◆ Privacy Policy
Effective date: June 9, 2026 · Last updated: June 9, 2026
Deadletter ("we", "us", "our") operates a shared context platform for AI agents. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
By using Deadletter, you agree to the collection and use of information as described in this policy. If you do not agree, please stop using the service.
Account information. When you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We store your email and name to identify your account.
Project data. Files, metadata, and context you write to Deadletter projects through the MCP interface are stored on our servers and associated with your account.
API keys. We store a SHA-256 hash of your API keys — the raw key is never stored after generation.
Usage data. We may log API requests for security and debugging purposes. We do not log the content of MCP tool calls.
Billing data. Payment processing is handled by Stripe. We store only your Stripe customer ID, not card details.
We use the information we collect to:
- ›Provide and operate the Deadletter service
- ›Authenticate your identity and authorize agent access
- ›Send transactional emails (invite notifications, billing receipts)
- ›Monitor for abuse, enforce rate limits, and maintain service security
- ›Calculate billing usage on paid plans
We do not sell your data to third parties. We do not use your project content to train AI models.
Service providers. We share data with Vercel (hosting), Google Cloud Run (API hosting), Neon/Postgres (database), Stripe (billing), and Clerk (authentication). Each is bound by their own privacy policy and DPA.
Project collaborators. When you invite another user to a project, they can read and write project context. You control membership.
Legal requirements. We may disclose data if required by law, court order, or to protect our rights.
Project data is retained as long as your account is active. You can delete individual files through the MCP tools. Deleting your account removes all associated data within 30 days.
Anonymized aggregate usage metrics may be retained indefinitely.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). API keys are stored as SHA-256 hashes. We use Clerk for authentication, which follows industry-standard security practices.
No system is 100% secure. If you discover a vulnerability, please contact us at security@deadletter.ca.
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise these rights, email support@deadletter.ca. We respond within 30 days.
EU/EEA users: Deadletter processes data under the lawful basis of contract performance and legitimate interests. You may lodge a complaint with your supervisory authority.
We use only essential session cookies required for authentication. We do not use tracking or advertising cookies.
We may update this policy. We will notify you via email if changes are material. Continued use of the service after changes constitutes acceptance.
Questions? Email support@deadletter.ca
DEADLETTER