Skip to main content

Privacy Policy

Last updated: July 15, 2026

Overview

2SMTP ("we", "our", "us") respects your privacy. This policy explains what data we collect, how we use it, and your rights regarding your information.

Information We Collect

Account Information

  • Email address (required for account creation)
  • Password (hashed, never stored in plain text)

SMTP Credentials

  • SMTP host, port, username, and password
  • Sender email and name
  • Encrypted at rest using industry-standard encryption

Usage Data

  • Number of emails sent per API key
  • Credits remaining
  • API request timestamps (for rate limiting)

Payment Information

  • Processed by Stripe - we do not store credit card numbers
  • Stripe customer ID for billing purposes

Email Content

We do NOT store email content. Email data (recipients, subject, body) is processed in memory and immediately forwarded to your SMTP server. We do not log, store, or read the content of your emails.

How We Use Your Information

  • To provide and maintain the email relay service
  • To authenticate API requests
  • To track credit usage and enforce rate limits
  • To process payments
  • To communicate important service updates
  • To prevent abuse and maintain security

Data Sharing

We do not sell your personal information. We only share data with:

  • Stripe: For payment processing
  • Your SMTP provider: To send emails (using credentials you provide)
  • Google: For website analytics, and only if you accept analytics cookies
  • Legal authorities: If required by law

Data Security

  • SMTP credentials are encrypted at rest
  • All communications use HTTPS/TLS
  • Passwords are hashed using Argon2
  • Regular security reviews and updates

Data Retention

  • Account data: Retained until account deletion
  • Usage statistics: Retained for billing and rate limiting purposes
  • Email content: NOT retained (processed in memory only)

Your Rights

You have the right to:

  • Access your account data
  • Update or correct your information
  • Delete your account and associated data
  • Export your data (API keys and usage stats)
  • Revoke API keys at any time

Cookies and Analytics

We use browser localStorage for session management and authentication. It stays in your browser and you can clear it at any time.

We also use Google Tag Manager to load Google's analytics and advertising tags. Under Google Consent Mode, these are denied by default β€” no analytics or advertising cookies are set unless you accept them through our cookie banner. You can decline, or change your choice at any time from the banner, and we will not set those cookies.

Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use after changes constitutes acceptance.

Questions about privacy? Contact us for more information.

"For God so loved the world, that He gave His only begotten Son, that all who believe in Him should not perish but have everlasting life." β€” John 3:16