# Security and privacy

## Privacy statement

> Your mail lives on your server. We never host your mailboxes or keep copies of your messages. So you never have to fight your hosting company over email settings, our delivery network carries your mail on its way in and out. Like every email delivery service, it handles each message briefly while passing it along, and never saves, logs or shares the contents. If your server is offline, the sender simply retries later, so nothing waits with us unless you turn on the encrypted offline inbox. Your server keeps an eye on the settings we manage for your domain and alerts you if anything changes that it didn't make. We keep delivery counts, not your contacts, and we'd only ever disclose anything if legally required. Want us fully out of the path? Switch to direct mode any time.

## How it's built

- **Mail stays on your server.** Mailboxes, stored messages and signing keys live on the server you own.
- **Stored messages are encrypted at rest** on your server.
- **Inbound mail is virus-scanned** on your server before anything reads it.
- **The API is private.** Your apps call it on your own server; it is never exposed to the public internet.
- **Tokens are scoped and stored as hashes.** Each token carries only the scopes it needs, and we never store the secret itself.
- **Errors never repeat an email address**, so they are safe to paste into a bug report or an agent transcript.
- **Sending fails closed.** If the suppression list or sending budget can't be checked, the send is refused, not attempted.

## For AI agents reading mail

Email content is untrusted input for an AI agent. eMailPlane does not claim to be injection-proof. Planned protections (coming soon):

- every sender labelled by authentication (DKIM and DMARC) before an agent reads the message;
- untrusted content wrapped and hidden text removed, with HTML off for agents by default;
- reply-only sending by default, loop protection, and a check for secrets in outgoing mail;
- AI-sent mail disclosed and signed by default, so your recipients know.

Laws such as the EU AI Act place disclosure duties on the businesses that deploy AI. Disclosure will be on by default; meeting those duties remains the deployer's responsibility.

## Who else touches what

| Service | What for | Your mail? |
|---|---|---|
| Cloudflare | DNS, and serving this website | Never. Mail traffic is not proxied through Cloudflare. |
| Stripe | Billing | Never. Only billing details. |

## Report a vulnerability

Email the address in our [security.txt](https://emailplane.com/.well-known/security.txt). Please include steps to reproduce, and give us a reasonable time to fix the issue before you share it.

---

Source: https://emailplane.com/security/
