finemail

LEGAL

Privacy Policy

Last updated: 2026-07-23. FineMail is a Fine Structure product and shares its account system. The Fine Structure Privacy Policy applies to your account. This page adds what is specific to FineMail: how the email service itself handles data.

What FineMail processes

To provide agent email, FineMail processes:

  • Account context. Your Fine Structure account identity and the agents you operate, used to scope every inbox and API call to you.
  • Email content. Messages sent and received through your agent inboxes, including subjects, bodies, headers, recipients, attachments, and thread relationships. This content is stored so you and your agents can read, search, and reply to it.
  • Security signals. SPF, DKIM, and DMARC results, allow/block rules, phishing heuristics, prompt-injection flags, and quarantine state, computed to protect you from malicious mail.
  • Operational logs. API requests, delivery events, and webhook deliveries, kept for security, debugging, and abuse prevention.

How email content is used

Your message content is used to operate the service: storing, indexing, delivering, and displaying mail, and computing the security signals described above. Inbound email may be processed by automated classification to flag phishing and prompt-injection risks. Message content is not sold and is not used for advertising.

Delivery providers and infrastructure

FineMail relies on service providers to operate:

  • Amazon Web Services (SES). The primary email sending and custom-domain verification path. Outbound messages are transmitted through SES.
  • Hosting infrastructure. FineMail runs on Fine Structure servers, and traffic to finemail.app is delivered through Cloudflare, which processes IP addresses and request data for security and delivery.
  • Webhooks you configure. If you create a webhook, event payloads are sent to the endpoint you chose. That endpoint's handling of the data is your responsibility.

Cookies and local storage

finemail.app does not set tracking, analytics, or advertising cookies. Signing in stores an authentication token in your browser's local storage so your session persists; dismissing the cookie notice is also remembered in local storage. Cloudflare may set strictly necessary security cookies. If we ever add non-essential cookies, this policy will be updated first and you will be asked for consent.

Retention and deletion

Email content is retained while your account is active so your inboxes keep working. Deleting messages, inboxes, or your Fine Structure account removes the associated content from the live service, after which residual copies are cleared from operational backups on their normal cycle. Operational logs are kept for a limited period for security and debugging and then discarded.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, including under the EU GDPR and the Israeli Privacy Protection Law. Most data is directly accessible and deletable inside the FineMail console. For anything else, contact the operator through finestructure.ai and we will respond.

Changes

We may update this policy from time to time. The date above shows when it was last updated. Material changes will be reflected on this page before they take effect.