Privacy policy
Last updated 8 October 2026
MailRules is made by TurtleByte, the trade name of Tilak Kumar G, a sole proprietor trading as TurtleByte, Bengaluru, Karnataka, India ("we", "us"). This policy explains what we collect when you use the MailRules website, the open-source software and the hosted cloud service, why we collect it, and the choices you have. It is written to meet India's Digital Personal Data Protection Act, 2023 and, for visitors in the EU and UK, the GDPR.
1. The short version
- If you self-host MailRules, it runs on your server and sends us nothing.
- In the cloud service, we read email only to decide where it goes. We never sell your data or use it for advertising.
- Full email bodies are never stored or logged. When a model is needed, it gets the sender, subject and a trimmed plain-text excerpt.
- You can export or delete your data at any time.
2. Self-hosted MailRules
The open-source version runs entirely on infrastructure you control. It does not send us usage data, email content or credentials. If you configure an AI model provider (for example OpenRouter, Anthropic or an OpenAI-compatible service), MailRules sends that provider the data described in section 4, under your own account and that provider's terms.
3. The website and waitlist
- Waitlist: your email address, used only to tell you when the cloud service opens. With it we keep how you found us: the campaign tags in the link you followed (for example "github" or "producthunt") and the website that sent you, if any. We use these only to learn which channels bring people. The waitlist runs on Keila, hosted by us. We send nothing else, and you can leave at any time.
- Your browser: to remember how you found us until you join, the site keeps those campaign tags and the sending website in your browser's session storage. It is not a cookie, nothing else is stored, and it is deleted when you close the tab.
- Server logs: IP address, browser type and pages requested, kept for up to 30 days for security and debugging.
- Analytics: Umami, which we host ourselves. It uses no cookies, does not store your IP address, and counts visits, button clicks and whether the pricing section was seen, in aggregate. For a sample of visits, Umami also records how the page is used (mouse movement, clicks, scrolling and moving between pages) so we can see where people get stuck, and turns clicks into heatmaps. Anything typed into a form is masked in your browser before it is sent. Recordings are kept for 30 days. We use no advertising trackers and no third-party analytics.
- Errors and performance: the website records no errors or timings. When the cloud service launches, GlitchTip and SigNoz, both hosted by us, will record its technical errors and timings so we can fix problems. We strip email content and credentials before anything is recorded.
4. The cloud service
When the hosted service launches, we process:
- Account data: name, email address and plan. Payments are handled by Paddle, our reseller and Merchant of Record. We never see or store your card details.
- Mailbox access: app-specific passwords or OAuth tokens, encrypted at rest with per-customer keys and never written to logs.
- Email we sort: headers (sender, recipients, subject, date, list and authentication headers) and up to 2,000 characters of plain text from the body, held in memory while a decision is made. Full bodies are never stored; a short snippet is kept with each decision for 30 days by default (adjustable in Settings) so you can see what was sorted.
- Your rules and decisions: the rules you write, and a log of each action (time, sender, subject, rule, reason, confidence) so you can see and undo it.
- Usage: counts of emails processed and model calls, for limits and billing.
We use this data only to provide MailRules: sorting your mail, showing you why, letting you undo, sending summaries or notifications you turn on, billing and support. We do not use your email to train AI models, and we choose model providers and settings that do not train on it.
5. Who we share it with
Only service providers that help us run MailRules, under contracts that limit their use of your data. Our email (summaries, account and waitlist emails), analytics and monitoring run on servers we operate ourselves.
| Provider | Purpose | Data |
|---|---|---|
| Hetzner Online GmbH (Finland, EU) | Servers we manage ourselves for the app, database, email, analytics and monitoring | All cloud data, encrypted |
| OpenRouter (Jev) | Deciding which rule applies | Headers, excerpt, rule text |
| Cloudflare (Clef) | Alternative decision model | Headers, excerpt, rule text |
| Anthropic (Claude) | Second opinion; rule composer | Headers, excerpt, rule text |
| Paddle.com | Checkout, billing, tax and invoices (Merchant of Record) | Name, email, country, payment details |
We may disclose data if the law requires it, and we will tell you unless we are legally prevented from doing so. If TurtleByte is acquired, this policy continues to apply to your data.
6. Google and Microsoft accounts
If you connect Gmail, MailRules' use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail and Outlook data only to provide the features you see in MailRules, never for advertising, and people at TurtleByte do not read it unless you ask us to for support, or the law requires it.
7. How long we keep it
- Email snippets: 30 days by default, adjustable in Settings. Action log: 180 days, and longer while an action can still be undone.
- Account, rules and credentials: while your account is open. When you delete it, they are erased within 30 days, including backups.
- Billing records: as long as tax law requires.
- Waitlist emails: until launch, or until you ask us to remove yours.
8. Security
TLS in transit, encryption at rest, per-customer encryption keys for mailbox credentials, least-privilege staff access, and logs that never contain credentials or email bodies. If a breach affects your data, we will notify you and the relevant authorities as the law requires.
9. Your rights
You can access, correct, export or delete your data, withdraw consent, and nominate someone to exercise these rights for you. In the EU and UK you can also object to or restrict processing and complain to your data protection authority. Most of this is self-serve in Settings; otherwise email us and we will respond within 30 days.
10. International transfers
Our servers are in Finland, in the European Union. TurtleByte is based in India, and the AI model providers and Paddle may process data in other countries, including the United States. Where required, we rely on contractual safeguards such as the EU Standard Contractual Clauses.
11. Children
MailRules is not intended for anyone under 18, and we do not knowingly collect their data.
12. Changes
If we make a material change, we will email account holders at least 14 days before it takes effect and update the date above.
13. Contact and grievance officer
TurtleByte (proprietor: Tilak Kumar G), Bengaluru, Karnataka, India.
Support: [email protected]
Grievance officer: Tilak Kumar, [email protected]. We acknowledge complaints within 48 hours and resolve them within 30 days.