays that way (Art. 21(2) and (3) GDPR)

8. Login-free demo access

We provide prospective customers with demo environments that work without a password: industry demos and demos tailored to individual companies. A session is established server-side for a dedicated demo account. These environments contain fictitious sample data only, never real customer data.

Each time a demo link is opened we store the time and the browser identifier (user agent), but no IP address. If we sent the link to a particular company, this tells us whether the demo was opened there. Automated link checks by mail servers are filtered out.

Purpose
Detecting abuse and seeing whether our offering is of interest
Legal basis
Art. 6(1)(f) GDPR
Retention
12 months
Objection
At any time, as described in section 7

Part B – Processing on behalf of our customers

The core purpose of Mailthy is the automatic analysis of our customers' business email. This processing is carried out on documented instructions on behalf of the customer company. Under the GDPR that customer company is the controller, not Mailthy.

If you have written to a company that uses Mailthy and want to know what happens to your data, please contact that company. It is your point of contact for access, rectification and erasure and informs you under Articles 13 and 14 GDPR. We forward any such request to them without delay.

Data processed on behalf: sender and recipient details, subject, body and attachments of incoming email, structured information derived from it such as contact person, company, phone number, project location, materials and dates, along with the resulting classification and draft reply.

The basis is a data processing agreement under Art. 28 GDPR. Customers conclude it at their first sign-in to Mailthy and can find it there at any time. We are happy to send the template to prospective customers on request.

Connecting a mailbox

The customer company usually connects its mailbox itself on the “Mailboxes” page. With Google and Microsoft it signs in directly with the provider and grants Mailthy access there. Mailthy never sees the password; only an access token is stored. With other providers the customer enters the server, username and password of the mailbox.

  • Access tokens and passwords are stored encrypted in the database vault (Supabase Vault, Frankfurt, Germany) or, for connections set up via the automation platform, in its encrypted credential store. They can only be read server-side, are never returned to the browser and are not viewed by us.
  • Mailthy uses this access to fetch new messages from the inbox, to keep the read status in sync and to send replies that a person has approved or for which the customer company has switched on automatic sending. Messages are never moved or deleted. Fetching alone does not mark anything as read; the read status only changes when someone opens the message in Mailthy or explicitly marks it as read or unread.
  • The customer company can disconnect the mailbox at any time on the “Mailboxes” page. The token or password is deleted immediately; for Google, access is also revoked with the provider. Access can also be withdrawn at any time in the account settings at the provider.

For data from Google accounts: Mailthy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use this data solely to provide the user-facing features of Mailthy to the customer company: classification, analysis and draft replies. The data is not used for advertising, not sold and not used to train general-purpose AI models, neither by us nor by the model provider we use. People read the data only with the customer company's explicit consent (for example for a support request), where necessary for security purposes, or to comply with applicable law.

9. Use of artificial intelligence

We use OpenAI language models, accessed through OpenAI's application programming interface (API), to classify incoming messages and to draft replies. The contracting party is OpenAI Ireland Ltd., Dublin; the processing itself takes place in the USA. For each email we transmit the sender, subject, body and the extracted content of attachments, together with the customer company's settings such as categories and responsibilities. When the dictation feature in the dashboard is used, speech is transmitted in encrypted form directly from the browser to OpenAI while speaking and converted into text there. For technical reasons OpenAI receives the IP address of the device used. To get names right, we also send known names from the customer company's cases (projects, companies, contact persons, responsible staff) as a vocabulary aid. We do not store the recording itself. For a captured note we also transmit matching cases of the customer company (emails, extracted attachments, material lists) so that the language model can compile a callback note from them. The transfer takes place on behalf of and on the instructions of the customer company under the data processing agreement; the safeguards for the transfer to the USA are described in section 11.

  • Content is not used to train the models. This is contractually agreed with the provider.
  • The model provider retains transmitted content for up to 30 days for abuse detection and deletes it afterwards. It is not stored beyond that.
  • There is no automated decision producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR. The classification is a suggestion and the reply is a draft. A reply is sent only once a person approves it, or automatically where the customer company has expressly switched this on. Even then the reply is business correspondence and not a decision about the data subject.
  • Results can be wrong. They are a working aid and do not replace review by a person.

Where reply texts are generated wholly or partly with the help of artificial intelligence, we make our customers aware of the transparency obligations under Article 50 of Regulation (EU) 2024/1689 (AI Act) and provide the settings needed to meet them.

Part C – Provisions applying to both roles

10. Recipients and service providers

We disclose personal data only where necessary to run the service. The providers listed below are bound by a data processing agreement unless the Safeguard column says otherwise:

ProviderPurposeRegistered office / server locationSafeguard
Vercel Inc.Hosting of the portal (web application), page delivery, server log files, fetching connected mailboxes and sending repliesRequests processed in Frankfurt, Germany (fra1); static files served from the nearest location of Vercel's global network; company in the USADPA with standard contractual clauses, EU-US Data Privacy Framework
Supabase Inc.Database, authentication, file storageData centre Frankfurt, Germany (eu-central-1); company in the USADPA with standard contractual clauses
n8n GmbHRunning the automation (analysing incoming messages, passing content to the language model, sending replies)Company in Germany; servers in the EU (Microsoft Azure)DPA
OpenAI Ireland Ltd. / OpenAI, L.L.C.AI analysis of email content, speech recognition for dictationContracting party in Ireland; processing in the USADPA with standard contractual clauses, no training on customer data
Google Cloud (Google Ireland Ltd.)Only with a connected Gmail mailbox: notification about new messages (mailbox address only, no content)Company in Ireland/USADPA with standard contractual clauses, EU-US Data Privacy Framework
Microsoft Ireland Operations Ltd. (Microsoft 365)Our own mailbox: enquiries, communication with customers and prospects, business outreach (section 7)Stored in data centres in the EU; company in Ireland, group in the USADPA with standard contractual clauses, EU-US Data Privacy Framework
Resend, Inc.Sending internal alerts about disruptions to us, which may contain company names and mailbox addresses; notifying us of booked calls and confirming them to the person bookingCompany in the USADPA with standard contractual clauses
Google Ireland Ltd. (Gmail)Receiving the internal alerts in our mailboxCompany in Ireland/USAArt. 6(1)(f) GDPR, EU-US Data Privacy Framework
The customer's email provider (e.g. Google Gmail, Microsoft 365 or an IMAP/SMTP provider)Fetching incoming messages and sending replies through the mailbox the customer connectsDepends on the customer's providerAccess authorisation granted by the customer; the provider is a service provider of the customer, not of ours

Beyond this we disclose data only where legally required or where necessary to enforce our rights.

11. Transfers to third countries

To make clear what happens where:

  • Processed in the EU: the database and file storage (Supabase, Frankfurt, Germany), page requests to the portal including server log files (Vercel, Frankfurt, Germany) and the automation (n8n, servers in the EU).
  • Transferred to the USA: the content sent to OpenAI for AI analysis (section 9), voice recordings when the dictation feature is used, and our internal alerts (Resend, Gmail).
  • In addition, Vercel and Supabase are companies based in the USA, Microsoft 365 belongs to a US group, and n8n runs its servers with Microsoft. Even though the data is stored in the EU, access from the USA, for example for support purposes or under US law, cannot be ruled out entirely.

These transfers rely on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, where the provider concerned is certified under it, and additionally on the Commission's standard contractual clauses (Implementing Decision 2021/914). We review our providers' certification regularly and maintain the standard contractual clauses as a second, independent safeguard.

12. Retention periods

DataPeriod
Server log files30 days maximum
Account and user dataFor the term of the contract, deleted within 30 days thereafter
Email data processed on behalf of a customerAs instructed by the customer, at the latest deleted or returned when the contract ends
Held by the model provider for abuse detectionUp to 30 days
Proof of concluding the DPA (name, position, time, IP address, browser identifier)Term of the contract and three years thereafter
Days of use in the dashboard12 months
Demo link openings12 months
Contact data from business outreachUntil objection, otherwise no longer than 24 months after the last contact; after an objection only a suppression note
Security-related audit recordsUp to 12 months
Records with tax or commercial law relevanceStatutory periods, generally 6 or 10 years

13. Security

All transmission is encrypted via TLS. Access to data is separated per company by row-level security rules in the database, user account passwords are stored only as hashes. Credentials for connected mailboxes (access tokens and passwords) are stored encrypted in the database vault and can only be read server-side, as are all other access keys to third-party systems. Technical and organisational measures are reviewed regularly.

14. Your rights

You have the following rights against us where we act as controller. If your request concerns data we process on behalf of a customer, please contact that customer.

  • Access to the personal data we hold about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a common, machine-readable format (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

An informal message to kontakt@mailthy.com is enough to exercise any of these.

15. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz. You may equally contact the authority where you live or work.

16. Notes for users in Switzerland

For individuals in Switzerland the revised Federal Act on Data Protection (revDSG) applies in addition. Data is disclosed to the following countries: Germany and other EU member states, and the United States of America. Disclosure to the United States relies on the Swiss-US Data Privacy Framework and, additionally, on standard contractual clauses. Your point of contact is the controller named above.

17. Notes for residents of California

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We use no third-party advertising trackers. Where the CCPA/CPRA applies to you, you may request access to, correction of, or deletion of your personal information using the contact details above, and we will not discriminate against you for exercising those rights.

18. Changes

We update this policy when our processing changes or the law requires it. The version published on this page is the one that applies. We notify customers by email of material changes.