Short answers, with the detail underneath. Anything missing is a fair question for [email protected].
Is email content encrypted at rest?
Yes. Message bodies (HTML and text) and attachments are sealed with envelope encryption before they are written: a per-message data key encrypts the content and is wrapped by the instance key, so the database holds ciphertext and a wrapped key. The wrapping key lives outside the database — the environment master key, or AWS KMS when configured. Recipients, subject and delivery events are stored as rows rather than secrets, and they age out on the retention window below.
Is MepMail SOC 2 compliant?
Not today. SOC 2 and ISO 27001 are on the roadmap, no auditor is engaged and no date is announced. Until then, hold us to the control list on this page — and because the product is open source, you can verify those controls yourself instead of relying on a report.
Is MepMail GDPR compliant?
MepMail Cloud is built for it: the application and its database run in Germany, inside the EU. Two subprocessors sit in the United States — Amazon SES (us-east-1) for delivery and Stripe for payments — and the Privacy Policy states those transfers. We do not claim a certification we do not hold.
How do I get a signed DPA?
There is no pre-signed DPA published today: write to [email protected] with your legal entity and it is agreed per customer. Self-hosting removes the question entirely — the processing agreement is then between you and your own infrastructure.
Where is my data stored, and does it stay in the EU?
MepMail Cloud: the application and its database in Germany; delivery events with Amazon SES in us-east-1; DNS and network protection through Cloudflare's global edge. The table above lists every provider and its role. A self-hosted instance stores everything wherever you deploy it.
How long is email data retained?
Message bodies and attachments leave on the team's retention window — 30 days by default — and the row is stamped when it is purged. Recipients, subject, status and events age out on the same window, as do webhook delivery records. Nightly backups are pruned after 14 days.
How do I delete a contact's data?
Delete the contact with erase=true on the API: the address is then erased from email history, event payloads and API logs — the GDPR/LGPD path. Without it, the send log ages out with the retention window. Suppressions keep only a hash of the address, as the do-not-contact record. API reference
Do AI or model subprocessors receive my email content?
No. No AI provider processes your email content on MepMail Cloud. The open-source code ships an optional abuse monitor (ABUSE_JUDGE, off by default), which a self-hoster can turn on: an already-accepted send may then be sampled and sent to TypeSafe System One for an abuse verdict. MepMail Cloud runs with it off, and a self-hoster decides for themselves.
Where can I find the current subprocessor list?
On this page — the table above, which mirrors the Privacy Policy. A self-hosted instance has no such list, because it runs on infrastructure you choose.