Privacy policy
Last updated: April 27, 2026
Secure Salt, Inc. ("Secure Salt," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use Secure Salt services, including SaltMail and related identity, authentication, and messaging infrastructure (collectively, the "Service").
Secure Salt is designed with a privacy‑first architecture intended to minimize data collection and avoid accessing message content whenever possible.
By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Information we collect
Secure Salt collects only the information necessary to operate the Service.
Account information
When you create an account or interact with the Service, we may collect:
- Name
- Email address
- Authentication credentials
- Billing information (if applicable)
This information is used to provide and maintain the Service.
Gmail and email provider data access
If you connect an email account such as Gmail, Secure Salt may access certain email data through the Gmail API or other email provider APIs.
The data accessed may include email metadata only, such as:
- Sender email address
- Recipient email address
- Subject line
- Message timestamps
- Message labels or categories
- Read/unread status
Secure Salt does not access, extract, analyze, or store the body content of your personal email messages.
Personal email message bodies remain with your email provider and are not processed or stored by Secure Salt systems.
Secure Salt's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
Information collected through the Service may be used to:
- Provide inbox routing and access‑control features
- Operate SaltMail and related messaging infrastructure
- Authenticate users and verify sender identity
- Process micropayment transactions
- Detect and prevent spam, abuse, fraud, and security threats
- Maintain system reliability and performance
- Comply with legal obligations
Secure Salt does not use email data for advertising or marketing purposes.
Secure Salt does not sell personal information.
Data minimization
Secure Salt is designed to collect the minimum amount of information required to operate the Service.
Secure Salt does not:
- Perform behavioral advertising
- Sell personal data
- Train machine learning models on personal email content
- Mine user communications for marketing insights
Storage of email metadata
Email metadata may be temporarily processed and stored only to the extent necessary to provide routing, authentication, spam filtering, and inbox management functionality.
Secure Salt does not store or analyze email body content.
Aggregated and de‑identified data
Secure Salt may generate aggregated or de‑identified information derived from the operation of the Service.
Examples include:
- Spam and abuse trends
- Aggregate email traffic statistics
- System performance metrics
This information does not identify individual users.
Payment information
Certain features of the Service may involve micropayments or transaction fees.
Payment processing may be handled by third‑party payment processors. Secure Salt does not store full credit card numbers or financial account credentials on its systems.
Payment processors may collect and process payment information according to their own privacy policies.
Data security
Secure Salt maintains administrative, technical, and organizational safeguards designed to protect user information.
Security practices include:
Encryption
All stored data is encrypted at rest using technologies such as AWS Key Management Service (KMS) or equivalent encryption systems.
Access controls
Access to systems and user data is restricted to authorized personnel who require access to perform operational duties.
Monitoring
Secure Salt maintains logging and monitoring systems designed to detect unauthorized access and potential security threats.
Incident response
Secure Salt maintains procedures to investigate and respond to potential security incidents.
If a confirmed data breach involving personal information occurs, Secure Salt will provide notification as required by applicable law.
Data retention
Secure Salt retains personal information only as long as necessary to:
- Provide the Service
- Maintain system integrity
- Prevent fraud or abuse
- Comply with legal obligations
When information is no longer needed, it may be deleted or anonymized.
Sharing of information
Secure Salt shares information only in limited circumstances.
Service providers
We may share information with trusted service providers that help operate the Service, including:
- Cloud infrastructure providers
- Payment processors
- Security monitoring services
These providers are contractually required to protect the information and may use it only to perform services on our behalf.
Legal requirements
Secure Salt may disclose information if required by law, subpoena, or court order.
Protection of rights
Secure Salt may disclose information when necessary to:
- Protect the rights or safety of Secure Salt or its users
- Prevent fraud or abuse
- Investigate security incidents
International data transfers
Information may be processed and stored in the United States or other jurisdictions where Secure Salt or its service providers operate.
By using the Service, you consent to such transfers.
Your privacy rights
Depending on your jurisdiction, you may have rights including:
- Access to personal information
- Correction of inaccurate data
- Deletion of personal data
- Restriction of processing
- Data portability
Requests may be submitted using the contact information below.
California privacy rights (CCPA / CPRA)
California residents may have the right to:
- Request disclosure of personal information collected
- Request deletion of personal information
- Request correction of inaccurate information
- Opt out of the sale of personal information
Secure Salt does not sell personal information.
Children's privacy
The Service is not intended for children under 13.
Secure Salt does not knowingly collect personal information from children under 13.
Changes to this privacy policy
Secure Salt may update this Privacy Policy periodically.
When updates occur, the "Last Updated" date will be revised.
Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
Contact information
Secure Salt, Inc.
Pasadena, California, USA
Privacy inquiries: privacy@securesalt.com
Security disclosures: security@securesalt.com
General inquiries: info@securesalt.com