Legal
Privacy Policy
Last updated: 27 May 2026
This policy explains how MAILHAUS handles personal data during the waitlist-first public launch and open beta. MAILHAUS is currently a web MVP for lead import, campaign drafting, reply management, CRM tasks, and safe provider-gated outreach.
Data we collect
Public visitors may submit an email address to join the early-access waitlist. We may also store the page or source that created the signup, a referrer, timestamp, and basic operational metadata.
Approved beta users may add workspace information, projects, leads, campaign drafts, templates, inbox records, tasks, settings, integration readiness data, and admin support notes.
Imported contact data
MAILHAUS lets users import contact and business lead data such as names, business names, email addresses, phone numbers, websites, addresses, tags, scores, notes, and status fields.
Users are responsible for ensuring they have a lawful and appropriate basis to upload, store, and contact imported leads. Live bulk sending is disabled for the first launch until unsubscribe, suppression, sender-domain, and compliance checks are complete.
AI and provider processing
AI features can generate email copy, subject ideas, enrichment suggestions, website analysis, reply summaries, classifications, draft replies, and template improvements.
When live AI is disabled or keys are missing, MAILHAUS returns safe fallback output. If live AI is enabled later, relevant prompts and workspace context may be sent to the configured AI provider to produce a response.
How we use data
We use data to provide the product, manage waitlist access, operate beta workspaces, improve reliability, support users, protect the service, and prepare safe launch operations.
We do not sell waitlist emails or imported lead data. We do not send live bulk campaigns from the MVP unless the product owner explicitly enables the required provider and safety settings.
Security and retention
The product uses Supabase/Postgres with row-level security patterns for workspace data. Service-role credentials must remain server-side only.
Data may be retained while the waitlist, beta, or customer workspace remains active, unless deletion is requested or retention is required for operational, security, or legal reasons.