Datenschutz · Privacy Policy
How AllSend handles your data. Short, honest, and in plain language.
Data minimization by design
AllSend is built to store as little as possible. We do NOT store IP addresses or user-agent strings in application data. There are no third-party analytics, no ad pixels, and no external CDNs loaded from the app.
What we store
Your throwaway or kept address, incoming and (for kept accounts) outgoing messages, attachments, labels, and a session token issued by our authentication provider. Nothing else.
Where it lives
Data at rest is stored in the European Union (Frankfurt, eu-central-1). Application compute runs on Cloudflare's global edge — no request payloads are persisted in edge logs.
Retention
Throwaway addresses and their contents are deleted 72 hours after the last activity. Trash is permanently emptied after 30 days. Kept addresses persist until you delete them or your account.
Your rights (GDPR)
You can access, export, correct and delete your data at any time from Settings. For any further request under Art. 15–22 GDPR contact abuse@allsend.io.
Operator
AllSend LLC (US) — see Impressum. Under the market-location principle (Art. 3 GDPR), the GDPR applies to us because we serve users in the EU.
Placeholders
[PLACEHOLDER: full DPO contact, if appointed] [PLACEHOLDER: list of subprocessors] [PLACEHOLDER: cookie table — currently: only a first-party session token and language/theme preferences]