Privacy Policy
Effective Date — September 3, 2026
Razix ("we," "our," or "us") provides a unified multi-domain email management platform ("Service"). This Privacy Policy details how we collect, process, store, and protect your information when you use our web application, APIs, and dashboard.
1. Information We Collect
- Account Information: Name, email address, authentication credentials, and billing details processed securely via our Merchant of Record, Polar.
- Email & Content Data: Inbound and outbound email headers (sender, recipient, timestamp), subject lines, message bodies, and attachments transmitted through your configured domains and mailboxes.
- Usage & Metering Telemetry: Inbound and outbound email counts, active mailbox counts, domain configurations, storage consumption, and download/egress bandwidth utilized to compute plan usage and metered overages.
- Domain & DNS Records: Domain names, SPF, DKIM, MX, and DMARC verification records configured through your dashboard.
2. How We Process Email Data
- Outbound Transmission: Outbound emails created within the platform are routed directly through industry-standard email service infrastructure to recipient mail servers.
- Inbound Ingestion & Ephemeral Staging: Inbound emails are received via our mail routing infrastructure and staged temporarily in encrypted object storage buckets. Automated event triggers process message headers, bodies, and metadata directly into our database. Once successfully parsed and stored, the raw inbound message payload is immediately and permanently purged from temporary staging.
- Attachment Storage: File attachments are stored in persistent, access-controlled encrypted object storage linked to your account.
- No Data Mining or Model Training: We do not read, monetize, sell, or analyze your email contents for advertising purposes or AI/ML model training.
3. Sub-Processors & Third-Party Infrastructure
We partner with enterprise-grade infrastructure providers to host and deliver our Service:
| Provider | Purpose | Data Handled |
|---|---|---|
| Amazon Web Services (AWS) | Email delivery (SES), event messaging (SNS), attachment storage & staging (S3) | Email payloads, attachments, sender/recipient metadata |
| Supabase | Primary database, edge compute parsing, authentication | Account records, parsed email bodies, metadata, tenant logs |
| Polar | Merchant of Record, subscription billing & metered invoicing | Billing details, payment tokens, metered usage calculations |
| Vercel | Web dashboard hosting & edge delivery | IP addresses, browser telemetry, session state |
4. Security & Tenant Isolation
- Encryption in Transit: All communications across clients, dashboard sessions, database connections, and API endpoints are strictly enforced over Transport Layer Security (TLS 1.2+ / HTTPS).
- Encryption at Rest: Attachments, database storage volumes, and staging files are encrypted at rest using industry-standard AES-256 encryption.
- Row-Level Security (RLS): We enforce PostgreSQL Row-Level Security policies at the database level to ensure strict multi-tenant isolation, guaranteeing that accounts can never query or access other users' mailboxes or messages.
5. Data Retention & Deletion
- Active Records: Parsed messages, contact metadata, and attachments are retained as long as your account remains active and within quota limits, or until manually deleted from your dashboard.
- Account Termination: Upon account cancellation or deletion, all stored emails, domain configurations, and associated attachments are queued for permanent deletion within 30 days.
6. Contact & Data Rights
Under applicable data protection frameworks (including GDPR and CCPA), you have the right to access, rectify, port, or request deletion of your personal data.
For data requests, privacy inquiries, or legal concerns, please contact us at legal@razix.com.