This Privacy Policy explains how Banger, a product of BangerMail Inc., collects, uses, shares, protects, and deletes information when you use the Banger website, web app, API, MCP server, mailboxes, and related services (the Service). It forms part of our Terms of Service.
Banger is designed for business and professional users. It is not intended for anyone under sixteen years old.
1. Who we are and our role
Throughout this policy, Banger, we, our, and us refer to the Service operated by BangerMail Inc.
For account administration, billing, security, and our public website, Banger generally acts as a controller of Personal Data. When Banger processes mail, contacts, and other workspace content on behalf of a customer, the customer is generally the controller and Banger acts as its processor or service provider. Workspace administrators control who, and which agents, can access workspace data and which features are enabled.
In this policy:
- Personal Data means information relating to an identified or identifiable person.
- Customer Data means mail, contacts, templates, and other content that Banger processes on behalf of a customer to provide the Service.
- Authentication Data means credentials and tokens used to sign in or connect agents and third-party services, including API keys and OAuth tokens.
- Analytics Data means limited information about use and performance of the Service that does not include mail content.
- Subprocessor means a service provider that processes Personal Data on Banger’s behalf to help provide the Service.
2. Information we collect
2.1 Account and workspace data
Your name, email address, sign-in and session information, workspace membership, roles and permissions, products, domains, mailbox addresses, approvals, settings, and similar account information.
2.2 Mail
For mailboxes hosted by Banger and mailboxes you connect, this includes message content, attachments, sender and recipient information, subjects, timestamps, headers, thread information, labels, drafts, and delivery status. For email you send through Banger (mailbox, product, Broadcast, and Journey email), it includes the message, its recipients, and delivery events such as delivered, bounced, complained, and unsubscribed.
2.3 Contacts and audience data
Contacts, lists, segments, and custom fields that you or your agents add or import, subscription status, consent records (who confirmed consent, when, and any evidence provided), and signup form submissions. For Broadcast and Journey email, Banger records engagement such as opens and link clicks, using a tracking image and redirected links.
2.4 Brand and website data
When you set up a product, Banger may read your public website to suggest your brand’s name, colors, fonts, logo, and tone. You can also upload images and other brand assets.
2.5 Connected provider and agent data
If you connect a provider such as Gmail, Banger receives the account identifiers, authorization tokens, and mail needed for that connection. If you connect an AI agent or create an API key, Banger stores the connection, its permissions, and a record of the actions it takes.
2.6 Authentication and security data
OAuth tokens, API keys, session records, audit events, abuse signals, IP addresses, browser information, and infrastructure logs needed to authenticate users, operate the Service, and investigate security incidents.
2.7 Analytics and website data
Limited product and website analytics such as pages visited, referral source, browser and device type, feature usage, and conversion events. Product analytics use pseudonymous identifiers and do not receive mail content or email addresses.
2.8 Billing data
Stripe processes payment-card and billing information needed to charge for the Service. Banger does not store complete payment-card numbers.
2.9 Support and feedback
When you contact us or send feedback or a bug report from the Service, we receive your email address, your message, and any attachments you choose to include.
2.10 Data about other people
Mail, attachments, and contact lists contain Personal Data about people who do not use Banger, such as your recipients, subscribers, and correspondents, and may incidentally contain sensitive information. Banger processes that information only to provide the Service to the customer that controls it. Customers are responsible for having a lawful basis, including consent where required, for the Personal Data they bring to Banger and the email they send. See our Acceptable Use & Anti-Spam Policy.
3. Where information comes from
We receive information:
- directly from you, your organization, or the agents you authorize;
- from connected providers such as Google after you authorize access;
- from people who send email to, or subscribe through, a mailbox or form hosted by Banger;
- from recipients’ mail systems, which report deliveries, bounces, and complaints;
- automatically when you use the Service or public website; and
- from service providers involved in authentication, payment, delivery, security, and support.
4. How we use information
We use information to:
- create and manage accounts, workspaces, products, domains, mailboxes, and permissions;
- receive, store, search, display, and deliver email, and run Broadcasts, Journeys, and signup forms;
- honor unsubscribes, suppress bounced and complaining addresses, and protect deliverability;
- let you and your agents review, approve, and act on mail and sending;
- provide the AI features described in section 5;
- provide customer support and investigate issues;
- detect, prevent, and respond to spam, fraud, abuse, and security incidents;
- operate, measure, and improve the reliability and usability of the Service; and
- comply with legal, regulatory, accounting, and tax obligations; and
- measure public website visits with PostHog, with a browser opt-out.
We do not use Customer Data to train AI models or to build advertising profiles.
Support and debugging
If resolving a support request requires looking at specific mail or contacts, we will ask for your permission first. Access is limited to the people working on the issue, the minimum information needed, and the duration of the investigation.
5. AI processing
Banger uses AI for specific features. We send each provider only what the feature needs, and neither Banger nor these providers use the data to train AI models.
-
OpenAI powers these features:
- Email design, when you or an agent ask Banger to create or revise an email. OpenAI receives your request, your brand details, the audience you describe, and the draft email.
- The mail assistant, when you ask it a question about your mail. OpenAI receives your request and the messages the assistant looks up to answer it, which can include subjects, senders, and message text. Banger keeps the assistant’s run history for one hour.
- Brand discovery during setup, which reads your public website. OpenAI receives public text, styles, and images from that site.
- Translation of your email templates, when you ask for it. OpenAI receives the text to be translated.
Banger’s requests to OpenAI ask it not to store them.
-
TypeSafe powers these features:
- Labels & Triage. When you have enabled rules in a mailbox, TypeSafe receives the incoming thread with some personal details removed. This includes sender and recipients, the subject, the message text, and whether it has attachments.
- Contact import mapping. When you import contacts, TypeSafe receives the file name, the column headers, and up to eight sample values per column so it can suggest how to map them. The samples may include names and email addresses.
-
Your own AI keys. If you connect your own OpenAI or Anthropic account, Banger sends the content for the features you use with that key to that provider under your own agreement with them. Banger stores your key encrypted.
-
Your own agents. When an AI agent you connect, such as an assistant using the Banger MCP server, reads mail or contacts through Banger, that data goes to the agent’s provider under your agreement with them. Banger does not control how that provider handles it.
AI output can be incomplete or wrong and should be reviewed before you rely on it.
6. Connecting Gmail
Banger connects to Gmail only after you approve Google’s OAuth authorization. Banger requests your basic account identity and permission to read your Gmail mail and send email on your behalf. It uses these to receive, display, and search your mail, apply Labels & Triage when you enable it, answer your questions through the mail assistant, and send only when you or an agent you authorized instructs it to. Banger does not request permission to modify or delete Gmail messages. Labels and other changes you make in Banger stay in Banger.
Banger does not sell information received from Google APIs, use it for advertising, or use it to train AI models. You can revoke Banger’s access at any time from your Google account permissions. Banger’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Legal bases for processing
Where the GDPR, UK GDPR, LGPD, or similar laws apply, Banger relies on one or more of these legal bases:
- Performance of a contract: to provide the Service and the features you or your organization request.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Service, prevent spam and abuse, and operate our business, where those interests are not overridden by your rights.
- Consent: where you connect an account or choose an optional feature that requires it.
- Legal obligations: to comply with tax, accounting, regulatory, and valid legal requirements.
- Vital interests: in exceptional circumstances where processing is necessary to protect someone from serious harm.
Where we rely on consent, you may withdraw it. Where we rely on legitimate interests, you may object.
8. How we share information
We share information only as needed to provide, secure, or administer the Service:
- Within your workspace: with members, administrators, and agents authorized by you or your organization.
- Subprocessors: with the providers listed in section 9.
- Message recipients and mail systems: when you or an authorized agent sends email.
- Providers you connect: with AI providers, agents, and integrations that you authorize.
- Legal and security matters: when reasonably necessary to comply with valid legal process, investigate spam, abuse, or security incidents, or protect the rights, safety, and integrity of Banger, our users, or others.
- Business transfers: in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
We do not sell Personal Data or Customer Data. Personalized advertising is disabled on the public website. We do not share Customer Data, mailbox content, contacts, or data received from Google mailbox APIs for advertising. See section 13 for the website analytics opt-out.
9. Subprocessors
Subprocessors may process information only to provide their services to Banger and are bound by data-protection and confidentiality obligations. Our current subprocessors are:
- Cloudflare hosts the application, queues, and logs. It also provides bot protection and DNS lookups.
- PlanetScale hosts the primary database, running on AWS in the United States.
- Backblaze B2 stores mail, attachments, and files in the United States.
- Amazon Web Services sends email through Amazon SES and stores secrets, in the EU (Frankfurt).
- Hetzner runs the mail receiving and sending servers, spam and malware filtering, and self-hosted logs and monitoring.
- Google provides the Gmail connection for mailboxes you link.
- OpenAI powers the AI features described in section 5.
- TypeSafe powers Labels & Triage and contact import mapping.
- Stripe handles billing and payments.
- PostHog provides product analytics from the United States, with pseudonymous identifiers only.
- Linear and Slack receive the support and feedback messages you send us.
The same list is published on How Banger handles your mail.
Google Analytics / Google Ads and the Meta Pixel are disabled on the public website.
10. International processing
Banger and its subprocessors process information in the United States, the European Union, and other countries that may differ from where you live. Where applicable law requires a transfer mechanism, we use a legally recognized safeguard, such as the European Commission’s Standard Contractual Clauses or applicable UK, Swiss, or Brazilian mechanisms.
11. Retention and deletion
We keep Personal Data only as long as needed to provide the Service, maintain security, resolve disputes, enforce agreements, or comply with legal obligations.
- Account, workspace, mail, and contact data are generally kept while the account and workspace remain active.
- Deleting your Banger account starts a seven-day window during which you can cancel. After it, Banger deletes the workspace’s database records and stored files, except for limited records we must keep for security, audit, fraud-prevention, billing, or legal purposes.
- Suppression records, such as unsubscribes, bounces, and complaints, are kept while the workspace exists so that people who opted out are not emailed again. They are stored as one-way hashes of the email address.
- AI mail assistant run history is kept for one hour.
- Logs and backups may remain for a limited period until they expire through normal retention cycles.
- Revoking Google access stops future access. It does not by itself delete mail already received into Banger. To remove Banger’s copy, delete your account or ask us to delete that mailbox’s mail.
Plan history limits do not delete stored mail today: mail stays in your workspace until you delete your account or ask us to delete it.
You may request account or data deletion by contacting hello@team.bangermail.com.
12. Security
Banger uses administrative, technical, and organizational safeguards designed to protect Personal Data and Customer Data:
- Traffic to and from Banger uses TLS 1.2 or higher. Outbound mail from domains set up with Banger is DKIM-signed.
- The primary database is encrypted at rest by our database provider.
- OAuth refresh tokens, connected provider keys, and your own AI keys are envelope-encrypted with AES-256-GCM before storage. DKIM signing keys are also stored encrypted.
- Workspace data is separated with database-level access controls, and access by agents and API keys is limited to the permissions you grant.
- Sign-in, agent actions, and administrative actions are recorded in audit logs.
Banger manages these encryption keys for you, and mail is processed in readable form on Banger’s servers so the Service can search, filter, triage, display, and deliver it. Banger can therefore technically access stored data. Banger is not an end-to-end encrypted service. Access to production data is restricted to the people who need it to run the Service.
Banger’s Google mailbox integration has completed a CASA Tier 2 independent security assessment. More information is available on How Banger handles your mail.
No security program can guarantee absolute security. If a Personal Data breach requires notification under applicable law, we will notify affected customers and authorities as required.
13. Cookies and analytics
The website and Service use essential storage and cookies for sign-in, security, and preferences. Website analytics are controlled separately from the web app.
PostHog measures visits to public website pages and clicks on signup links by default. It uses pseudonymous visitor identifiers. These events exclude email addresses, mailbox and message content, customer data, search text, and authentication tokens. Query parameters and fragments are removed from page URLs before capture.
You can turn off website analytics using the control at the top of this Privacy Policy. We save the opt-out in this browser’s local storage; it remains in effect until you turn analytics back on or clear that storage. A first-party cookie provides a fallback when storage is unavailable. Opting out stops future website collection and clears website analytics persistence; it does not delete previously collected events. Use the contact details in section 19 to exercise applicable rights. Existing saved analytics denials are respected.
Google Analytics and personalized advertising through Google and Meta are disabled on this website. Website analytics settings do not control the Banger web app, email subscriptions, or customer sending. Banger’s product analytics remain separate. Browser settings can also limit cookies; blocking essential storage may prevent parts of the Service from working.
14. Communications
We send transactional and administrative messages, such as sign-in codes and account, security, service, and billing notices. You may opt out of non-essential marketing messages using the unsubscribe link, but not from messages required to operate or secure your account.
15. Your rights and choices
Depending on where you live, you may have the right to:
- access Personal Data about you;
- correct inaccurate Personal Data;
- request deletion;
- receive a portable copy of certain data;
- object to or restrict certain processing;
- withdraw consent; and
- appeal a denied request or complain to your local data-protection authority.
To exercise a right, contact hello@team.bangermail.com. We may need to verify your identity and authority over the relevant account or workspace.
If you are a recipient or subscriber of a Banger customer, that customer controls your data. Use the unsubscribe link in their email or contact them directly. If you contact us, we will forward your request to the customer where we can.
16. California privacy rights
California residents may have rights to know, access, correct, or delete Personal Data; obtain information about how it is collected, used, and disclosed; limit certain uses of sensitive Personal Data; and receive equal service when exercising privacy rights. Banger does not sell Personal Data. Personalized advertising is disabled on this website. We do not share mailbox content, contacts, messages, or web-app activity for this purpose.
17. Children’s privacy
Banger is not intended for anyone under sixteen, and we do not knowingly collect Personal Data from children under sixteen. If you believe a child has provided Personal Data to Banger, contact us so we can investigate and delete it when required.
18. Changes to this policy
We may update this policy as the Service or applicable law changes. We will update the date shown above and provide additional notice by email or in the product when a material change requires it. The English version controls if a translated version conflicts with it.
19. Contact
For privacy questions, rights requests, or account deletion, contact BangerMail Inc. at hello@team.bangermail.com. Report security vulnerabilities to security@team.bangermail.com under our Vulnerability Disclosure Policy.