cyberpidgeon

Trust & legal · Updated September 11, 2026

Privacy notice

Draft beta notice. Operator details are awaiting confirmation; public registration is not yet open.

Who is responsible

Operator details pending confirmation. The legal company name, registered business address and public privacy contact have not yet been confirmed. Public registration is paused until these details are supplied.

Cyberpidgeon is an email infrastructure service for software agents. For account administration and service security, the operator acts as controller. For message content processed on a customer's instructions, the customer normally acts as controller and Cyberpidgeon acts as processor. Where the customer is itself a processor, Cyberpidgeon is its subprocessor. The customer determines its own lawful basis, notices and permissions for agent email workflows.

Data and purposes

DataPurpose and proposed legal basis
Account email, workspace name, password hash, recovery-code hash and terms acceptance version/timeProvide and administer the account and contract (GDPR Article 6(1)(b)); comply with applicable recordkeeping duties where required (6(1)(c)).
Session tokens, API-key hashes, scopes, key usage timestamps and rate-limit identifiersAuthenticate requests and prevent unauthorized access or abuse, on the basis of providing the service and our legitimate interest in securing it (6(1)(b) and 6(1)(f)).
Agent names/addresses, custom domains, DNS verification records, email bodies, headers, recipients, attachment metadata and delivery eventsProvide the email functionality instructed by the customer under the applicable processing agreement. Email may contain information about senders, recipients and people mentioned in content.
Request method/path, request identifiers, error type, service logs and hashed rate-limit bucketsOperate and troubleshoot the service and limit abuse (legitimate interests, 6(1)(f)). We do not intentionally log passwords, bearer keys, cookies or message bodies.
Privacy requests and responsesHandle and document rights requests and meet applicable legal duties (6(1)(c)).

Account and credential information is needed to use an account. You choose agent names, email content and recipients. Your email address is currently unverified; email-based password reset is unavailable. Recovery uses the one-time code shown at account creation or password change.

Where data goes

The application and PostgreSQL database run on Microsoft Azure in North Europe (Ireland). Resend is the planned sending and receiving provider; mail remains unavailable until the provider and DNS are activated. Once enabled, email content and recipient information pass through that provider and the recipients' mail systems. Inbound attachments remain at the email provider and are accessed using temporary download links.

Authorized operators may access data to support the service, investigate security incidents or meet legal duties. We do not sell account or message data. This application does not use email content to train models, run advertising analytics, or make automated decisions with legal or similarly significant effects. Your own agent integration may process email with other services under your control.

An EU application region is not a promise that every provider's processing stays in the EEA. Provider support and subprocessors may process data internationally. Applicable vendor agreements, transfer safeguards and transfer assessments must be confirmed before enabling production personal-data workloads. See providers and processing locations.

Retention and deletion

Messages and account records remain in the live database while the account is open; there is currently no automatic age-based message retention setting. You can export the data and close the account in Settings. Closing immediately revokes browser sessions and API keys, pauses agents and cancels unattempted queued sends. An already attempted email may still be delivered.

Live account data is erased by a background process after at least five minutes and after custom-domain provider cleanup has completed. Cleanup retries when a provider is unavailable. Provider-held message and attachment copies require separate operator follow-up; recipients' copies cannot be withdrawn by Cyberpidgeon. Minimal closure/request audit records and hashed retired-address fingerprints remain to record the request and prevent address reassignment.

Azure database rolling backups are configured for seven days and operational logs for thirty days. Separately retained deployment/migration backups and the previous infrastructure require operator review during erasure; they do not automatically follow the rolling-backup period. Expired sessions are removed by the background process. Rate-limit buckets are removed after two days. These statements describe the current beta configuration, not a guarantee of immediate deletion from every system.

Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent without affecting prior lawful processing. You can complain to the supervisory authority where you live or work, or where an alleged infringement occurred. Find an authority through the EDPB member list.

Account owners can download a machine-readable export or submit a rights request in Settings → Privacy. Senders, recipients and other people without accounts can contact the public privacy contact above, once confirmed. If the request concerns a customer's email workflow, contact that customer as controller; Cyberpidgeon can assist them. We may need proportionate proof of identity. GDPR generally requires a response within one month; permitted extensions must be explained within that first month. Requests and any reason for limitation should be documented.

Cookies, changes and contact

We use an essential sign-in cookie, with no optional analytics or advertising cookies in this application. See the cookie notice. Material changes to processing will be reflected here before they take effect and communicated to affected account owners where required. This beta is intended for adults using developer tools; do not submit children's data or special-category data without a separately agreed and assessed arrangement.