Sign in Check my email

Privacy Policy

Last updated 2026-08-08

MailArrive checks whether email is set up correctly and reaches the inbox. To do that we handle some of your data. This page says exactly what we collect, why, who else touches it, and how to get rid of it. Plain English, no hedging.

Who we are

MailArrive is operated by Matano Enterprises LLC, a New Jersey limited liability company, trading as Matano IT Solutions. Contact us at privacy@mailarrive.com.

What we collect and why

DataDetail
Account detailsYour email address, name, and optionally your company and phone number. If you sign in with Google we receive your Google account identifier and email, never your Google password.
Why: To create and secure your account and to contact you about your account.
How long: Until you delete your account.
Emails you forward for analysisWhen you forward or submit a message for a scam, phishing, deliverability, or bounce check, we store that message including its headers and body while we analyze it. A bounce notification also contains the address you were writing to, which is somebody else's, so we treat these the same way we treat everything else you forward.
Why: To produce the report you asked for.
How long: The stored message and its raw copy are cleared once the report expires. You can delete any report yourself at any time.
Emails forwarded to our public Scam Check addressAnyone can forward a suspicious message to our public scan address without an account. We store that message, its headers and body, and the address it was sent from. The message you forward usually contains someone else's details, because that is the nature of a scam, and we treat it accordingly.
Why: To produce the verdict you asked for, to email it back to you, and to limit how many free checks one address can run per day.
How long: The message and its raw copy are deleted after 30 days. If you open an account with the same address, the checks you already ran move into that account and are then kept like the rest of your reports, until you delete them or close the account. We may keep the verdict and an anonymised description of the scam pattern for longer, to warn other people about it, with names, addresses and any identifying detail removed first. We do not add you to any mailing list for using it.
Email auditsWhen an audit is run for a business, test messages are sent to an address we give out and grouped under that piece of work. We store the name of the audit, the address it takes mail at, and any report link created from it. The messages themselves are covered by the row above. Test messages are usually sent by somebody at the business being audited rather than by the account holder, so they are somebody else's mail and are treated that way.
Why: To keep the messages of one investigation together and to produce a report that can be handed to the business.
How long: Until the account is closed. Each report link also carries its own expiry date and stops working then, and can be withdrawn before that.
DMARC reports for your domainsWhen you point a domain's DMARC record at us, mailbox providers such as Google, Microsoft and Yahoo send us daily reports about mail claiming to come from that domain. These contain sending IP addresses, message counts, and whether each source passed authentication. They describe senders, which may include third parties you use and anyone spoofing you; they never contain message content, subjects, or recipient addresses.
Why: To show you who is sending as your domain and whether it is passing, which is the whole point of DMARC monitoring.
How long: Per-source detail for 90 days, the summary totals for 400 days so year-on-year trends still work, and the original report file for 30 days. You can delete a domain at any time, which removes its reports with it.
Domains and addresses you checkDomains, email addresses, IP addresses and links you submit to our tools, plus the results. When you check whether an email address is valid we read public DNS only. We never send a message to an address you check, and we never connect to somebody else's mail server to ask whether their mailbox exists.
Why: To run the check, show your history, and power monitoring and alerts.
How long: Until you delete them or close your account.
Signatures you buildThe name, title, company, phone, website, social links and logo you put into Signature Studio, and any logo you upload.
Why: To build, render, save and re-install your signature.
How long: Until you delete the signature or close your account.
Contact details when you get in touchWhen you request a report, forward a message to our public Scam Check address, or otherwise contact us, we record your email address and which of those you used.
Why: To reply to you, to understand which parts of the service people arrive through, and to follow up about business enquiries.
How long: We keep this contact record after an account is closed, because it is a record of you contacting us rather than part of the account. Ask us to remove it and we will.
The shape of scams people reportWhen somebody forwards us a suspicious message we keep a description of the scam itself: the verdict, the subject line, and the domain the message claimed to come from. We do not keep the full sending address, because the part before the @ is often a real person being impersonated. Nothing in this record says who reported it, and it cannot be joined back to them.
Why: So we can see which scams are circulating and warn other people about them.
How long: Indefinitely. It describes a scam rather than a person.
Payment detailsYour plan and subscription status, plus identifiers from our payment processor. We never see or store your card number.
Why: To run your subscription.
How long: As long as required for tax and accounting.
Product usageWhich pages and features are used, which templates and options are chosen, and where visits came from (campaign tags and referring site). Some of this is our own, stored here. We also run Google Analytics, so Google receives the page you viewed and how you arrived. Report and inbox addresses are redacted before they are sent, so a shared report link never reaches Google. Signature Studio analytics are stored with a random per-visit identifier and are not linked to your account.
Why: To understand what works and improve the product.
How long: Aggregated over time.
Security and delivery logsStandard server logs including IP address, browser type, and timestamps.
Why: To keep the service running, prevent abuse, and enforce rate limits.
How long: A short period, then discarded.
About emails you forward to us. A message you send for analysis may contain private or sensitive information. We only use it to produce your report, we do not read it for any other purpose, we never sell it, and reports are deleted automatically when they expire. If a message is highly sensitive, consider whether you need to send it at all.

What we do not do

Cookies

We set one cookie to keep you signed in. It is required for the site to work, it is not used for advertising, and it is not shared with anyone. Google Analytics sets its own cookies to recognize a returning browser; a content blocker or Global Privacy Control stops those, and nothing on the site breaks. Some pages also use your browser's own storage to remember a draft or a random per-visit identifier used for anonymous product analytics; that never leaves your browser except as described above.

Who else processes your data

We keep this list short on purpose. Each of these is a service we depend on to run MailArrive.

ServiceWhat it doesWhere
CloudflareHosting, database, storage, and DNS lookups. All service data lives here.Global
Anthropic (Claude)AI analysis. Content you submit for analysis, and website content we read to detect your brand, is sent here to be processed. Used to generate your result, not to train models.United States
StripePayment processing and subscriptions. Card details go directly to Stripe.United States
ResendSending our outbound email, such as alerts and account mail.United States
GoogleTwo separate things. Optional sign-in with Google, only if you choose it. And Google Analytics on our pages, which tells Google which page you viewed, roughly where in the world you are, and how you arrived. We have turned off the setting that would join that to Google's cross site advertising profiles, and we strip everything but campaign tags out of the address before it is sent, so tokens in a link never reach them. Turn on Global Privacy Control and none of it runs.United States
SoroWhere we write the articles on our blog. We fetch the posts from them on our own servers and serve you the finished page, so your browser never contacts them and they receive nothing about you.United States
WhatsApp (Meta)Only if you choose to message us on WhatsApp. Meta operates that service and can see that you contacted us and what you sent. Every other way of reaching us avoids them entirely.United States
Spamhaus, RIPE, ARINReputation and network lookups for domains and IP addresses you ask us to check.Global

Your choices

Depending on where you live you may have additional rights over your data. Ask us and we will honor them rather than argue about which law applies.

Children

MailArrive is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.

Changes to this policy

We update this page when the product changes, not on a schedule. If a change materially affects how we handle your data, we will say so on this page and, where it matters, by email. The date at the top always reflects the current version.

Contact

Questions, requests, or complaints: privacy@mailarrive.com. A real person answers.