Privacy
What happens to your email.
Draft, September 2026. This page will be reviewed before the public launch.
What leaves your device
When you ask for a draft, the brief, the selected text, the thread you pasted and any attachments go to the mailpen API over HTTPS, together with your token. Nothing is sent before you ask, and nothing is sent anywhere else. The web app loads no analytics and no third-party scripts.
Model providers
The API calls language models through OpenRouter. Every call is made with data collection turned off, so providers may not train on your text. You can switch on zero data retention per request, which limits the choice to providers that keep nothing.
What we store
By default, nothing about the content of your email. The API keeps metadata for each request: the route, the identity, the model, timing and token counts. Content is stored only when content storage is switched on for your account, which is off unless you turn it on.
What it learns
Your style profile holds patterns, not emails: greeting and sign-off, sentence length, tone, habits and a handful of short example emails you provided. You can read it and change every line of it in the app.
Your email is data, not instructions
Thread text and attachments are handed to the model as reference material and marked as such. An email that tells the model to do something is not obeyed.
Access and limits
Access uses bearer tokens, stored hashed on our side. Requests are capped at 10 MB and rate limited per token.
The waitlist
The waitlist stores your email address and the time you signed up, nothing else, until launch. We use it for one message when you can get in.
This browser
Your settings and API token are kept in this browser's local storage so you do not have to type them again. Clearing site data removes them.