Last updated: July 2026
Privacy Policy
This policy describes how eusend collects and uses data when you use our service.
1. Who we are
Eusend is a transactional email service operated from Norway. All infrastructure runs inside the European Union. You can reach us at privacy@eusend.dev.
2. Data we collect
Account data — when you sign up we collect your name, email address, and a hashed password.
Email sending data — when you use the API to send email, we process the recipient addresses, message content, and delivery metadata (timestamps, bounce codes, open and click events) on your behalf. This data belongs to you and is processed only to deliver the service.
Content you save — if you store contact lists (audiences), reusable templates, or broadcasts in your account, we keep that content so you can reuse it. It belongs to you and stays until you delete it or close your account.
Billing data — Polar is the seller of record for every purchase and handles payment itself. We store only a Polar customer and subscription ID; we never see or store your card number.
Usage data — we log API requests for rate limiting, debugging, and abuse prevention. These operational logs are retained for up to 90 days.
3. How we use your data
- To operate and improve the email delivery service
- To authenticate your account and secure your API keys
- To process billing and send receipts
- To detect and prevent abuse, spam, and fraudulent use
- To respond to support requests
We do not sell your data or use it for advertising.
4. Data storage and residency
All customer data is stored within the European Union, on infrastructure we operate ourselves:
- Germany (database, API servers, and email delivery — Hetzner, Nuremberg and Falkenstein)
- Finland (encrypted backups — Hetzner, Helsinki)
Your email sending data — recipient addresses, message content, and delivery events — is stored and delivered exclusively from these EU servers. A small number of external services support the platform around it; they are listed in the next section.
5. Sub-processors and third-party services
We keep the list of third parties short, and none of them store your email sending data. Here is exactly what each one does:
Hetzner (Germany) — hosts the servers listed above. All customer data lives on Hetzner machines in the EU that we manage.
Polar (Polar Software, Inc., USA) — the seller of record for all eusend purchases. Unlike the other services on this page, Polar is not our sub-processor: it sells the subscription to you in its own name and is an independent data controller for your billing data. It holds your name, email address, billing address, any tax identifier you provide, and your payment method. We receive only a customer ID, a subscription ID, and the plan you are on — never your card number. Polar is a US company, so your billing data is processed outside the EU/EEA — note that this applies to billing data only. The emails you send, your recipient lists, and your account content never reach Polar and remain on EU infrastructure as described above. Your billing data is governed by Polar's privacy policy, and you can exercise your data rights over it directly with Polar.
Cloudflare (USA) — provides DNS and sits as a security layer in front of our website and dashboard, so requests to those pages (including your IP address and request metadata) pass through Cloudflare's network in transit. Cloudflare also receives mail sent to our own operational addresses (such as abuse reports and bounce feedback) and runs the bot check on our signup form. Cloudflare does not store your email sending data, contacts, or database contents. Cloudflare is certified under the EU–U.S. Data Privacy Framework.
Vercel (USA) — serves the website and dashboard front-end. Requests to those pages are processed by Vercel; your email sending data is not stored there. Vercel is certified under the EU–U.S. Data Privacy Framework.
Better Stack (Czech Republic, EU) — monitors the uptime of our public endpoints. It only checks that our services respond and has no access to customer data.
6. Data retention
Sent-email logs and delivery events (opens, clicks, bounces) are retained for 30 days on every plan — 90 days on Scale — and then deleted automatically.
That window covers the whole email, not just the delivery record: the rendered message body and any attachments you sent are deleted on the same schedule, attachments included from the storage they are held in. Nothing is archived past it.
Content you save in your account — audiences and contacts, templates, and broadcasts — is kept until you delete it. Account data is retained while your account is active and deleted within 30 days of account closure — unless we are legally required to retain it — at which point your sending identity is torn down as well.
7. Your rights
You can at any time:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion of your account and associated data
- Export your data in a machine-readable format
To exercise any of these rights, email privacy@eusend.dev.
8. Cookies
We use a single session cookie to keep you logged into the dashboard. We do not use tracking or advertising cookies.
9. Changes to this policy
We may update this policy from time to time. We will notify registered users of significant changes by email. The date at the top of this page indicates when it was last updated.
10. Contact
Questions or concerns? Email us at privacy@eusend.dev.