Last updated July 31, 2026

Privacy Policy

This Privacy Policy explains how Banger Mail, a product of BangerMail Inc., collects, uses, shares, protects, and deletes information when you use the Banger website, applications, APIs, hosted mailboxes, connected mailboxes, and related services (the Service). It forms part of our Terms of Service.

Banger Mail is designed for business and professional users. It is not intended for anyone under sixteen years old.

1. Who we are and our role

Throughout this policy, Banger, Banger Mail, we, our, and us refer to the Service operated by BangerMail Inc.

For account administration, billing, security, and operation of our public website, Banger generally acts as a controller of Personal Data. When Banger processes mailbox content and workspace data on behalf of a customer organization, the organization is generally the controller and Banger acts as its processor or service provider. Workspace administrators control who may access shared workspace data and which mailbox and AI features are enabled.

In this policy:

  • Personal Data means information relating to an identified or identifiable person.
  • Customer Data means mailbox content, workspace content, and related records that Banger processes on behalf of a customer to provide the Service.
  • Authentication Data means credentials and tokens used to authenticate users or connect third-party services, including OAuth tokens.
  • Analytics Data means limited information about use, performance, devices, and features that does not include mailbox content.
  • Subprocessor means a service provider that processes Personal Data on Banger’s behalf to help provide the Service.

2. Information we collect

We collect and process the following categories of information.

2.1 Account and workspace data

This includes your name, email address, login and session information, workspace membership, workspace and domain names, mailbox addresses, roles, permissions, approvals, settings, and similar account information.

2.2 Mailbox content and state

For hosted or connected mailboxes, this may include message content, sender and recipient information, subjects, timestamps, thread and message identifiers, labels, drafts, attachments, delivery state, routing information, and workflow records. In core mailbox-storage paths, Banger stores message bodies and queued mailbox records in encrypted form.

2.3 Connected mailbox provider data

If you connect a mailbox provider such as Gmail, Banger receives the provider account identifiers, authorization tokens and permissions, and mailbox content and state needed for that connection. We receive this information only after you authorize the connection and handle it as Account Data, Mailbox Data, or Authentication Data under this policy rather than using it for a separate purpose.

2.4 Authentication and security data

This includes OAuth tokens, granted scopes, session records, audit events, abuse signals, IP addresses, device and application diagnostics, and infrastructure logs needed to authenticate users, operate the Service, and investigate security incidents.

2.5 Analytics and website data

We collect limited operational and website analytics such as pages visited, referral source, browser and device type, feature usage, performance measurements, and conversion events. Product analytics and crash reporting are configured not to receive mailbox content. PostHog product analytics do not receive email addresses, and Sentry crash reporting does not receive mail content.

2.6 Billing data

Stripe processes payment-card and billing information needed to charge for the Service. Banger does not store complete payment-card numbers.

2.7 Data about other people and sensitive content

Emails and attachments may contain Personal Data about recipients, senders, employees, customers, or other people who do not use Banger. They may also incidentally contain sensitive information. Banger processes that information only as part of providing the Service to the customer that controls the mailbox. Customers remain responsible for ensuring that their use of Banger and the content they connect or upload complies with applicable law.

3. Where information comes from

We receive information:

  • directly from you or your organization when an account, workspace, domain, or mailbox is configured;
  • from connected providers such as Google after you authorize access;
  • from people who send messages to a mailbox hosted by or connected to Banger;
  • automatically when you use the Service or public website; and
  • from service providers involved in authentication, payment, delivery, security, and support.

4. How we use information

We use information to:

  • create and manage accounts, workspaces, domains, mailboxes, roles, and permissions;
  • receive, connect, sync, search, display, route, and deliver email;
  • provide collaboration features such as triage, approvals, drafts, labels, shared visibility, and workflow state;
  • provide AI-assisted categorization, drafting, summarization, routing, and workflow features when enabled;
  • send messages only when you or an authorized workspace workflow instructs Banger to do so;
  • provide customer support and investigate issues;
  • detect, prevent, and respond to fraud, abuse, security incidents, and service failures;
  • operate, measure, and improve the reliability and user experience of the Service; and
  • comply with legal, regulatory, accounting, and tax obligations.

We do not use mailbox content to train AI models, build advertising profiles, or improve generalized AI models. Product improvement uses Analytics Data, reliability information, de-identified or aggregated information, and feedback that users choose to provide.

Support and debugging

If resolving a support request requires access to specific mailbox content, we will ask you to provide that content or authorize access for that investigation. Access is limited to the people working on the issue, the minimum information needed, and the duration of the investigation. You may decline, in which case we will investigate using diagnostics and other information that does not require access to mailbox content.

5. AI processing

Email categorization by OpenAI

When email categorization is enabled, Banger sends OpenAI selected mailbox content and metadata relevant to determining the email’s category. This may include the subject, sender and recipient information, snippet, and relevant message-body text. OpenAI processes this data solely to return the categorization result. Neither Banger nor OpenAI uses the submitted mailbox content or categorization output to train or improve AI models.

Other AI-assisted features may use OpenAI or Anthropic when the feature is enabled by you or your workspace. We send only the content needed to produce the requested result. AI output may be incomplete or inaccurate and should be reviewed when appropriate.

6. Connecting Gmail

Banger connects to Gmail only after you approve Google’s OAuth authorization. Banger requests permission to read your Gmail mailbox and send messages on your behalf so it can synchronize, display, and search mail, retrieve attachments, categorize messages when enabled, support workspace workflows, and send only when you or an authorized workflow instructs it to do so. Banger does not request permission to modify or delete Gmail messages.

Mail obtained from Gmail receives the same storage-encryption, access, retention, and deletion protections described for other mailbox content in this policy. Banger does not sell information received from Google APIs, use it for targeted advertising, or use it to train generalized or personalized AI models. You can disconnect Gmail in Banger or revoke access through your Google account permissions. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Where the GDPR, UK GDPR, or similar laws apply, Banger relies on one or more of these legal bases:

  • Performance of a contract: to provide the Service and features requested by you or your organization.
  • Legitimate interests: to secure, maintain, troubleshoot, and improve the Service; prevent abuse; and operate our business, where those interests are not overridden by your rights.
  • Consent: where you authorize a connected account or choose an optional feature or non-essential analytics that requires consent.
  • Legal obligations: to comply with tax, accounting, regulatory, and valid legal requirements.
  • Vital interests: in exceptional circumstances where processing is necessary to protect someone from serious harm.

Where we rely on consent, you may withdraw it. Where we rely on legitimate interests, you may object to the processing.

8. How we share information

We share information only as needed to provide, secure, or administer the Service:

  • Within your workspace: with members, administrators, approvers, and agents authorized by you or your organization.
  • Subprocessors: with providers of hosting, encrypted storage, key management, authentication, logging, mail transport, AI processing, analytics, crash reporting, and billing.
  • Message recipients and mail systems: when an authorized user or workflow sends a message.
  • Legal and security matters: when reasonably necessary to comply with valid legal process, investigate abuse or security incidents, or protect the rights, safety, and integrity of Banger, our users, or others.
  • Business transfers: in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal protections.
  • With your direction or consent: when you instruct us to share information or authorize an integration.

We do not sell Personal Data or Customer Data, and we do not share it for cross-context behavioral advertising.

9. Subprocessors

Subprocessors are permitted to process information only to provide contracted services to Banger and are subject to data-protection and confidentiality obligations. Our current providers and their purposes are listed on How Banger handles your mail. OpenAI is Banger’s AI subprocessor for email categorization; it processes the selected content described in Section 5 without using that data to train or improve its models.

10. International processing

Banger and its subprocessors may process information in countries other than the country where you live. Where applicable law requires a transfer mechanism, we use a legally recognized safeguard, which may include contractual data-protection terms, the European Commission’s Standard Contractual Clauses, or applicable UK or Swiss transfer mechanisms.

11. Retention and deletion

We retain Personal Data only for as long as needed to provide the Service, maintain security, resolve disputes, enforce agreements, or comply with legal obligations.

  • Account, workspace, and mailbox data are generally retained while the applicable account, workspace, or mailbox remains active.
  • Disconnecting or deleting a mailbox causes Banger to remove its synchronized copy and stop or revoke access to the connected provider, subject to limited backup and recovery periods.
  • Deleting your Banger account begins a seven-day cancellation window. After that window, Banger removes the account and associated Customer Data, except for limited records that must be retained for security, audit, fraud-prevention, billing, or legal purposes.
  • Infrastructure logs, encrypted backups, and replicas may remain for a limited period until they expire or are overwritten through normal retention cycles.
  • Revoking Google access stops future access but does not by itself delete data previously synchronized into Banger; disconnect or delete the mailbox or account to remove Banger’s copy.

You may request account or data deletion by contacting hello@team.bangermail.com.

12. Security

Banger uses administrative, technical, and organizational safeguards designed to protect Personal Data and Customer Data.

Before email is written to persistent mailbox storage, Banger independently encrypts stored content objects, including message bodies, raw messages where retained, and stored attachments. Banger also encrypts the message metadata record needed to reconstruct the email. This protected metadata includes fields such as sender and recipient addresses, subject, dates, snippets, message and thread references, provider labels, attachment names, content types and sizes, and read-receipt information. Those fields are therefore not stored in plaintext in Banger’s mail-object storage or mailbox synchronization queues.

Each encrypted content object and metadata record receives a newly generated random 256-bit data-encryption key and an independent random nonce. Banger protects the data with XChaCha20-Poly1305, then wraps the data key to the mailbox’s public key using ephemeral X25519 key agreement, HKDF-SHA-256, and AES-256-GCM. These are authenticated-encryption mechanisms: they protect confidentiality and cause modified ciphertext or key material to fail authentication instead of being silently accepted. Synchronized mailbox action payloads and cloud mailbox snapshots are also protected with authenticated AES-256-GCM encryption using a mailbox-specific derived key.

For managed mailboxes, the private mailbox key is encrypted before it is uploaded. The encrypted private key is stored separately on dedicated AWS infrastructure, while its wrapping key is itself protected through a separate envelope-encryption layer. The systems holding encrypted mail objects do not store the corresponding plaintext private key. Mail and application traffic use TLS 1.2 or higher. Search is performed locally on the user’s device against a local index.

This protection covers email content and user-facing message metadata. Banger still retains the minimum operational metadata needed to route and synchronize encrypted objects and operate the Service, such as workspace and mailbox identifiers, queue and action identifiers, object locations, ciphertext sizes, processing timestamps, and delivery or provider status. On a user’s device, Banger decrypts mail into its local app database and search index so the application can display and search it; those local files are protected by the user’s device and operating-system access controls.

Banger manages encryption keys for users and therefore retains the technical ability to decrypt stored mail; Banger is not a strictly end-to-end encrypted service. Stored mail is not decrypted on Banger’s servers for routine indexing or search, and key operations are protected by access controls and audit logging. Banger has completed a CASA Tier 2 independent security assessment. More information is available on How Banger handles your mail.

No security program can guarantee absolute security. If a Personal Data breach requires notification under applicable law, we will notify affected customers and authorities as required.

13. Cookies and analytics

The website and Service may use strictly necessary storage or cookies for authentication, security, routing, and preferences. The public website uses PostHog for limited analytics with automatic interaction capture and session recording disabled. Analytics events are restricted and sanitized to exclude mailbox content, email addresses, authentication tokens, codes, and similar sensitive fields.

You can use browser controls and available product settings to limit cookies or analytics. Blocking strictly necessary storage may prevent parts of the Service from functioning.

14. Communications

We may send transactional or administrative communications such as account, security, service, and billing notices. You may opt out of non-essential marketing communications using the unsubscribe mechanism provided, but not from communications required to operate or secure your account.

15. Your rights and choices

Depending on where you live, you may have the right to:

  • access Personal Data about you;
  • correct inaccurate Personal Data;
  • request deletion;
  • receive a portable copy of certain data;
  • object to or restrict certain processing;
  • withdraw consent; and
  • appeal a denied privacy request or complain to your local data-protection authority.

To exercise a right, contact hello@team.bangermail.com. We may need to verify your identity and authority over the relevant account or workspace. Some rights are subject to legal exceptions, and we will explain if we cannot fully honor a request.

16. California privacy rights

California residents may have rights to know, access, correct, or delete Personal Data; obtain information about how it is collected, used, and disclosed; limit certain uses of sensitive Personal Data; and receive equal service when exercising privacy rights. Banger does not sell Personal Data and does not share it for cross-context behavioral advertising.

17. Children’s privacy

Banger is not intended for anyone under sixteen, and we do not knowingly collect Personal Data from children under sixteen. If you believe a child has provided Personal Data to Banger, contact us so we can investigate and delete it when required.

18. Changes to this policy

We may update this policy as the Service or applicable law changes. We will update the date shown above and provide additional notice by email or in the product when a material change requires it. The English version controls if a translated version conflicts with it.

19. Contact

For privacy questions, rights requests, account deletion, or connected-mailbox data questions, contact BangerMail Inc. at hello@team.bangermail.com. Security vulnerabilities should be reported to security@team.bangermail.com under our Vulnerability Disclosure Policy.