This documentation copy is provided for convenience. The controlling Privacy Policy published on the Mermail website governs if there is any difference.
Company: Nudgen LLC
Contact: [email protected]
1. Scope
This Privacy Policy explains how Nudgen LLC (“Mermail,” “we,” “our,” or “us”) collects, uses, shares, and protects information when you use the Mermail website, console, APIs, agent inboxes, and related services (the “Service”). Mermail provides privacy-first email inboxes and APIs for AI agents and software teams. This policy applies to information collected from account holders, workspace members, developers, visitors, and message participants whose information is processed through the Service.2. Information we collect
We may collect the following categories of information:- Account and profile information, such as name, email address, avatar, authentication identifiers, organization details, and workspace preferences.
- Workspace and team information, such as workspace names, roles, invitations, membership settings, billing administrators, and usage limits.
- Mailbox and message information, such as mailbox addresses, aliases, folders, labels, threads, message metadata, message bodies, attachments, drafts, outbound messages, delivery events, and suppression status.
- Developer and integration information, such as API keys, OAuth client metadata, webhook URLs, custom domain settings, DNS configuration status, connected provider identifiers, and agent registration details.
- AI workflow information, such as prompts, instructions, draft responses, tool calls, triage rules, automation settings, and related context that you choose to process through the Service.
- Billing and subscription information, such as plan tier, subscription status, customer IDs, order references, payment-provider metadata, invoices, taxes, credits, and usage counters.
- Usage, device, and analytics information, such as browser and device details, IP-derived approximate location, referral data, product interactions, logs, diagnostics, rate-limit events, and security events.
- Support and communications information, such as messages you send to us, feedback, support requests, demo requests, and operational troubleshooting records.
3. Sources of information
We collect information directly from you, automatically, and from service providers.- Directly from you when you create an account, configure a workspace, create inboxes, connect integrations, send mail, or contact us.
- From your organization or teammates when they invite you to a workspace or administer a shared account.
- Automatically from your use of the Service, including application events, API activity, mailbox routing events, and security telemetry.
- From service providers that support the Service, such as authentication, hosting, analytics, billing, email routing, and AI infrastructure providers.
- From inbound and outbound email systems when messages are sent to, received by, or routed through Mermail-managed inboxes.
4. How we use information
We use information to operate, secure, and improve the Service, including to:- Authenticate users and manage accounts, workspaces, roles, and permissions.
- Create, route, receive, store, search, display, draft, send, and organize email for authorized users and agents.
- Operate APIs, webhooks, custom domains, connected inboxes, automation rules, and developer tooling.
- Provide AI-assisted drafting, triage, summarization, and agent workflow features at your direction.
- Enforce usage limits, rate limits, anti-abuse safeguards, deliverability protections, and security controls.
- Process subscriptions, billing changes, customer portal requests, invoices, taxes, and plan entitlements.
- Respond to support requests, debug incidents, monitor reliability, and improve product quality.
- Detect, investigate, and prevent fraud, abuse, unauthorized access, spam, malware, phishing, and policy violations.
- Comply with legal obligations and enforce our agreements and policies.
5. Customer content and mailbox data
Customers decide what mailbox data, message content, attachments, prompts, instructions, and related materials they process through Mermail. For Customer Content, Mermail generally acts as a service provider or processor and processes that information on the customer’s behalf to provide the Service. Mermail also acts as an independent controller for limited business information we need to operate our company, such as account administration, billing, security, support, legal compliance, fraud prevention, website analytics, and product communications. Standard hosted workspaces retain message content, attachments, drafts, agent conversations, and related mailbox data so authorized users and agents can use features such as message history, search, attachments, drafting, retrieval, and automation. Full message bodies and attachments use Harbor-backed blob storage instead of plain database text. Mermail is designed around data minimization and privacy-first access controls. We use encryption in transit and encryption-at-rest patterns for sensitive data. Access to Customer Content is limited to authorized workflows, users, agents, providers, and service operations needed to provide, secure, and support the Service. You are responsible for ensuring that you have the rights, notices, consents, and lawful bases required to process mailbox data and message participant information through the Service.6. Legal bases for processing
Where GDPR or similar laws apply and Mermail acts as a controller, we rely on the legal bases that fit the processing activity. We process account, workspace, billing, and support information to perform our contract with you, provide the Service, and administer customer relationships. We process security, abuse-prevention, reliability, debugging, and product-improvement information based on our legitimate interests in operating a secure and reliable service. We process information when necessary to comply with legal obligations, enforce agreements, resolve disputes, and respond to lawful requests. Where required, we rely on consent for marketing communications, non-essential cookies or analytics, and similar activities, and you may withdraw consent where applicable. When we process Customer Content as a processor or service provider, our customer is responsible for identifying and documenting the lawful basis or other legal authority for that processing.7. AI features
Mermail may provide AI-assisted features for agent workflows, drafting, classification, summarization, task triage, and response generation. When you use AI features, we may process prompts, mailbox context, message content, instructions, and generated outputs as needed to provide the requested feature. You are responsible for reviewing AI-generated output before sending, publishing, or relying on it. Mermail does not use Customer Content to train shared AI models unless the customer expressly agrees in writing. AI infrastructure providers may process Customer Content to provide requested features, subject to their applicable contractual restrictions and the configuration available for the Service.8. Cookies, analytics, and similar technologies
We may use cookies, browser storage, logs, analytics tools, and similar technologies to operate the website and console, understand product usage, measure reliability, secure accounts, and improve the Service. Some technologies are strictly necessary for authentication, security, routing, preferences, fraud prevention, and product operation. Where applicable law requires consent or opt-out controls for non-essential analytics, advertising, or similar technologies, we will use appropriate controls or limit those technologies as required. Where possible, we limit analytics on authenticated product surfaces and avoid collecting raw message content for marketing analytics. Browser settings, privacy controls, and any consent tools we provide may affect how cookies and analytics technologies operate.9. How we share information
We may share information in the following circumstances:- With service providers that help us run the Service, such as hosting, storage, authentication, analytics, billing, support, email routing, deliverability, security, and AI infrastructure providers.
- With members of your workspace based on their role, permissions, and the features available within the product.
- With administrators and personnel who need access for operations, support, fraud prevention, compliance, or security.
- When required by law, legal process, court order, subpoena, or a valid governmental request.
- In connection with a merger, financing, acquisition, restructuring, or sale of assets.
- To protect rights, safety, property, the Service, our users, message recipients, or the public.