Legal
Privacy Policy
This policy explains how stmp ("we") handles data in the stmp email testing sandbox.
What this service does
stmp is a developer tool for testing email flows. It receives test email into sandbox mailboxes and exposes a web UI and REST API to inspect, search, and download it. It is not a public messaging, bulk-sending, or marketing service.
Data we store
To operate the sandbox we store account credentials, domains, sandbox email accounts and mailboxes, API token metadata, message metadata, message bodies (text and HTML), raw RFC 5322 email source, headers, attachments, authentication results (SPF/DKIM/DMARC), and operational logs generated by the web and SMTP processes.
How we use data
We use stored data to authenticate users, route and retain inbound test email, render the web UI, serve the REST API, and support debugging and deliverability checks. We do not sell data, run advertising, or integrate third-party marketing or analytics-resale products.
Retention and deletion
Messages may expire through the configured retention cleanup job or a per-message expiry time. You can delete accounts, domains, tokens, and messages through the UI or API where implemented. Backups, logs, and snapshots are controlled by the operator of this instance.
Your rights and contact
You may request access to, or deletion of, your account data. For questions about this policy, contact the instance operator (contact details are configured by the operator).