Privacy Policy

Last updated 1 August 2026

This policy explains what MastroSDR("we") collects, why, and what you can do about it. It covers the MastroSDR application and marketing site.

Who is responsible for what

For your own account information, we are the data controller. For the prospect data you upload and the emails you generate, you are the controller and we are your processor: we handle it on your instructions. See our Data Processing Addendum for those terms.

What we collect

  • Account data. Name, email address, hashed password, workspace name and role.
  • Prospect data you upload. Company name, contact name, email address, website and location.
  • Content you generate. Your pitch text and the email drafts produced from it.
  • Delivery events. Whether a message was delivered, opened, bounced or reported as spam.
  • Integration keys. API keys you connect, encrypted at rest with AES-256-GCM.
  • Security logs. IP address, user agent and timestamps for sign-ins and sensitive actions.

What we do not do

  • We do not sell personal data.
  • We do not use your prospect data or pitch to train any model.
  • We do not share one workspace's data with another, ever.
  • We do not run third-party advertising or tracking pixels on the application.

Why we process it

To provide the service you asked for (contract), to keep it secure and prevent abuse (legitimate interests), to bill you (contract), and to meet legal obligations such as anti-spam and tax rules.

Where it goes

Your prompts and prospect details are sent to an AI provider, purely to generate the email you asked for. Which account that runs through depends on how you have set things up:

  • Your own key connected, for the provider selected under Model in Settings. Everything goes through your provider account, under your key, and we never see the content. Settings always names which account is actually in use, because connecting a key for a provider you have not selected leaves the selected one still in charge.
  • Using the AI drafts included with a paid plan. Those run through our provider account, because that is what the included credits are. The provider processes the content to generate the email and nothing more; we do not use it to train anything, and connecting your own key opts out entirely.
  • A self-hosted or local model. Nothing leaves the machine you point us at.

Outbound email is handled by your connected delivery provider. Payments run through Stripe; we never see your card number. The full list is on our subprocessors page.

How long we keep it

  • Account and workspace data: while your account is open.
  • Prospect and message data: until you delete it, or 30 days after account closure.
  • Proof of what was sent: when an email goes out, the audit log records the recipient address, the subject and the time. That entry is kept for 12 months even if you later delete the prospect, because it is the only record that can answer a complaint about an email you sent.
  • Suppression list entries: kept for the life of the workspace and not removable by anyone in it, because deleting them would let someone who opted out be contacted again. They go when the workspace is closed, with the rest of its data.
  • Security and audit logs: 12 months.

Your rights

Depending on where you live, you may have the right to access, correct, export, delete or restrict processing of your personal data, and to object to it. Email privacy@mastrosdr.com and we will respond within 30 days. You can also complain to your local data protection authority.

If you received an email sent through MastroSDR and want your data removed, use the unsubscribe link in that email or contact the sender directly. They control that data; we process it for them.

Security

Passwords are hashed. Integration keys are encrypted at rest and never displayed again after you save them. API keys are stored only as hashes. Access is scoped to a single workspace at every layer. More detail is on our security page.

Children

MastroSDR is a business tool and is not directed at anyone under 16.

Changes

If we change this policy materially, we will email account owners before it takes effect.

Contact

privacy@mastrosdr.com