Legal
Privacy Policy
The short version
We store what we need to run an email API and no more: your account, the domains you have added, and one row per message describing who it went to and what happened to it. We do not store the bodies of your messages. Everything runs on servers in Sweden. We do not sell anything to anyone, and there is no advertising or analytics tracking on this site or in the app.
This box is a summary and is not the policy. The sections below are.
Who we are
Announcer is a product of Trohld AS, registered at Ladebekken 38, 7041 Trondheim ("Misralo", "we", "us"). For the personal data described in this policy we are the data controller, except where this policy says otherwise.
Questions about this policy, or about your data, go to privacy@misralo.com. A person reads that address; expect a reply within a few working days.
What we store
Your account
- Your email address, and the name you give your organisation.
- If you sign up with a password: an Argon2id hash of it. We never store the password itself and cannot recover it.
- If you sign in with Google or GitHub: that provider's permanent user ID for you, and the email address they tell us belongs to you. We never receive your password for those accounts, and we do not ask for access to anything else you keep there.
- Sessions and API keys, stored as SHA-256 hashes. The secret itself crosses the wire once, when it is created, and is never stored in a form we can read back.
The domains you send from
Each domain you add, its DKIM selector and public key, and whether we have seen the matching DNS record resolve. The private half of each signing key stays on our servers and is never exposed through the API or the dashboard.
The messages you send
One row per message, holding the sender address, the recipient address, the subject line, the message ID, delivery status, and any error the receiving server returned — plus a timestamped event for every change of status. Bounce and complaint reports we receive about your mail are stored the same way, as is your suppression list: the addresses that have hard-bounced or complained and that we will refuse to send to again.
What we do not store
The body of your messages is not written to our database. The content you submit is assembled, signed and handed to the outbound mail server, and what persists afterwards is the envelope metadata described above. Subject lines are the exception, and they are stored deliberately, because "which message was that?" is unanswerable without them. Do not put anything in a subject line you would not want us to hold.
Technical data
Our servers keep operational logs — request paths, response codes, timings, IP addresses, and the SMTP conversations our mail server has with the receiving side. These exist to keep the service working and to investigate abuse. IP addresses are also held in memory, briefly, to rate-limit sign-in attempts; that is not written to disk. This site sets no cookies and loads nothing from a third party. The dashboard sets one cookie, which holds your session and nothing else.
Data you send us about other people
When you send mail through Announcer you are giving us personal data about your recipients. For that data you are the controller and we are your processor: we act on your instructions, which are the API calls you make. You are responsible for having a lawful basis to email those people, and for the content of what you send. We are responsible for handling the data as this policy and our agreement with you describe, and for not using it for anything else — we do not mine it, profile recipients, or send them anything of our own.
The terms that govern this are written down and already in force: our data processing agreement applies to every account from the moment it is created, so there is nothing to request and nothing to sign. If your organisation needs a countersigned copy on paper, write to privacy@misralo.com and we will sign one.
Why we are allowed to hold it
Under the GDPR, our legal bases are:
- Performance of a contract — account data, domains, and message records. Without them there is no service to provide.
- Legitimate interests — logs, rate limiting, suppression lists and abuse investigation. Keeping a shared sending reputation intact is what makes the product work for everyone using it, and none of this is used to profile anyone.
- Legal obligation — where we are required to retain or produce something.
How long we keep it
| Data | Kept for |
|---|---|
| Account, domains, API keys | As long as your account is open. |
| Message records and delivery events | The history window on your plan — 14 days on Free — after which a job running on our servers deletes them. This is enforced automatically, not on request. |
| Suppression list | Until you remove an entry. A dead address that comes back is a reputation problem, so we do not expire these on our own. |
| Sessions | Until they expire or you sign out, at which point the same job deletes the record rather than leaving a spent one behind. |
| Operational and mail logs | A rolling window measured in weeks, then rotated away. |
| Encrypted backups | A short rolling window. Deleted data survives in backups until those roll off. |
You can close your account yourself, from the Plan page in the dashboard — you do not have to ask us, and there is no retention offer to sit through. Closing it deletes the account and everything attached: your domains and their signing keys, your API keys and webhooks, every message record and its delivery history, and your suppression list. It happens immediately and there is no grace period in which we could undo it, including for you. Mail already handed to our servers still goes out. Backups are the exception noted above, and logs age out on their own schedule.
Who else touches it
We keep this list short on purpose. Every name here is a company that can, in the course of doing its job, come into contact with data covered by this policy.
| Who | What for | Where |
|---|---|---|
| Akamai (Linode) | The servers everything runs on, and their backups. | Stockholm, Sweden |
| Cloudflare | DNS for our own domains, and forwarding mail sent to our published addresses. | Global |
| Google, GitHub | Only if you choose to sign in with them, and only to confirm who you are. | Global |
| Stripe / Link | If you are on a paid plan, Link (a Stripe company) is the seller of record: it takes the payment, holds your card, issues your invoices and handles the VAT. It decides how it uses that billing data as its own controller, under its own privacy policy. We never see the card number, and it receives nothing about the mail you send. | Global |
Beyond that: the mailbox providers you are sending to necessarily receive the messages you address to them — that is the whole point — and any webhook endpoint you configure receives what you have told us to send it. We do not sell personal data, and we do not share it for anyone else's marketing.
Where your data lives
The service runs on a single host in Stockholm, Sweden, inside the EEA, and that is where accounts, domains and message records are stored. Email is a global system: once a message leaves us it goes wherever the recipient's mail is hosted, which may be outside the EEA, and that is determined by the address you send to rather than by us.
How it is protected
- Everything is served over TLS. The API and the dashboard are not reachable any other way.
- Passwords are Argon2id hashes; sessions and API keys are stored only as SHA-256 hashes.
- DKIM private keys never leave the server and are never returned by any endpoint.
- Backups are encrypted before they leave the host.
- Sign-in, signup and account endpoints are rate-limited against guessing.
No system is perfect. If you think you have found a security problem, please tell us at privacy@misralo.com before telling anyone else, and we will work with you on it.
Your rights
If you are in the EEA or the UK you have the right to ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Ask at privacy@misralo.com. We will not charge you and we will not make it difficult. Erasure you do not have to ask for at all: closing your account in the dashboard deletes it, on the spot, without going through us.
If a request concerns data one of our customers sent us about you — you received an email sent through Announcer and want to know why — we will point you to the customer who sent it, because they are the controller for that data and only they can answer it.
You can also complain to your national data protection authority. In Norway that is Datatilsynet; in Sweden, IMY.
Children
Announcer is a developer tool and is not directed at children. We do not knowingly create accounts for anyone under 16.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects what we do with your data, we will email account holders before it takes effect rather than relying on you to re-read this page.
Contact
privacy@misralo.com — or write to Trohld AS, Ladebekken 38, 7041 Trondheim.