Legal
Privacy Policy
How MailThreatZero handles personal data while scanning and relaying inbound email.
Last updated 2026-08-06.
What we process, and why
Inbound messages pass through the MailThreatZero gateway for security analysis before being relayed to the configured destination mail server. To do that, the gateway necessarily processes the content and metadata of inbound messages addressed to your domains — sender and recipient addresses, subject, message body, attachments, and the connecting server's IP address.
- Message bodies
- Yes. Full message bodies are retained for 30 days to support quarantine review, release and per-message investigation.
- Tracking metadata
- Tracking records — sender, recipient, subject, size, sender IP, per-engine scores and the delivery decision — are retained for 90 days.
- Quarantined messages
- Quarantined messages remain available for review until they are released or deleted; released and deleted items are removed 30 days afterwards.
- Aggregated statistics
- Aggregated daily statistics are retained for 365 days.
- DMARC aggregate reports
- DMARC aggregate reports addressed to a domain's report mailbox are parsed and stored as structured data (sending IP, volume, authentication results, published policy). They describe mail sent as the domain, not mail sent to it, and contain no message bodies. Reports are kept for 120 days and then removed automatically — except where an alert raised from one is still unreviewed, in which case the report is held so the evidence behind an open finding cannot expire out from under it.
- Account data
- Administrator names, email addresses and hashed passwords for console access, retained while the account exists.
Link protection, and what it records
If a customer enables link protection for a domain, web links in mail for that domain are
replaced with links that pass through click.mailthreatzero.com. The link is
checked again at the moment it is clicked, because a link that was harmless when the message
arrived can be turned malicious afterwards — that is the whole point of doing it this way.
This means we learn which links are clicked, and when. What is recorded for each click is the destination hostname, a hash of the full address, the verdict, and the time. Recipient identity is not recorded unless the customer explicitly turns that on for their domain; it is off by default, because some organizations want the security signal and specifically do not want a per-person record of browsing.
Click records are kept for 30 days and then deleted. They are visible to the administrators of the customer's own account and to nobody else's.
Some things are deliberately never rewritten: unsubscribe links, digitally signed or encrypted messages, calendar invitations, and anything that is not a normal web address. Rewriting those breaks something the reader needs.
Roles
For mail processed on behalf of a customer domain, the customer determines the purpose of the processing and we process it to provide the filtering service under that customer's instructions. Data-processing terms are available on request and form part of the customer agreement.
Disclosure to others
We do not sell personal data and do not use message content for advertising or for training any model of our own. Content reaches third parties only in these cases:
- AI analysis, if you enable it. Optional AI analysis uses the provider and credentials selected by the customer, and can be disabled per domain. Data processed by optional integrations is subject to the configuration and terms of the selected provider.
- DNS blocklist operators receive the query inherent in a reputation lookup — the connecting IP address, not message content.
- Attachment reputation, if you enable it, runs on the customer's own VirusTotal account under that provider's terms.
- Your destination mail server, which is where the message is going.
- Legal obligation, if we are lawfully required to disclose.
Our subprocessors are published: who they are, what they process, whether they are required, and which optional integrations are accounts you hold rather than ours.
Security of processing
SMTP connections to and from the gateway use TLS (STARTTLS) with every server that supports it, which is the standard configuration for a public MX. Administrative access to the console and API is HTTPS only. Administrative access requires an account with a role — platform, tenant or domain administrator. Passwords are hashed, sessions are signed tokens, TOTP two-factor authentication is available on any administrative account, and repeated failed sign-ins lock the account. Sign-ins, quarantine releases from the console and from recipient links, allow-list additions, classifier training decisions and storage-allocation changes are recorded with the user, address and time. Further detail on data handling, retention and access is on the security page.
Your requests
Use the contact form for access, correction or deletion requests, or questions about this policy. Where the request concerns mail processed for a customer domain, we will normally direct it through that customer, who determines how that data is used. Tell us which jurisdiction's rules apply to your request and we will respond on that basis.
