Privacy Policy

Effective 4 October 2026

In short: we collect what we need to run your account and keep it secure. We pass your emails through to you but don't store their content. We don't sell data, don't use advertising or analytics trackers, and only set a login cookie.

1. Who we are

GhostParse is operated by WILDYE LIMITED, a company registered in England and Wales ("WILDYE LIMITED", "we", "us"). For personal data about our users (described in section 2) we are the controller. Contact us about privacy at hello@wildye.com.

For personal data inside the emails our customers receive through the Service, the customer is the controller and we act as their processor (see section 4). If you are the sender or recipient of such an email, please contact the organisation that sent or received it.

2. What we collect about our users

DataWhy
Company or project name, email address, role in a teamTo create and run your account and team
Password (stored only as a salted scrypt hash)To let you log in
Two-factor authentication secret (encrypted) and recovery codes (hashed)To protect your login if you turn on 2FA
Login sessions: a hashed session identifier, IP address, browser user agentTo keep you logged in and detect suspicious access
Domains, DNS verification status, webhook URL, encrypted webhook secret and DKIM keys, hashed API keysTo provide receiving
Audit log entries: who did what and when, with IP address and user agent, e.g. logins, setting changes, invitations (including the invited email address)Security, abuse prevention and to show you your account's activity
Delivery log entries for inbound email: when it arrived, the outcome (delivered, refused and why, retried), the recipient addresses at your own domain, the sender's domain (not their address), the Message-ID, size, spam score and your webhook's responseTo show you what happened to your email and to alert you when deliveries fail
Email we send you: verification, password reset and team invitationsTo operate your account
Billing: your plan, usage counts (how many emails and AI extractions, never their content), and your Stripe customer reference. Card details, billing name and address and VAT number are collected and held by Stripe, not us.To charge for paid plans, keep tax records and enforce plan limits
If your account was set up by a reseller (for example your hosting company): which reseller, and your reference with themSo the reseller can manage your account, as agreed between you and them
Server logs: IP addresses, requested URLs, timings and errorsTo keep the Service running and secure

If CAPTCHA is enabled on our signup page, the CAPTCHA provider processes information about your browser and IP address to tell humans from bots (see section 5 and our Cookie Policy).

3. Our legal bases (UK GDPR)

4. Emails passing through the Service

When we receive an email for a customer's domain, we parse it in memory, check its SPF, DKIM and DMARC authentication, and deliver it as JSON to the customer's webhook. We do not store the content of these emails (body, subject or attachments) once they have been delivered or rejected. Limited metadata (the Message-ID, the sender's domain, the recipient addresses at the customer's own domain, size, spam score and the delivery outcome) is kept in the customer's delivery log for 90 days.

If spam or virus scanning is enabled, messages are scanned in memory by software running on our own servers; they are not sent to a third party for scanning. If a customer chooses to receive the original message or attachments, they are sent only to that customer's webhook.

Integrations (optional). A customer can send emails on to services they choose, such as Slack, Microsoft Teams, Google Sheets, Zapier, Make, n8n or another webhook, and can set routing rules that decide which emails go where. We send each email only to the services the customer set up, and we don't keep a copy. Once it arrives, that service holds the email under the customer's own agreement with it.

We process this data only on the customer's instructions, as described in section 7 of our Terms.

5. Who we share data with

We do not sell personal data or share it for advertising. We share it only with:

The sub-processors that handle email passing through the Service are listed in our Data Processing Agreement.

6. International transfers

Email passing through the Service is processed on servers in the United Kingdom. Some of our providers may process data outside the UK. Where they do, we use safeguards recognised under UK data protection law, such as adequacy regulations or the UK International Data Transfer Agreement or Addendum.

7. How long we keep data

DataKept for
Account, team, domain and API key dataUntil your account or the item is deleted
Login sessionsUp to 14 days, or until you log out
Email verification and password reset links48 hours and 1 hour respectively
Team invitations7 days unless accepted
Audit log entries90 days
Delivery log entries (inbound email metadata)Your plan's delivery log period (up to 90 days)
Invoices and payment recordsSix years, as UK tax law requires
Email content passing through the ServiceNot stored
Server logsA limited period for security and troubleshooting

We may keep data longer where the law requires it or to deal with a dispute or abuse investigation.

8. Security

Connections are encrypted in transit. Passwords, API keys, session identifiers and recovery codes are stored only as hashes; webhook secrets, DKIM private keys and 2FA secrets are encrypted at rest. Access is restricted by role, 2FA is available (and can be required for your team), and account activity is audit-logged. No system is perfectly secure, but we work to protect your data and will tell you without undue delay about any breach that affects you.

9. Your rights

Under UK data protection law you can ask to access, correct, delete or receive a copy of your personal data, and to restrict or object to how we use it. To make a request, email hello@wildye.com. We will respond within one month. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to help first.

10. Children

The Service is for businesses and developers and is not intended for anyone under 18.

11. Changes

We may update this policy. We will post the new version here with its effective date and, for significant changes, let you know by email or in the dashboard.

12. Contact

WILDYE LIMITED, a company registered in England and Wales. Email: hello@wildye.com.