What MXcatch stores, where it lives, and who else touches it.
Last updated August 29, 2026.
MXcatch is operated from the Netherlands by Sander Boersma. For anything in this policy, including data subject requests, write to hello@mxcatch.net.
For your account data we are the controller. For the email we receive on your behalf we act as a processor on your instructions — the instructions being the domains, aliases and actions you configure.
When mail arrives for one of your domains we store the message and everything derived from it: sender and recipient, subject, headers, plain-text and HTML bodies, and attachments. We also keep the raw .eml.
We do not read, scan, profile, or mine the content of your mail, and we do not use it to train anything. It is processed to carry out the actions you configured and to show you the message in your inbox. Nothing else.
We use a self-hosted Umami instance for aggregate page statistics. It sets no cookies, does not track individuals across sites, and the data never leaves our own infrastructure.
Application servers and databases run in Germany. Message bodies and attachments are stored in object storage in Amsterdam. Both are inside the EU, and mail content is not replicated outside it.
Messages, bodies and attachments are deleted once they pass your plan's retention window — 3 days on Free, up to 90 days on Scale. Deletion is automatic and applies to the stored bodies and attachments as well as the message record.
If you configure an archive action, the archived copy is kept until you remove it. That copy is under your control, not the retention schedule.
Delete your account and we remove your account data, domains, aliases and stored mail. Backups age out on their own cycle, within 30 days.
| Processor | Purpose | Data involved |
|---|---|---|
| Hetzner (Germany) | Servers and databases | All application data |
| DigitalOcean (Amsterdam) | Object storage | Message bodies and attachments |
| Mailgun (EU region) | Relaying forwarded mail and sending account notifications | Messages you have configured to be forwarded |
| Stripe | Subscription billing | Your email address and payment details, which are handled by Stripe and not stored by us |
| Sentry | Error monitoring | Technical error reports, which may incidentally include identifiers such as a user ID |
We do not sell your data, and we do not share it with anyone beyond the processors above except where the law requires it.
When you configure a forward, webhook, Slack or archive action, you are instructing us to send your mail to a destination you chose. Once it arrives there, that destination's operator — including you — is responsible for it. Point a webhook at a third party and you are sharing your mail with that third party.
No service is perfectly secure. If you find a vulnerability, please report it to hello@mxcatch.net before disclosing it publicly.
Under the GDPR you can request access to your data, correct it, have it deleted, object to processing, or receive it in a portable form. Most of this is available directly in the app — your inbox, your domain settings, and account deletion in profile settings. For anything else, email us and we will respond within 30 days.
You also have the right to complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
We set a session cookie so you stay signed in, and a CSRF token cookie for form security. Both are strictly necessary and neither is used for advertising or cross-site tracking. Our analytics do not use cookies at all, which is why there is no cookie banner.
If this policy changes materially we will tell account holders by email. The date at the top always reflects the current version.