This policy describes how FlareMail (“FlareMail,” “we,” “us”) handles information when you use the inbox at app.sendwithflare.com, the iOS app, the API, and the marketing site at sendwithflare.com. Effective September 12, 2026.
Who this covers
It applies to people who create a FlareMail account, connect a Cloudflare domain, send or receive mail through FlareMail, visit the marketing site, or contact us for support.
What we collect
- Account. Email address, password (stored hashed), Google sign-in identifiers if you use Google, session tokens, and team invites or mailbox grants you create.
- Mail. Messages you send and receive through FlareMail: headers, bodies, attachments, folders, labels, drafts, scheduled sends, and related metadata. Metadata lives in Cloudflare D1. Bodies and attachments live in Cloudflare R2.
- Billing. Subscription and entitlement status. Card numbers and payment details are processed by Paddle; we do not store full payment card numbers.
- Device and app. On iOS, an Apple Push Notification service device token if you allow notifications, plus the app environment (sandbox or production). The web and desktop apps store a session token on the device (browser storage or OS keychain).
- Optional product features. Contacts, filter rules, API keys you create, webhooks you configure, and (if you use them) AI summaries or writing help.
- Marketing site. Pages on sendwithflare.com record browser pageviews (path, referrer, browser, OS, country) and may load Microsoft Clarity. That is separate from mail in your inbox.
How we use it
- Provide the inbox: store, list, search, send, and receive your mail.
- Authenticate you, keep sessions working, and honor team mailbox access.
- Bill the unlimited-domain plan through Paddle when you go past three domains.
- Send iOS notifications for new mail when you have enabled them.
- Improve the product and the marketing site (pageviews, Clarity on sendwithflare.com).
- Respond when you email [email protected].
AI features
If you use in-app AI (summaries, writing polish, similar), relevant message text is sent to OpenAI to produce the result. Memory features may create embeddings with Cloudflare Workers AI and store them in Cloudflare Vectorize. You can avoid this by not using those features. We do not use your mailbox to train a public FlareMail model.
Processors we rely on
- Cloudflare — Workers, Pages, D1, R2, Email Routing, Queues, Workers AI, Vectorize, and related logs for hosting the product.
- Paddle — subscriptions and invoices.
- Resend — outbound mail to recipients outside a Cloudflare-provisioned domain.
- OpenAI — optional AI features you invoke.
- Google — only if you sign in with Google.
- Apple — APNs, if you enable iOS notifications.
- Microsoft Clarity — usage analytics on the marketing site.
What we do not do
- We do not sell your personal information.
- We do not show ads in the inbox.
- We do not scan your mail to profile you for advertising.
- Inbound tracking pixels and remote images are blocked by default; see Privacy & tracking protection.
Cookies and local storage
The hosted app authenticates with a bearer session token, not a cookie. The browser stores that token locally. The marketing site may set Clarity cookies. Cloudflare may set cookies required to run Pages and related services.
Retention
We keep account and mail data while your account is active. If you close the account or ask us to delete it, we delete stored mail, attachments, API keys, and device tokens associated with that account, except records we must keep for billing, abuse, or legal reasons (for example Paddle invoices or security logs).
Your choices
- You can export or download messages and attachments you have access to in the app.
- You can revoke Google access from your Google account.
- You can disable iOS notifications in system settings; we then stop using that device token for alerts.
- You can email [email protected] to access, correct, or delete personal data we hold.
Children
FlareMail is not directed at children under 13, and we do not knowingly collect personal information from them.
International processing
The product runs on Cloudflare’s network. Your information may be processed in the United States and other locations where Cloudflare or the processors above operate.
Changes
We will update this page when the policy changes. The date at the top is the current version. Continued use after a change means the new policy applies.
Contact
Questions about privacy: [email protected]. Support page: sendwithflare.com/support.