Last updated: August 3, 2026
Email content. AgentPost is an email service: messages sent to or from inboxes you create are stored (subject, body, attachments, sender/recipient addresses, and our injection-safety analysis of them) so your agents can read and search them. That's the product.
Account data. When you sign up we store the email address you verify (verification codes are stored only as hashes and expire in minutes) and use it to send your verification and welcome emails and to contact you about your account. API keys are stored as hashes; we cannot recover a raw key after creation.
Usage analytics. We use Umami, which we host ourselves on our own infrastructure — your analytics data is never sent to a third-party analytics vendor. It measures page views and product events (e.g. "inbox created"). We don't use advertising trackers.
Session recording. We record how people use the product — clicks, scrolling and page navigation — so we can find and fix the parts that are confusing. Because AgentPost displays email content, recordings are fully masked: all text is replaced before the recording leaves your browser, so message subjects, bodies, addresses and anything you type are never captured. What we see is layout and interaction, not content. Recordings are stored on our own infrastructure and are automatically deleted after 30 days. We respect Do Not Track — switch it on in your browser and we record nothing at all.
We don't sell your data. We don't read your mail except as needed to operate the service (automated parsing, injection scoring, abuse prevention) or as required by law. We don't train models on your mail.
AgentPost runs on Cloudflare (Workers, D1, Email Routing); message data is stored in Cloudflare's infrastructure. Email is not end-to-end encrypted — like all standard email, treat it accordingly.
Messages are retained until you delete them or the inbox that holds them (deleting an inbox deletes its messages, threads, and attachments). To have waitlist or account data removed, email privacy@maildesk.email.
We'll update this page when the policy changes; material changes will be noted on the landing page or by email.