Privacy Policy
Draft — last updated 31 July 2026. Pending legal review before public launch.
What this covers
PostalMCP prints and posts physical mail on behalf of its users. This policy explains what we store, why, and for how long. Two groups of people are involved, and they are treated differently: users, who hold accounts and send mail, and recipients, who receive it and have no relationship with us.
What we store about users
- Identity — your name and verified email address from Google or GitHub. We never receive your password, and we request identity scopes only.
- Payment — a Stripe customer reference and the last four digits and brand of your card. Full card details never reach our servers; they go directly from your browser to Stripe.
- Mail you send — recipient addresses, the rendered content, proofs, prices, and delivery status.
- Return address — the sender address you supply, saved so you do not have to repeat it.
What we store about recipients
To print and post a piece we necessarily process the recipient's name and address, supplied by the user sending it. We do not build profiles of recipients, do not sell or share address data, and do not use one user's recipient list for anything other than that user's mail.
Our do-not-mail list stores only a one-way SHA-256 hash of the name and address — it cannot be reversed into a mailing list. It is scoped to the specific named recipient, so opting out never affects anyone else at the same address.
Content of your mail
We render, store and transmit the content you send so it can be printed, and so a proof of what was sent remains available to you. Content is screened automatically before printing for a narrow set of prohibited categories (see the Terms). We do not read your mail for any other purpose and do not use it to train models.
Processors we use
- Cloudflare — hosting, database and file storage.
- Lob — printing and postal handling. Recipient address and content are necessarily shared.
- Stripe — payments. Card data is held by Stripe, not by us.
- Resend — transactional email (order confirmations, delivery notices).
- Anthropic — automated content screening before printing.
Retention
Order records, recipient addresses and proofs are kept for 2 years, which covers the period USPS retains certified-mail delivery records and the window in which a filing or dispute may need evidence of what was sent. Unpaid drafts are deleted 30 minutes after they expire. Do-not-mail hashes are kept indefinitely — deleting them would restart the mail.
Your rights
You can see everything sent from your account in the dashboard, and export or request deletion by contacting us. Deleting an account does not retract mail already posted, and does not remove do-not-mail entries.
Contact
privacy@postalmcp.com