Privacy Policy

Draft Version 0.1 No effective date Last updated 9 July 2026

Deloosh is an email marketing service — an “email brain” that helps small businesses protect their deliverability, plan their email strategy, and draft emails with AI assistance. This policy explains what personal information we handle, why, and what your rights are. We have written it in plain language on purpose. Plain language does not make it less binding: everything here is a commitment.

It covers our websites (deloosh.com), our application (app.deloosh.com), our sending and tracking infrastructure (including delooshmail.com), and our APIs (api.deloosh.com).

1. Who we are

Deloosh is operated by [FACT-CONFIRM: legal entity name, place of incorporation, company/ABN registration number] (“Deloosh”, “we”, “us”), with its principal place of business in [FACT-CONFIRM: address], Australia.

Privacy contact: privacy@deloosh.com [FACT-CONFIRM: mailbox exists and is monitored]

[LAWYER + FACT-CONFIRM: EU Article 27 / UK representative — if appointed, name and contact details go here; if not yet appointed, the appointment decision is an escalation item and must be resolved before publishing to EU/UK customers.]

2. The two roles we play (please read this first)

Deloosh handles personal data in two very different capacities, and your rights depend on which one applies:

  • Your account — we are responsible. For the data you give us when you sign up and use Deloosh (your account details, billing, your conversations with the Deloosh agent, information about your business), we decide how and why it is processed. In GDPR terms we are the controller; in US state privacy law terms we are the business. This policy is the governing document for that data.

  • Your subscribers’ data — you are responsible, we act on your instructions. When you import your contact list and send email through Deloosh, your subscribers’ data (email addresses, names, engagement history) is your data. You are the controller; we are your processor (GDPR) / service provider (CCPA). We process it only to provide the service to you, under our Data Processing Addendum (deloosh.com/legal/dpa [FACT-CONFIRM: DPA drafted and published before this policy goes live — this policy cross-references it]), and we do not use it for our own purposes.

If you received an email from someone who uses Deloosh and you have questions about your data, see Section 12 — “Did you get an email sent with Deloosh?“

3. Information we collect about our customers (Deloosh as controller)

Account information. Your email address, your name, and your Google account identity if you sign in with Google. Deloosh is passwordless — you sign in with Google or a magic link sent to your email. We never create or store a password for you, so there is no Deloosh password to be breached.

Billing information. Payments are handled by Stripe through Stripe’s hosted checkout and customer portal. Your card number never touches Deloosh’s systems. We receive from Stripe only what we need to run your subscription: your billing status, plan, and Stripe customer reference.

Conversations with the Deloosh agent. Deloosh works as a chat-based assistant. We store your conversations with it so the product works and improves for you. Anything you type into the chat is stored — please don’t paste sensitive personal information (e.g. health or financial details about identifiable people) into it that isn’t needed for your email marketing.

Brand memory. Deloosh builds up a working memory of facts about your business — including a scan of your public website and business facts you confirm in conversation — so the agent doesn’t ask you the same questions twice. This can include personal data (for example, your name and role, or testimonials on your site).

Usage data. Counters and operational telemetry: how many contacts you have, how many emails you send, which features you use, and internal AI-usage accounting. We use this to run the service, enforce plan limits, and understand product usage.

Website visitors. When you visit deloosh.com we collect [FACT-CONFIRM: analytics tool on deloosh.com — name the tool, what it collects, whether cookies are set, and whether a consent banner is required; this section cannot be finalised until the tool is chosen]. The app at app.deloosh.com uses strictly necessary session storage to keep you signed in (via our authentication provider, Supabase); this is required for the service to function and is not used for advertising.

Support and correspondence. If you email us, we keep the correspondence.

4. Information we process for our customers (Deloosh as processor)

When you use Deloosh to manage your audience and send email, we process your subscribers’ (“recipients’”) data on your instructions:

  • Contact identity: email address, plus any attributes you import (name, location, tags, custom fields).
  • Permission and provenance records: for every contact you import, Deloosh records where the contact came from, the permission basis you declare (for example, explicit opt-in or an existing customer relationship), when consent was collected, and a risk classification. This is deliberate: it is your evidence trail that you have permission to email people, and it protects your deliverability and your legal position.
  • Engagement data: link clicks on emails you send, collected via our tracking infrastructure (delooshmail.com or your branded tracking domain). [FACT-CONFIRM: whether an open-tracking pixel is embedded in sent emails at all — if yes, disclose opens collection here; if no, we can say plainly "we do not embed open-tracking pixels", which is a differentiator. Do not publish either statement unverified.]
  • Suppression records: unsubscribes, spam complaints, and bounces. These are authoritative in Deloosh — an unsubscribe can never be overridden or cleared by re-importing a list.
  • Send history: what was sent, to whom, and when.

Three structural commitments about recipient data:

  1. We do not sell recipient data, enrich it from third-party sources, or merge identities across customers. Deloosh is built to refuse data-broker behaviours.
  2. We use recipient data only to provide, secure, and improve the service for you, as permitted by the Data Processing Addendum — never for our own marketing, and never to build cross-customer profiles.
  3. Nothing is sent without a human’s approval. The Deloosh agent prepares and suggests; your emails go out only when you approve them.

Where GDPR or UK GDPR applies, our legal bases as controller are:

PurposeDataLegal basis
Creating and operating your account; providing the service, including the agent, brand memory, and draftingAccount, agent conversations, brand memory, usagePerformance of a contract (GDPR Art 6(1)(b))
Billing and subscription managementBillingPerformance of a contract (Art 6(1)(b)); legal obligation for tax/accounting records (Art 6(1)(c))
Securing the service, preventing abuse and spam, enforcing our Acceptable Use PolicyAccount, usage, send historyLegitimate interests (Art 6(1)(f)) — running a trustworthy email platform
Service communications (e.g. billing notices, security notices)AccountPerformance of a contract (Art 6(1)(b))
Marketing our own service to prospectsProspect contact detailsConsent (Art 6(1)(a)), or legitimate interests where permitted for existing customers, always with an opt-out
Improving the product (aggregate/de-identified analysis)UsageLegitimate interests (Art 6(1)(f))
Complying with law (tax, sanctions, lawful requests)As requiredLegal obligation (Art 6(1)(c))

For recipient data (Section 4), the legal basis is yours to establish as controller — Deloosh processes it under Article 28 on your documented instructions. Deloosh’s provenance records exist to help you evidence that basis.

6. AI processing

Deloosh’s assistant, strategy engine, and drafting features are powered by AI models provided by Anthropic, acting as our subprocessor. Your agent conversations, brand memory, and draft content are sent to Anthropic to generate responses.

  • Your data is not used to train Anthropic’s models. Anthropic’s Commercial Terms of Service provide that “Anthropic may not train models on Customer Content from Services” (verified 2026-07-09 against anthropic.com/legal/commercial-terms). Retention of API data by Anthropic is governed by its data retention policy and our agreement with Anthropic.
  • We do not use your data or your subscribers’ data to train our own models.
  • A human approves every send. The AI proposes strategy and drafts; nothing is emailed to your subscribers without your explicit approval.
  • Automated decision-making: Deloosh’s strategy engine makes automated suggestions about email timing, audience, and content. These suggestions do not produce legal or similarly significant effects on you or your subscribers without human involvement — you decide what is sent.

7. Who we share personal data with

We do not sell personal information, and we do not share personal information for cross-context behavioural advertising (as those terms are defined in the California Consumer Privacy Act). We have not done so in the preceding 12 months. [FACT-CONFIRM: this statement must be re-checked once the deloosh.com analytics tool is chosen — an advertising-grade analytics/ads pixel could make "share" untrue.]

We share personal data only with:

Subprocessors and service providers — companies that help us run Deloosh, under contracts that bind them to protect your data:

VendorWhat they do for usData touchedLocation
SupabaseDatabase and authenticationAccount and service data, recipient data[FACT-CONFIRM: region]
Amazon Web Services (SES/SNS)Email sending and delivery eventsRecipient email addresses, send/delivery events[FACT-CONFIRM: SES region]
RailwayApplication hostingService data in transit[FACT-CONFIRM: region]
VercelWebsite and app hostingVisitor and app session dataGlobal edge network
StripePayments and billingBilling identity (card data goes to Stripe directly, never to us)United States
AnthropicAI processing (chat, drafting, strategy)Agent conversations, brand memory, draft contentUnited States
ResendEmail sending [FACT-CONFIRM: still in the sending path, or fully cut over to AWS SES? Remove this row if cut over]Recipient email addresses[FACT-CONFIRM]

The current subprocessor list is maintained at deloosh.com/legal/subprocessors [FACT-CONFIRM: page exists at publish], and customers on our Data Processing Addendum are notified of changes.

Legal compulsion. We may disclose personal data where required by law — for example a valid subpoena, warrant, or production order. Where lawful, we will notify the affected customer before disclosure.

Business transfers. If Deloosh is acquired or merges, personal data may transfer to the successor, who must honour this policy or give you notice and choices before changing it.

We do not share your data with any other third parties.

8. International data transfers

Deloosh serves customers globally. Personal data is processed in Australia (where Deloosh is operated), the United States (most subprocessors above), and the regions noted in the subprocessor table.

  • From the EEA/UK: Australia is not covered by an EU adequacy decision (verified 2026-07-09 against the European Commission’s adequacy decisions list), so transfers to Deloosh rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated into our Data Processing Addendum, together with the UK Addendum/IDTA for UK transfers.
  • Onward transfers to US subprocessors rely on the EU-US Data Privacy Framework where the vendor holds an active certification (Stripe and Amazon verified active as of 2026-07-09), and on Standard Contractual Clauses otherwise. [FACT-CONFIRM: Anthropic, Vercel, Supabase, Railway DPF status must be individually confirmed before publish — Anthropic's DPF certification could NOT be confirmed on 2026-07-09; the DPA transfer architecture is a lawyer sign-off item.]
  • We assess transfer risk for our subprocessors and impose contractual safeguards down the chain.

9. How long we keep personal data

DataRetention
Account dataFor the life of your account, then deleted within [FACT-CONFIRM: deletion window on termination] of account closure, except as noted below
Billing recordsAs required by tax and accounting law (typically 5–7 years)
Agent conversations and brand memoryFor the life of your account — this is your accumulated working memory; you can ask us to delete specific content
Recipient data (contacts, engagement, send history)For the life of your account, on your instructions; on termination, deleted or returned per the DPA within [FACT-CONFIRM: window]
Suppression records (unsubscribes, complaints, bounces)Retained even after account closure and even if other data is erased. Keeping the unsubscribe record is what guarantees the person stays unsubscribed — deleting it would risk unlawful email to someone who opted out. We keep the minimum needed for this purpose.
Downgrade to the free planWe keep all your data (“retain-all”) — nothing is deleted because you stopped paying; if you exceed free-plan limits, sending pauses but your data stays intact

10. Security

  • Passwordless sign-in (Google or magic link) — no password database to steal.
  • Card payments handled entirely by Stripe — no card data in our systems.
  • Data encrypted in transit; tenant data logically isolated per customer. [FACT-CONFIRM: which specific security claims are provable today — encryption at rest, row-level security, access controls — align this list with the DPA security annex before publish]
  • Unsubscribe links are cryptographically signed so they cannot be forged or tampered with.

No internet service can promise perfect security. If a breach affects your personal data, we will notify you and the relevant regulators as required by applicable law.

11. Your rights

You can exercise any of these by emailing privacy@deloosh.com. We will verify your identity (usually by confirming control of your account email), respond within the timeframe the applicable law requires, and never charge a fee for a reasonable request. We will not discriminate against you for exercising your rights.

If you are in the EEA or UK (GDPR / UK GDPR): you have the right to access your personal data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent where processing is based on consent. You may also lodge a complaint with your national supervisory authority (or the ICO in the UK) — though we would appreciate the chance to resolve it first.

If you are in California or another US state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Texas, and others): you have the right to know/access the personal information we hold about you, delete it, correct it, and opt out of sale, sharing, and targeted advertising. We do not sell or share your personal information, so there is nothing to opt out of. You may appeal a refusal by replying to our decision, and Californians may also contact the California Privacy Protection Agency or Attorney General.

If you are in Australia: we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to and correction of your personal information. If you are unsatisfied with our response to a complaint, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).

If you are in Canada: you have rights of access and correction under PIPEDA, and may complain to the Office of the Privacy Commissioner of Canada.

Elsewhere: we extend the same core rights — access, correction, deletion — to everyone, regardless of where you live.

One honest caveat: we cannot delete suppression records (Section 9) — retaining your unsubscribe record is what keeps you unsubscribed, and we rely on legal obligation and compelling legitimate grounds to keep it.

If the data is about you but held for one of our customers (you are someone’s email subscriber): the customer who imported your data is responsible for it. Send us your request and we will pass it to them promptly and help them honour it — see Section 12.

12. Did you get an email sent with Deloosh?

If an email landed in your inbox with “Sent with Deloosh” in the footer, or links pointing to delooshmail.com, it was sent by one of our customers using Deloosh. Here is what you should know:

  • The sender is responsible for having your permission. They imported your address and control their list; Deloosh requires customers to declare where every contact came from and records it.
  • Unsubscribing works, permanently. Every email sent through Deloosh has an unsubscribe link. When you use it, the unsubscribe is recorded in a way the sender cannot undo — re-importing a list can never re-subscribe you.
  • What we hold about you: typically your email address, attributes the sender imported (like your name), which links you clicked in their emails, and your unsubscribe/complaint status. We hold it for the sender, not for ourselves, and we never sell it or use it to profile you across senders.
  • Want your data accessed or deleted? Contact the sender directly (the email’s From address), or email privacy@deloosh.com and we will route your request to them and assist. Deletion requests will not delete your unsubscribe record — that stays so you stay unsubscribed.
  • Think it’s spam? Email abuse@deloosh.com [FACT-CONFIRM: mailbox exists]. We enforce a permission-based Acceptable Use Policy against our customers and we act on complaints.

13. Children

Deloosh is a business tool for users aged 18 and over. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact privacy@deloosh.com and we will delete it.

14. Changes to this policy

When we change this policy, we will update the version and effective date at the top, keep prior versions available, and — for material changes — notify account holders by email or in-app notice at least 14 days before the change takes effect. Continued use after the effective date means the updated policy applies.

15. Contact us