Privacy policy

Last updated: April 27, 2026

Secure Salt, Inc. ("Secure Salt," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use Secure Salt services, including SaltMail and related identity, authentication, and messaging infrastructure (collectively, the "Service").

Secure Salt is designed with a privacy‑first architecture intended to minimize data collection and avoid accessing message content whenever possible.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

Information we collect

Secure Salt collects only the information necessary to operate the Service.

Account information

When you create an account or interact with the Service, we may collect:

  • Name
  • Email address
  • Authentication credentials
  • Billing information (if applicable)

This information is used to provide and maintain the Service.

Gmail and email provider data access

If you connect an email account such as Gmail, Secure Salt may access certain email data through the Gmail API or other email provider APIs.

The data accessed may include email metadata only, such as:

  • Sender email address
  • Recipient email address
  • Subject line
  • Message timestamps
  • Message labels or categories
  • Read/unread status

Secure Salt does not access, extract, analyze, or store the body content of your personal email messages.

Personal email message bodies remain with your email provider and are not processed or stored by Secure Salt systems.

Secure Salt's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

Information collected through the Service may be used to:

  • Provide inbox routing and access‑control features
  • Operate SaltMail and related messaging infrastructure
  • Authenticate users and verify sender identity
  • Process micropayment transactions
  • Detect and prevent spam, abuse, fraud, and security threats
  • Maintain system reliability and performance
  • Comply with legal obligations

Secure Salt does not use email data for advertising or marketing purposes.

Secure Salt does not sell personal information.

Data minimization

Secure Salt is designed to collect the minimum amount of information required to operate the Service.

Secure Salt does not:

  • Perform behavioral advertising
  • Sell personal data
  • Train machine learning models on personal email content
  • Mine user communications for marketing insights

Storage of email metadata

Email metadata may be temporarily processed and stored only to the extent necessary to provide routing, authentication, spam filtering, and inbox management functionality.

Secure Salt does not store or analyze email body content.

Aggregated and de‑identified data

Secure Salt may generate aggregated or de‑identified information derived from the operation of the Service.

Examples include:

  • Spam and abuse trends
  • Aggregate email traffic statistics
  • System performance metrics

This information does not identify individual users.

Payment information

Certain features of the Service may involve micropayments or transaction fees.

Payment processing may be handled by third‑party payment processors. Secure Salt does not store full credit card numbers or financial account credentials on its systems.

Payment processors may collect and process payment information according to their own privacy policies.

Data security

Secure Salt maintains administrative, technical, and organizational safeguards designed to protect user information.

Security practices include:

Encryption

All stored data is encrypted at rest using technologies such as AWS Key Management Service (KMS) or equivalent encryption systems.

Access controls

Access to systems and user data is restricted to authorized personnel who require access to perform operational duties.

Monitoring

Secure Salt maintains logging and monitoring systems designed to detect unauthorized access and potential security threats.

Incident response

Secure Salt maintains procedures to investigate and respond to potential security incidents.

If a confirmed data breach involving personal information occurs, Secure Salt will provide notification as required by applicable law.

Data retention

Secure Salt retains personal information only as long as necessary to:

  • Provide the Service
  • Maintain system integrity
  • Prevent fraud or abuse
  • Comply with legal obligations

When information is no longer needed, it may be deleted or anonymized.

Sharing of information

Secure Salt shares information only in limited circumstances.

Service providers

We may share information with trusted service providers that help operate the Service, including:

  • Cloud infrastructure providers
  • Payment processors
  • Security monitoring services

These providers are contractually required to protect the information and may use it only to perform services on our behalf.

Legal requirements

Secure Salt may disclose information if required by law, subpoena, or court order.

Protection of rights

Secure Salt may disclose information when necessary to:

  • Protect the rights or safety of Secure Salt or its users
  • Prevent fraud or abuse
  • Investigate security incidents

International data transfers

Information may be processed and stored in the United States or other jurisdictions where Secure Salt or its service providers operate.

By using the Service, you consent to such transfers.

Your privacy rights

Depending on your jurisdiction, you may have rights including:

  • Access to personal information
  • Correction of inaccurate data
  • Deletion of personal data
  • Restriction of processing
  • Data portability

Requests may be submitted using the contact information below.

California privacy rights (CCPA / CPRA)

California residents may have the right to:

  • Request disclosure of personal information collected
  • Request deletion of personal information
  • Request correction of inaccurate information
  • Opt out of the sale of personal information

Secure Salt does not sell personal information.

Children's privacy

The Service is not intended for children under 13.

Secure Salt does not knowingly collect personal information from children under 13.

Changes to this privacy policy

Secure Salt may update this Privacy Policy periodically.

When updates occur, the "Last Updated" date will be revised.

Continued use of the Service after changes become effective constitutes acceptance of the updated policy.

Contact information

Secure Salt, Inc.

Pasadena, California, USA

Privacy inquiries: privacy@securesalt.com

Security disclosures: security@securesalt.com

General inquiries: info@securesalt.com