Privacy Policy
Effective date: 2026-04-25
This Privacy Policy explains what information we collect when you use Authigent Email, how we use it, and the choices you have. If you have questions, email privacy@authigent.com.
1. Who we are
"We" / "us" refer to Authigent, the company providing Authigent Email. We are the data controller for your account information and a data processor for the mail content your agents send and receive through our service.
2. What we collect
Account information
- email address (provided at sign-up via Stripe Checkout);
- password hash (managed by Firebase Authentication; we never see plaintext) or Google sign-in identity tokens;
- billing information processed by Stripe (we receive a Stripe customer ID and summary, not card details);
- your subscription tier and history.
Agent registration data
- agent name, mailbox address, and webhook URL you register;
- optional custom auth header value, encrypted at rest and never displayed back;
- HMAC signing secrets we issue, stored encrypted; we display each secret to you once at issuance.
Operational and security data
- request logs (timestamp, IP, user agent, endpoint, response code) used for debugging, abuse prevention, and audit;
- delivery logs (which message was POSTed to which webhook, with response code and latency).
Mail content
When inbound mail is delivered to your registered mailboxes, we receive the message bytes (headers + body + attachments) and forward parsed content to your registered webhook endpoint. We retain message bytes for the operational windows described in Section 5 (Retention).
3. Why we use it
- Service delivery — to authenticate you, route mail to your registered endpoints, sign outbound mail, enforce subscription limits, and operate the consumer portal.
- Billing — to bill subscriptions and manage invoices via Stripe.
- Security and abuse prevention — to detect spam, fraud, and attempts to bypass authentication.
- Service improvement — to debug, measure performance, and improve reliability.
- Legal compliance — to respond to lawful requests and meet our regulatory obligations.
4. Service providers and sharing
We work with the following processors (sub-processors):
- Google Cloud Platform / Firebase — infrastructure hosting, authentication, Firestore database, Secret Manager.
- Stripe — subscription billing and Customer Portal.
- Cloudflare — DNS for our domains.
We do not sell or rent personal information. We may disclose information when legally required (subpoena, court order) or to protect rights, safety, or security.
5. Data retention
- account info — for the life of your account plus 30 days;
- billing records — 7 years (legal/financial requirement);
- request logs — 30–90 days, then aggregated;
- mail content — 30 days after delivery to your webhook (configurable in your dashboard);
- HMAC and webhook header secrets — for the life of the agent registration plus 30 days after deactivation, retained for forensics.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. To exercise these rights, email privacy@authigent.com. We will respond within 30 days (or the period required by your local law).
You may close your account at any time from the consumer portal. Closing your account deletes your registered agents and stops message delivery; existing message history may be retained per Section 5 above.
7. Security
We use commercially reasonable safeguards — TLS in transit, encryption at rest for sensitive material (HMAC secrets, webhook auth headers, OAuth refresh tokens), scoped IAM, audit logging. No system is impervious; you should keep your account credentials private and your registered webhook endpoints secure.
8. Cookies and similar technologies
The marketing site uses no marketing or analytics cookies as of this policy's
effective date. The consumer portal uses Firebase Authentication, which sets an
auth-session cookie and persists tokens in IndexedDB on your browser to
keep you signed in. We do not use third-party advertising cookies.
9. Children
The service is not intended for, and we do not knowingly collect personal information from, anyone under 18. If you believe a child has provided information, contact us and we will delete it.
10. International transfers
Our infrastructure runs in Google Cloud Platform regions; primary processing today is
in us-central1. If you are outside the United States, your information may
be transferred to and processed in the U.S. We rely on Standard Contractual Clauses or
other lawful transfer mechanisms where required.
11. Changes to this Policy
We may update this Policy from time to time. Material changes take effect 30 days after we post the updated version (or notify you by email if you have an active subscription).
12. Contact
Questions, concerns, or requests: privacy@authigent.com.