MXcatch
Legal

Privacy policy

What MXcatch stores, where it lives, and who else touches it.

Last updated August 29, 2026.

Who we are

MXcatch is operated from the Netherlands by Sander Boersma. For anything in this policy, including data subject requests, write to hello@mxcatch.net.

For your account data we are the controller. For the email we receive on your behalf we act as a processor on your instructions — the instructions being the domains, aliases and actions you configure.

What we store

Account data

Configuration

Email

When mail arrives for one of your domains we store the message and everything derived from it: sender and recipient, subject, headers, plain-text and HTML bodies, and attachments. We also keep the raw .eml.

We do not read, scan, profile, or mine the content of your mail, and we do not use it to train anything. It is processed to carry out the actions you configured and to show you the message in your inbox. Nothing else.

Website analytics

We use a self-hosted Umami instance for aggregate page statistics. It sets no cookies, does not track individuals across sites, and the data never leaves our own infrastructure.

Where it is stored

Application servers and databases run in Germany. Message bodies and attachments are stored in object storage in Amsterdam. Both are inside the EU, and mail content is not replicated outside it.

How long we keep it

Messages, bodies and attachments are deleted once they pass your plan's retention window — 3 days on Free, up to 90 days on Scale. Deletion is automatic and applies to the stored bodies and attachments as well as the message record.

If you configure an archive action, the archived copy is kept until you remove it. That copy is under your control, not the retention schedule.

Delete your account and we remove your account data, domains, aliases and stored mail. Backups age out on their own cycle, within 30 days.

Processors we use

ProcessorPurposeData involved
Hetzner (Germany)Servers and databasesAll application data
DigitalOcean (Amsterdam)Object storageMessage bodies and attachments
Mailgun (EU region)Relaying forwarded mail and sending account notificationsMessages you have configured to be forwarded
StripeSubscription billingYour email address and payment details, which are handled by Stripe and not stored by us
SentryError monitoringTechnical error reports, which may incidentally include identifiers such as a user ID

We do not sell your data, and we do not share it with anyone beyond the processors above except where the law requires it.

Data you send elsewhere

When you configure a forward, webhook, Slack or archive action, you are instructing us to send your mail to a destination you chose. Once it arrives there, that destination's operator — including you — is responsible for it. Point a webhook at a third party and you are sharing your mail with that third party.

Security

No service is perfectly secure. If you find a vulnerability, please report it to hello@mxcatch.net before disclosing it publicly.

Your rights

Under the GDPR you can request access to your data, correct it, have it deleted, object to processing, or receive it in a portable form. Most of this is available directly in the app — your inbox, your domain settings, and account deletion in profile settings. For anything else, email us and we will respond within 30 days.

You also have the right to complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.

Cookies

We set a session cookie so you stay signed in, and a CSRF token cookie for form security. Both are strictly necessary and neither is used for advertising or cross-site tracking. Our analytics do not use cookies at all, which is why there is no cookie banner.

Changes

If this policy changes materially we will tell account holders by email. The date at the top always reflects the current version.