MailQuell

Privacy Policy

Effective October 9, 2026

1. Who is responsible

MailQuell, Agadir, Morocco, operates MailQuell and is the controller of your account data. Privacy questions: privacy@mailquell.com.

For the email lists you upload, you are the controller and we act as your processor: we handle that data only to check it for you, under our Data Processing Agreement.

2. What we collect

  • Account: name, email, company and phone (optional), password (stored only as a scrypt hash), language and notification preferences.
  • Security: IP address, browser/device description and time of each sign-in attempt, active sessions, and your two-factor secret (encrypted).
  • Lists and results: the addresses (and optional name/company columns) you upload or send through the API, and the verification results.
  • Usage: credit history, tasks, API request logs (endpoint, status, time, IP), webhook deliveries.
  • AI Lead Qualification: the profiles you save (what you sell, your ideal customer, your criteria), the contacts you submit, and the result for each company.
  • Billing: Paddle.com processes payments as Merchant of Record. We receive your customer ID, plan, amounts and invoice numbers — never your full card details.
  • Referrals: if you joined through someone's invite link, we record who invited you. They see your address in masked form (e.g. j***@gmail.com), when you joined, and whether you became a paying customer, never your name or usage.
  • Support: messages you send through the contact form, the live chat or by email. For the live chat we also keep your IP address (abuse protection) and, if you are not signed in, the email address you choose to leave. Chat conversations are deleted 180 days after the last message.

3. How verification works

To check a mailbox, our server connects to the recipient domain's mail server and asks whether the address exists, then disconnects. No email is sent to the addresses you check. The recipient's mail server sees our server's IP address and domain name, not yours.

3b. How AI Lead Qualification works

When you run an AI qualification, our server reads the public home page and About page of each company domain in your list (respecting robots.txt) and sends that text, together with your profile, to TypeSafe (Jev model) (United States). The email addresses and names in your list are never sent, and email addresses printed on a website are removed from its text first; "team" pages are not read. The provider processes it under a data processing agreement with the EU Standard Contractual Clauses, keeps nothing (zero data retention) and does not train its models on it. Results are automated estimates based only on what the website says.

3c. MailQuell for Chrome

The browser extension only reads the recipient addresses of a message you are writing in Gmail, and the addresses you select or check yourself. It never reads your messages, their content or your contacts. Each address is sent to our server to be checked, exactly as if you checked it in the web app, and the result is kept in your browser for 30 days so the same address is not charged twice. The extension stores, in your browser only, the key that connects it to your account and those results. Disconnecting it, or revoking its key in Developer Hub, stops it; removing the extension deletes what it stored.

4. Why we use it (legal bases)

  • To provide the service and your account — performance of our contract with you.
  • To keep accounts secure and prevent fraud and abuse (e.g. multiple free accounts, spam lists) — our legitimate interests.
  • To keep billing and tax records — legal obligation.
  • To send service emails (verification codes, password resets, security alerts, task notifications you enable). We don't send marketing email.

5. Cookies and what we keep in your browser

We only keep what the site needs to work or what remembers a choice you made: no advertising, no tracking across sites, nothing shared with other companies. That is why there is no cookie banner. The full list:

NameTypeWhyHow long
mq_refreshCookieKeeps you signed in (http-only, only sent to our sign-in endpoint).30 days, renewed while you use the app; deleted when you sign out
mq_oauthCookieProtects a sign-in with Google or Microsoft while you are on their page.10 minutes
mq_session_hintLocal storageRemembers that you were signed in, to show a loading screen instead of the home page. Holds no secret.Until you sign out
mq_languageLocal storageThe language you chose.Until you change it or clear your browser
mq_theme, mq_modeLocal storageThe colour theme and dark mode you chose.Until you change them or clear your browser
mq_refLocal storageThe invite code from a referral link, so the invitation counts when you sign up.30 days
mq_couponLocal storageA discount code from a promotion link, sent with your next checkout.30 days
mq_chat_tokenLocal storageA random ID for the live chat when you are not signed in, so you see your conversation again.Until you clear your browser
mq_chat_hiddenLocal storageRemembers that you hid the chat bubble.Until you show it again
mq_announcement_closedLocal storageThat you closed the announcement bar, so it stays closed until the announcement changes.Until you clear your browser
mq_review_promptLocal storageWhether you chose "Later" or "Don't ask again" on the invitation to review us on Trustpilot.Until you clear your browser
mq_list_serviceLocal storageThe list service tab you last opened (Mailchimp, Brevo, MailerLite).Until you clear your browser
mq_team_inviteSession storageA team invitation from an email link, while you sign in to accept it.Until the tab is closed
mq_redeemSession storageA lifetime deal code from a link, while you sign in to redeem it.Until the tab is closed
mq_extension_connectSession storageThe MailQuell for Chrome connection request, while you sign in to allow it.Until the tab is closed

The sign-up form and the chat may show a Cloudflare Turnstile check against bots, and Cloudflare, which protects the site, may set a short-lived security cookie (such as __cf_bm) to tell people from bots. When you open checkout, Paddle.com may set its own cookies needed for payment and fraud prevention. Our fonts are served from our own site, not from Google. You can delete all of this at any time in your browser settings; you will then be signed out.

6. Who we share it with

We don't sell personal data. We use these processors, only as needed to run the service:

  • OVHcloud — servers and database (the United Kingdom).
  • Cloudflare (Cloudflare Pages) — delivers the website pages (processes visitors' IP addresses).
  • Paddle.com — payments, tax, invoices (as an independent Merchant of Record).
  • Mailjet (Sinch) — delivery of service emails (France (EU)).
  • TypeSafe (Jev model) — AI Lead Qualification only: receives public company website text and your profile, never the addresses or names in your list (United States).
  • Cloudflare Turnstile — bot protection on the sign-up form (processes your IP and browser signals).

The full list, with what each provider receives, is on the DPA & Sub-processors page. We may disclose data if required by law or to protect our rights, users, or the public.

7. How long we keep it

  • Uploaded lists: deleted as soon as their verification task finishes.
  • Per-address results: deleted automatically 20 days after the task finished (sooner if you delete the task). Only anonymous totals remain.
  • AI Lead Qualification: contacts and results 20 days after the run ended (sooner if you delete it); saved profiles until you delete them.
  • Webhook delivery records: 20 days. API request logs: 90 days. Sign-in history: 1 year.
  • Account, security and usage records: while your account exists.
  • Invoices and payment records: as long as tax law requires (up to 10 years), even after account deletion.
  • Deleting your account (Account & Security → Delete) removes your account, lists, results, API keys and sessions from our live database; backups roll over within 30 days.
  • To stop the same mailbox collecting the one-time welcome and referral credits again, we keep a keyed hash of your email address (it can't be turned back into the address) for 3 years, even after account deletion.
  • Free email checker: a keyed, daily-changing hash of your network address, for 2 days, to apply the daily limit. The checked address is not stored.

8. Security

HTTPS everywhere, scrypt-hashed passwords, optional TOTP two-factor authentication with encrypted secrets, hashed API keys, per-account rate limits, and an audit log of every administrative action. No system is perfectly secure; we will notify you and the relevant authorities of a breach as the law requires.

9. International transfers

Your data is stored in the United Kingdom. Our processors may handle data in other countries; where required we rely on appropriate safeguards such as standard contractual clauses. AI Lead Qualification sends public company website text (never the addresses in your list) to TypeSafe (Jev model) in the United States under standard contractual clauses.

10. Your rights

You can access and correct your data in the app, download a complete copy of it at any time (Account & Security → Download my data), export your results (Tasks → Download), and delete your account. You can also ask us to restrict or object to processing, or to erase data, by writing to privacy@mailquell.com. We reply within 30 days.

You may complain to a data-protection authority — in Morocco the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel), or the authority in your EU/UK country of residence.

If someone on a list checked by one of our customers contacts us, we will refer them to that customer, who controls that data.

11. Children

MailQuell is a business tool and not intended for anyone under 18.

12. Changes

We'll post updates here and notify you of material changes by email or in the app. See also our Terms of Service.

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders and provides all customer service inquiries and handles returns.