ReMail Legal
Back to the admin
Legal

ReMail — Privacy Policy

Last updated: 26 September 2026

Previous versions: 25 September 2026, 29 July 2026

This Privacy Policy explains how Aeropage Limited ("Aeropage", "we", "us") collects and uses personal information in connection with ReMail (the "Service"). It forms part of, and is incorporated into, our Terms of Service.

Capitalised terms not defined here have the meaning given in the Terms.

1. Two different roles, and why it matters

ReMail is a tool that our users ("Customers") use to send emails to their own contacts. Personal information reaches us in two distinct ways, and our role differs in each:

If you received an email sent with ReMail, it was sent by the organisation named in it, from their own email account. To stop receiving their emails, use the unsubscribe link at the bottom of the email: you can choose to stop all of their emails, the mailing list it came from, or just that email. To exercise your privacy rights, please contact that sender directly. We will help them respond where needed.

2. Information we collect

2.1 Customer account data

2.2 Recipient data (processed for our Customers)

When a Customer sends through ReMail, we process, on their behalf:

We do not add open or click tracking to emails. A Customer may enable such tracking in their own Resend account, under their agreement with Resend.

2.3 What we receive from Google

When you sign in with Google, our authentication provider (Supabase) requests Google's email and profile scopes. Google therefore discloses to us your email address, whether it has been verified, your name, and the address of your Google profile picture — nothing else, and Supabase stores them with your account. We use your email address to sign you in, and your name to address you in product-update and onboarding emails (Section 4). We do not use your profile picture. We do not use Google user data for advertising, we do not sell it, and we do not use it to train machine-learning models. Data obtained through Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

2.4 Cookies, storage, and third-party content

We do not use advertising cookies, cross-site tracking, or analytics pixels. The application stores in your browser's local storage your sign-in session, the campaign tag described in Section 2.1, the address you last used for test emails, and interface preferences. The application's own fonts are served from our own servers, not from Google Fonts. Brand fonts that a Customer chooses for its emails are loaded from Google Fonts when they are previewed in the editor, and may be loaded when that Customer's emails or unsubscribe page are displayed; this sends the viewer's IP address to Google. That is the Customer's choice.

2.5 Children

The Service is for business and professional use and is not directed to children. We do not knowingly collect personal information from children under 13.

3. How we use information

We use personal information to:

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never add Recipients to our own mailing lists or use Recipient data for our own purposes.

4. Product-update and onboarding emails

Because ReMail shares its sign-in with our other products, when you create an account we add your email address, and your name if we have it (for example, from Google sign-in), to our product-update list, hosted by Resend, and may send you onboarding emails. You can say no when you sign up with an emailed link (by ticking "opt out"), and you can switch product-update emails off or on at any time under My account in the application, by emailing privacy@aeropage.io, or by using an unsubscribe link where one is included. If you opt out, we keep your address on the list marked as unsubscribed, so that you are not added again, and we send you no onboarding emails. Opting out does not stop transactional messages about your account.

For Customer account data we rely on: performance of a contract (providing the Service you signed up for); legitimate interests (securing the Service, preventing abuse, measuring usage and campaign performance, improving reliability, and telling existing users about our products — which you can object to at any time); and legal obligation where applicable. Where we act as a processor for Recipient data, the Customer is responsible for establishing the legal basis for that processing and for any consent required to email Recipients.

6. Service providers and international transfers

We use the following providers to run the Service. They process personal information only to provide their services to us, under contractual confidentiality and security obligations:

Provider Purpose
Cloudflare Hosting, edge compute, caching of images, encrypted credential storage, usage analytics, rate limiting, and sending of sign-in emails (Email Sending)
Supabase Account sign-in, project and template records, the send log, and logo storage
Google Google sign-in (only where used); Google Fonts
Resend Our product-update list and onboarding emails; backup delivery of sign-in emails
Airtable The Customer's own data source, connected under credentials the Customer supplies and controls

Customers' emails are delivered by Resend under the Customer's own Resend account, not ours. Resend's storage and handling of those emails is governed by the Customer's agreement with Resend.

Aeropage Limited is established in the United States, and these providers may process data in the United States and other countries. Where personal information is transferred out of the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum where applicable.

7. Security

We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS); encryption at rest for stored credentials; storing recipient addresses in the send log only in coded and masked form, and in the suppression list only in coded form; per-account access controls on stored records; rate limiting; and restricted administrative access. We do not log email addresses, email content, or record data in our server logs.

No system is perfectly secure, and the Service may contain defects. Some content is intentionally reachable without signing in so that it can appear in emails: uploaded logos are stored at public addresses, and images from Airtable records are served through links that anyone holding them can open. As set out in Sections 10 and 17 of the Terms, Customers control their configuration and connected accounts. If a personal-data breach affects you, we will notify you and, where required, the relevant authorities, without undue delay.

8. Retention

Data How long we keep it
Account, projects, templates, brands, and settings While your account is active, until you delete them (see below)
Stored Airtable token and Resend key Until you delete them or your account is deleted
Send log and batch records (coded and masked recipients, subjects, statuses) For the life of the account, so that duplicate sends can be prevented; deleted when the account is deleted
Suppression list (coded recipient addresses and their unsubscribe choices) For the life of the account, so that unsubscribes keep working; deleted when the account is deleted
Simulation records Until you clear them
Uploaded logos Until you delete them or your account is deleted
Cached images from Airtable Up to 1 day
Campaign tag in your browser 30 days
Email bodies Not stored
Terms acceptance records Kept after your account is deleted, as a legal record of what you agreed to (no email address is stored with them)

Deletion. You can delete data yourself in the application:

Deleting data in ReMail does not delete emails held in your Resend account or records in your Airtable base; manage those directly with those providers. We keep limited records where required for legal, accounting, or security reasons, such as terms acceptance records. You can also ask us to delete your data by emailing privacy@aeropage.io from your account email address, and we'll complete it within 30 days.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing, including direct marketing; to withdraw consent where processing is based on consent; and to complain to your data-protection authority (in the UK, the Information Commissioner's Office). Residents of California and other US states with comprehensive privacy laws have comparable rights, including the right not to be discriminated against for exercising them — noting that we do not sell personal information or share it for cross-context behavioural advertising.

To exercise any of these rights over data we hold as a controller, contact privacy@aeropage.io. We will respond within the period required by applicable law. If you are a Recipient, you can unsubscribe using the link in any email sent with ReMail; for anything else, please contact the sender of the email — they control your data, and we will support them in responding.

10. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email. We will update the provider list in Section 6 before adding a new provider that processes Recipient data.

11. Contact

Aeropage Limited
1111B S Governors Ave STE 7987, Dover, DE 19904, United States
Privacy: privacy@aeropage.io
Legal: legal@aeropage.io