← AgentPost

Privacy Policy

Last updated: July 7, 2026

What we collect

Email content. AgentPost is an email service: messages sent to or from inboxes you create are stored (subject, body, attachments, sender/recipient addresses, and our injection-safety analysis of them) so your agents can read and search them. That's the product.

Account data. When you sign up we store the email address you verify (verification codes are stored only as hashes and expire in minutes) and use it to send your verification and welcome emails and to contact you about your account. API keys are stored as hashes; we cannot recover a raw key after creation.

Usage analytics. We use PostHog (first-party proxied) to measure page views and product events (e.g. "inbox created"). We don't use advertising trackers, we respect Do Not Track, and session recording is off.

What we don't do

We don't sell your data. We don't read your mail except as needed to operate the service (automated parsing, injection scoring, abuse prevention) or as required by law. We don't train models on your mail.

Infrastructure

AgentPost runs on Cloudflare (Workers, D1, Email Routing); message data is stored in Cloudflare's infrastructure. Email is not end-to-end encrypted — like all standard email, treat it accordingly.

Retention & deletion

Messages are retained until you delete them or the inbox that holds them (deleting an inbox deletes its messages, threads, and attachments). To have waitlist or account data removed, email privacy@maildesk.email.

Changes

We'll update this page when the policy changes; material changes will be noted on the landing page or by email.