Privacy Policy
Last updated: 30 August 2026
Andrew Dainty, operating as AutoArchive Mail ("we", "us", "our"), provides email-archiving software that you deploy and run within your own network, for businesses with compliance obligations. Unlike a hosted or cloud service, the archiving software itself runs on your infrastructure — this policy explains what data we collect when you use autoarchivemail.com (our marketing site, checkout, and support channels), why we collect it, and how it's protected. Address: Blackwall, NSW, Australia. Jurisdiction: New South Wales, Australia.
1. What we collect
We distinguish between two categories of data:
- Account and marketing data — name, work email, company name, and any information you submit via our contact form or during signup/onboarding.
- Archived email content — the AutoArchive Mail software, which you install and run on your own network, connects directly to your mailbox (Outlook, Gmail, Microsoft 365, or IMAP-compatible) and writes captured email content (headers, body, and attachments) directly to storage you designate. This connection and processing happens entirely within your own environment — email content is not transmitted to or processed on AutoArchive Mail's own servers, and we do not have access to it. Separately, based on the configuration you choose, the software may also leave the original email in your mailbox unchanged, move it into a dedicated folder within your mailbox, or delete it from your mailbox once archived — this action happens entirely on your own systems and is never itself transmitted to or performed by AutoArchive Mail's own servers.
2. How archived email data is handled
Because the archiving software runs on your own network, not ours, archived email content never transits or rests on AutoArchive Mail's infrastructure at any point — there is no staging copy, index, or backup of your email content on our systems. Captured email goes directly from your mailbox to storage that you control (your own cloud storage or on-premise destination). The only data we hold is what's described in Section 1 as "account and marketing data," plus operational logs from the software itself (e.g. connection status, error messages, counts of emails processed) that do not include email content.
On Team, Business, and On-Premise plans, the software also maintains a local SQL index to make searching across mailboxes faster. This index runs entirely on your own network alongside the archiving software itself — it is never transmitted to or accessible by AutoArchive Mail — and records only save metadata (mailbox, folder, filename, and save date), not email content.
3. Why we process this data
- To provide the archiving service you've signed up for (contractual necessity).
- To respond to support requests and contact form submissions.
- To maintain security, detect abuse, and comply with legal obligations.
4. Third parties and sub-processors
We use the following third-party service providers to operate this business:
- Stripe — payment processing and subscription billing. Stripe receives payment details directly; we never see or store your full card number.
- Brevo — transactional email delivery (contact form replies, signup/onboarding notifications). Brevo processes the contact/account details needed to send those emails.
- Cloudflare — content delivery, DDoS protection, and edge security for this website. Cloudflare sees standard web traffic metadata (IP address, request headers) for anyone visiting the site.
None of these providers ever receive your archived email content — as described in Section 1 and 2, that never reaches our infrastructure or any sub-processor's infrastructure in the first place.
5. Cookies and tracking
This site's own analytics are self-hosted and cookieless — page views, referrer, and screen size are recorded without a persistent identifier and without cross-site tracking. We do not use advertising or retargeting cookies.
Some cookies are set by third parties when you interact with specific features, on those providers' own domains:
- Cloudflare — our CDN and security provider may set strictly-necessary cookies (e.g. bot-management or challenge cookies) to distinguish legitimate visitors from automated abuse.
- Stripe — if you proceed to checkout, Stripe's hosted payment page sets cookies required for fraud prevention and session security, under Stripe's own privacy policy.
- Cal.com — if you open the demo-booking widget, it loads content from our Cal.com instance, which may set cookies required for the booking session.
6. Data retention
Account and marketing data is retained for as long as you have an active account or trial, and for up to 12 months afterward for legitimate business and legal purposes (e.g. re-engagement, dispute resolution, tax/accounting records), unless you request earlier deletion via our contact form. As covered in Section 2, no copies of your archived email content are ever created or retained on our systems — there is nothing of that kind to delete.
7. Security
All traffic to this website is encrypted in transit (TLS, enforced via HSTS). Account and marketing data is stored with our infrastructure providers (Stripe, Brevo, Cloudflare), each of whom encrypts data at rest under their own security programs. Access to account and marketing data is restricted to the business owner; there is no team or contractor access. If a security incident affecting your data occurs, we will notify affected customers without undue delay via the contact details on file.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us via our contact form.
If you are in the EU or UK (GDPR): you have the right to access, rectify, erase, or port your personal data, and to object to or restrict its processing, under the UK/EU General Data Protection Regulation. You also have the right to lodge a complaint with your local data protection authority.
If you are in California (CCPA/CPRA): you have the right to know what personal information we collect, to request deletion, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information to third parties for their own marketing purposes.
9. International data transfers
We are based in Australia. Account and marketing data is processed by our sub-processors (Stripe, Brevo, Cloudflare — see Section 4), each of which may process or store data outside Australia, including in the United States and the European Union, under their own respective data protection agreements and safeguards (including Standard Contractual Clauses where applicable to EU-origin data). Your archived email content is never transferred to us or any sub-processor in the first place — it moves only between your mailbox and the storage destination you control, both of which you choose.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
11. Contact
Questions about this policy or your data can be sent via our contact form.