← pombus.com

Privacy Policy

Effective date: September 25, 2026
Last updated: September 25, 2026

This Privacy Policy explains how Willian Clayton de Almeida, an individual (natural person) domiciled in Brazil, CPF 277.866.058-51, with correspondence address provided upon request to dpo@pombus.com, operating under the trade name Pombus ("Pombus", "we", "us"), collects, uses, shares, and protects personal data in connection with the Pombus service at pombus.com (the "Service"). Pombus is operated by an individual developer, not by a company.

Pombus is established in Brazil and processes personal data in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law No. 13.709/2018 — "LGPD"). The LGPD applies in full to Pombus: the exclusion in its Article 4, I, covers only natural persons processing data for exclusively private, non-economic purposes, and Pombus processes data for economic purposes. Where the Service is used by, or to communicate with, individuals in the European Union or United Kingdom, we also apply the principles of the EU General Data Protection Regulation ("GDPR") to the relevant processing.

1. Our Two Roles: Controller and Operator

Pombus plays two distinct roles, and this distinction determines who is responsible for the data and what this Policy covers.

1.1. Pombus as Operator / Processor — Customer Email Content

When our Business Customers (businesses and professionals using the Service in the course of their activity, together with the people and AI agents acting under their accounts) send, receive, and store email through their mailboxes, the Customer decides which personal data is processed and why. This is so whether the mailbox is at an address on our shared domain (for example, name@pombus.com) or on a domain the Customer owns and has verified. In relation to that email content and the personal data of the Customer's own correspondents, the Customer is the controller and Pombus acts as operator (LGPD) / processor (GDPR).

Mailboxes on pombus.com. Pombus owns and authenticates the pombus.com domain, but a mailbox such as name@pombus.com is provisioned to a Customer, and that Customer, its people, and its agents decide what is sent, received, and kept in it. The mail in that mailbox is the Customer's content, and owning the domain does not make Pombus the controller of it. If you received a message from a pombus.com address, the sender is the Customer that holds that mailbox, not Pombus, and we will direct your request to that Customer or forward it to them.

For this category, Pombus processes data only on the Customer's documented instructions, as set out in this Policy, the Terms of Service, and the applicable Data Processing Agreement ("DPA"). If you are an individual whose personal data appears in email processed through the Service, and you are not a Pombus Customer, please direct privacy requests to the relevant Customer (the controller); we will assist that Customer as their operator.

1.2. Pombus as Controller — Account, Billing, and Operational Data

For personal data we collect to create and run Customer accounts — such as account and contact details, billing data (the Service is paid), the mailbox names assigned on pombus.com, API-key metadata, authentication data, send and event logs, and the reports that third-party mail systems send us about the pombus.com domain as a whole (see Section 2) — Pombus is the controller and determines the purposes and means of processing. Sections 2 through 13 of this Policy describe that controller processing in detail.

1.3. Mailboxes Used by Individuals for Personal Purposes (Consumers)

If you use a mailbox as a Consumer, for personal, family, or household purposes, the LGPD does not treat you as a controller (Article 4, I), and the Data Processing Agreement does not apply to you. Pombus remains fully subject to the LGPD for that processing, because Pombus carries it out for economic purposes, and is the agent responsible for it. We process the content of your mailbox solely to provide, secure, and support the Service on your instructions: receiving, storing, displaying, sending, and deleting your messages as you, or the agents you authorize, direct. The legal bases are the performance of our contract with you (LGPD Article 7, V) and, for security and abuse prevention, our legitimate interest (Article 7, IX). Your messages are private communications protected by Article 5, XII, of the Federal Constitution and Article 7, I to III, of the Marco Civil da Internet, and we treat them accordingly: we do not read them except in the narrow situations described in Section 3.2, we do not sell them, we do not use them to train artificial-intelligence models, you can export or delete them at any time, and we delete them when your account closes (Section 8).

2. Personal Data We Process

CategoryExamplesOur role
Email contentMessage body, attachments, headers, sender and recipient addressesOperator (Business Customer is controller); for Consumers' mailboxes, see Section 1.3
Domain identityPombus Addresses (name@pombus.com) provisioned to the Customer's account and their status; Customer-verified sending domains and their DKIM/SPF/DMARC configurationController
Shared-domain reportsDMARC aggregate and failure reports and TLS reports (TLS-RPT) for pombus.com; abuse and postmaster reports concerning pombus.com addresses; mail addressed to unassigned, reserved, or reclaimed pombus.com addressesController
Account dataName, business name, contact email, login credentials, names of the people given access to the account's mailboxesController
Billing dataBilling contact, payment identifiers, transaction recordsController
API keysKey identifiers, scopes, creation and rotation metadataController
Web application dataSession data and user preferences (stored in Cloudflare D1); avatar images (stored in Cloudflare R2)Controller
Send logAppend-only, timestamped records of sends, tied to API key or web session and mailboxController
Access logsRecords of access to the website, web application, and API (for example, IP address, date and time)Controller
Event dataBounce, complaint, and delivery notifications (received via Amazon SNS)Controller
Suppression listRecipient addresses suppressed due to bounces or complaintsController (independent — abuse prevention and recipient protection)

We do not intentionally collect special categories of data (LGPD dados sensíveis / GDPR Article 9 data). Customers must not route special-category data through the Service unless they have established a valid lawful basis and have agreed appropriate terms with us in the DPA.

3. Purposes and Legal Bases

3.1. Controller Processing (Account/Billing/Operational)

PurposeLGPD legal basis (Art. 7)GDPR legal basis (Art. 6)
Provide, operate, and maintain the ServicePerformance of a contract (Art. 7, V)Contract (Art. 6(1)(b))
Bill and collect paymentPerformance of a contract; legal obligation (Art. 7, V and II)Contract; legal obligation (Art. 6(1)(b), (c))
Authenticate access and secure API keysLegitimate interest; contract (Art. 7, IX and V)Legitimate interests; contract (Art. 6(1)(f), (b))
Detect, prevent, and investigate abuse, fraud, and security incidentsLegitimate interest (Art. 7, IX)Legitimate interests (Art. 6(1)(f))
Protect the authentication and reputation of the shared pombus.com domain (including handling DMARC, TLS, and abuse reports and mail to unassigned addresses)Legitimate interest (Art. 7, IX)Legitimate interests (Art. 6(1)(f))
Maintain append-only send logs and event logsLegitimate interest; legal obligation (Art. 7, IX and II)Legitimate interests; legal obligation (Art. 6(1)(f), (c))
Comply with legal, tax, and regulatory obligationsLegal obligation (Art. 7, II)Legal obligation (Art. 6(1)(c))
Communicate service, security, and administrative noticesContract; legitimate interest (Art. 7, V and IX)Contract; legitimate interests (Art. 6(1)(b), (f))

Where we rely on legitimate interest, we have assessed that our interest (operating a secure, abuse-resistant email service) is not overridden by the rights and freedoms of the data subject, and you may object as described in Section 9.

3.2. Operator Processing (Customer Email Content)

For email content of Business Customers, the legal basis is determined by the Customer as controller. Pombus processes such data solely to deliver, receive, store, authenticate, log, and secure the Customer's mail in accordance with the Customer's instructions and the DPA. For Consumers' mailboxes, Section 1.3 states the legal bases. In both cases, Pombus does not read message content, with two exceptions: automated scanning for spam, malware, and security threats (including by Amazon SES), and access by authorized personnel to the specific messages reasonably necessary to investigate an abuse report, a security incident, or a legal request, as described in Section 5.3 of the DPA. Disclosure of message content to authorities requires a court order where the Marco Civil da Internet so provides (Articles 7, III, and 10, §2). Pombus does not use email content to train artificial-intelligence models.

4. How We Collect Data

5. Sub-processors and Infrastructure

Pombus relies on the following sub-processors to provide the Service. They process personal data on our behalf (and, for Business Customers' email content, on the Customer's behalf as sub-operators), under contractual data-protection terms. The table reflects the actual architecture of the Service: mail moves through Amazon SES and Cloudflare, and is stored at rest only on a server that Pombus operates.

Sub-processorWhat it doesPersonal data involvedLocation
Amazon Web Services — Amazon SESSends outbound email and signs it with DKIM; scans for spam and malwareFull message content and metadata, transiently, while in transitUnited States (us-east-1)
Amazon Web Services — Amazon SNSDelivers bounce, complaint, and delivery notificationsEvent metadata, including recipient addressesUnited States (us-east-1)
Cloudflare — Email Routing and WorkersReceives inbound email at the edge for pombus.com and for Customer Domains whose MX records point to Cloudflare, and passes it to our storage server through a Worker that does not keep message bodiesFull message content and metadata, transientlyGlobal edge network, may include the United States and other regions
Cloudflare — Workers, Pages, DNS, TLS, DDoS protectionServes the website, the web application, and the APIAPI requests and responses, which may contain message content, transientlyGlobal edge network
Cloudflare — D1Stores web application data: session and user preferencesAccount data only; no message contentCloudflare global network; no location restriction configured
Cloudflare — R2Stores user avatar images and encrypted backups of the message store (Section 10.2)Account data (avatars); encrypted backups of message content and metadata, which Cloudflare cannot decryptCloudflare global network; no location restriction configured
HostingerHosts the server on which message content, attachments, and message metadata are stored at rest, inside an encrypted volume (Section 10). The provider has physical access to the machine but does not receive the encryption keyFull message content and metadata at rest, in encrypted formBrazil

Our payment processor, Stripe, processes billing data only and never sees email content. The current list of sub-processors, with the transfer mechanism for each, is published at subprocessors.html. We update that page at least 30 days before a new sub-processor starts processing personal data, and we notify Business Customers by email to the Account owner, as provided in Section 8.4 of the DPA. The AI model providers and other tools that a Customer connects to its mailboxes are not Pombus sub-processors (Section 6).

6. Data Your AI Agents Receive

6.1. What is delivered. When a Customer connects an AI agent or another application to a mailbox through the API, webhooks, or an MCP (Model Context Protocol) server or tool, Pombus delivers the mailbox data that the agent requests or that the Customer has configured to be pushed to it. This can include the sender, recipients, subject, body, attachments, and metadata (such as dates, message and thread identifiers, and delivery events) of the messages in that mailbox. Pombus delivers this data only to the endpoint, application, or tool that the Customer has chosen and authorized, only within the scope of the API key used, and only for as long as that key or connection remains active. The Customer can revoke a key or remove a webhook at any time.

6.2. The Customer's AI provider is the Customer's choice. The AI model provider, agent framework, hosting environment, or other service that receives this data at the Customer's request is selected by the Customer and processes the data under the Customer's own arrangements and that provider's terms and privacy policy. That provider is not a Pombus sub-processor, and Pombus does not control, monitor, or take responsibility for how it processes the data once delivered. For Business Customers, the Customer, as controller, is responsible for having a lawful basis for that onward processing, for the international transfers it involves, and for its own agreements with those providers. For Consumers, the choice of which agent or provider to connect, and what it may do with your mail, is yours.

6.3. No model training by Pombus. Pombus does not use the content of any email, attachment, or message metadata to train, fine-tune, or evaluate artificial-intelligence models, whether its own or anyone else's.

7. International Data Transfers

7.1. Because email is sent through Amazon SES in the us-east-1 region (United States), inbound routing and web delivery run on Cloudflare's global edge network, and message content is stored at rest on a server at Hostinger in Brazil, personal data — including email content and event data — is transferred internationally, including to the United States. Data at rest remains in Brazil.

7.2. Pombus relies on the transfer mechanisms permitted under LGPD Articles 33 and 35 (which may include ANPD-approved standard contractual clauses, adequacy, or specific safeguards) and, for GDPR-scope data, on Standard Contractual Clauses (SCCs) and any supplementary measures required. Personal data at rest is stored in Brazil. Transfers to the United States occur in transit through Amazon Web Services and Cloudflare, under their standard data processing terms, which include the EU Standard Contractual Clauses. Pombus will adopt the ANPD standard contractual clauses as these providers make them available.

7.3. By using the Service to send and receive mail, Customers instruct Pombus to carry out these transfers as an inherent part of the Service. Customers remain responsible, as controllers, for ensuring a valid basis for the international transfer of their own recipients' data, including transfers to the AI providers they connect under Section 6.

8. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, or as required by law. The following retention periods apply:

DataRetentionBasis
Account and billing dataDuration of the account + 5 years after closureTax and commercial record-keeping obligations
Email content — Business Customers (as operator)Per Customer configuration and the DPA. On termination, the Customer has a 30-day export period; the content is then deleted from the production systems within 30 days after that period ends. Copies in backups are not deleted individually and expire automatically at the end of the backup retention window (30 days)Customer instruction
Email content — Consumers (Section 1.3)Until you delete it or your account closes. After closure, the 30-day export period applies, and the content is deleted within 30 days after it ends; backup copies expire automatically at the end of the backup retention window (30 days)Contract
Encrypted backups of the message store30 days, after which they are deleted automatically; during that window they are protected by object lock and cannot be altered or deletedSecurity and disaster recovery
Web application session and preference data; avatarsDuration of the account; sessions expire after a period of inactivityContract
Send log (append-only)Up to 24 monthsSecurity, abuse investigation, legal defense
Access logs12 monthsSecurity and legal orders; standard of Marco Civil Art. 15 (mandatory for legal-entity providers, applied by Pombus as policy)
Event data (bounce/complaint/delivery)12 monthsDeliverability and abuse prevention
Suppression listWhile the account is active. After an account closes or a deletion request is honored, the address is kept only in hashed form, so that it is not mailed again (DPA, Section 10.4)Abuse prevention and protection of the recipient's objection
Shared-domain reports (DMARC, TLS, abuse, postmaster)12 monthsDomain reputation and abuse prevention
Mail to unassigned, reserved, or reclaimed pombus.com addressesDiscarded at delivery and not storedDomain operation; minimization

Where retention is not fixed by law, we delete or anonymize data when it is no longer needed. The send log is append-only and is kept for its defined period because its integrity is the point; entries are not edited or selectively deleted.

9. Data Subject Rights

Under the LGPD (Art. 18) and, where applicable, the GDPR, data subjects have the right to:

To exercise these rights regarding data for which Pombus is the controller — including your account data, the send-log and suppression-list entries that contain your address, and, if you are a Consumer, the content of your own mailbox — contact our Data Protection Officer (Encarregado) at dpo@pombus.com. For data processed as operator (Business Customers' email content), we will forward requests to the relevant Customer (controller) and assist them in responding. If you are not a Customer and your address appears in our send log or suppression list, you may address requests, including a request to stop receiving mail through the Service, to the DPO directly.

Response time. The DPO responds to requests, including opt-out and objection requests, within 15 days of receipt, in line with Article 19 of the LGPD. Where a simplified confirmation is requested, we respond immediately where possible.

You also have the right to lodge a complaint with the Brazilian National Data Protection Authority (ANPD) or, for GDPR-scope processing, with your local supervisory authority.

10. Security

10.1. Measures. Pombus maintains technical and organizational measures appropriate to the risk, including: least-privilege, scoped API keys issued per agent; domain authentication (DKIM, SPF including a custom MAIL FROM domain, and DMARC), maintained by Pombus for the shared pombus.com domain and required of Customers for their own verified domains; append-only, timestamped send logging; automatic suppression of addresses that bounce or complain; bounce, complaint, and delivery events received through Amazon SNS; and encryption in transit. TLS protects the website, the web application, and the API, and HTTPS is mandatory, through Cloudflare. For mail transport, TLS is used where the other mail server supports it, and Pombus publishes an MTA-STS policy for pombus.com at https://mta-sts.pombus.com/.well-known/mta-sts.txt, currently in testing mode for the pombus.com mail exchangers (*.mx.cloudflare.net), with TLS reporting (TLS-RPT) sent to dmarc@pombus.com; Pombus intends to move the policy to enforce mode once the reports show clean delivery.

10.2. Encryption at rest. Message bodies, attachments, and message metadata are stored in a SQLite database and a compressed, content-addressed blob store located inside a LUKS-encrypted volume (full-volume encryption at rest) on a server that Pombus operates at Hostinger in Brazil, within an isolated container. The volume is unlocked on the server itself by keyfile/TPM, under Pombus's exclusive control, and the hosting provider does not receive the key. Inbound mail that arrives through Cloudflare Email Routing is passed to that server by a Cloudflare Worker that does not keep the message body. Cloudflare stores user avatars and encrypted backups (R2) and web-application session and preference data (D1), and Amazon SES handles mail in transit; those providers encrypt the data they hold at rest under their own controls. Backups of the message store are made daily, encrypted (GPG, AES-256) with a passphrase kept off the server, and stored in Cloudflare R2 under object lock, which keeps them immutable during their 30-day retention window, after which they are deleted automatically.

10.3. Abuse controls. Pombus also applies or may apply additional abuse controls, including sending limits per account according to the plan, per-message recipient caps, rate-limiting, review and automated pausing of a mailbox or account at published bounce and complaint thresholds, and an operator kill-switch, as described in the Acceptable Use Policy; on the shared pombus.com domain these controls are applied strictly and per mailbox, because one mailbox's behavior affects the deliverability of every other.

10.4. Incidents. No method of transmission or storage is fully secure. If a security incident affects personal data for which Pombus is the controller (Section 1.2, and Consumers' mailboxes under Section 1.3), Pombus will notify the ANPD and the affected data subjects as required by LGPD Art. 48 and ANPD Resolution CD/ANPD No. 15/2024 (three business days) and, for GDPR-scope data, the competent supervisory authority and data subjects as required by GDPR Articles 33 and 34. If the incident affects a Business Customer's email content, which Pombus processes as operator, Pombus will notify that Customer within 48 hours as provided in Section 12 of the DPA, and the Customer, as controller, decides on and makes the notifications to authorities and data subjects.

11. Cookies and Tracking

The Service uses minimal cookies, limited to what is strictly necessary to operate the site and the authenticated application (for example, session and security cookies). We do not use analytics or tracking cookies. We do not use the Service to serve third-party advertising.

12. Children's Data

The Service is offered to businesses and to adults. It is not directed to children or adolescents, and individuals must be at least 18 years old to create an account. We do not knowingly collect personal data from children or adolescents, and we close accounts found to belong to them.

13. Changes to This Policy

We may update this Policy to reflect changes in the Service, our sub-processors, or applicable law. Material changes will be notified through the Service or by email, and the "Last updated" date will be revised.

14. Contact and Data Protection Officer (Encarregado)

Controller: Willian Clayton de Almeida, an individual, trading as Pombus — CPF 277.866.058-51 (supplier identification under Article 2, I, of Decree No. 7,962/2013)
Correspondence address: provided upon request to dpo@pombus.com
Data Protection Officer (Encarregado / DPO): Willian Clayton de Almeida, dpo@pombus.com
General privacy contact: privacy@pombus.com
Abuse reports: abuse@pombus.com