Legal

Privacy Policy

Last updated September 4, 2026

How Sendly collects, uses, and protects personal information when you use our website and email platform.

1. Overview and scope

This Privacy Policy explains how Sendly handles personal information across our marketing site (sendly.now), our documentation site (docs.sendly.now), our application (app.sendly.now), and our APIs.

We act in two different roles. For information about you as a visitor or customer, Sendly is the data controller. For the contact and recipient data you process through the Service ("Customer Data"), you are the controller and Sendly acts as a processor on your behalf, as described in our Terms of Service.

Sendly is operated by Devino Solutions, which also hosts the product analytics and error monitoring described below on its own infrastructure.

2. Information we collect

Account and profile data

Your name, email address, company name, hashed password, and account preferences. Where you sign in with Google or Apple, we receive the identifiers and email address that provider returns.

Billing data

Payments are processed by Stripe. We store limited billing metadata, such as your plan, invoices, and the last four digits of a card, but we do not store full card numbers.

Usage and log data

IP address, device and browser information, pages viewed, API requests, and timestamps, used for security, debugging, and analytics.

Product analytics

When you consent, we record page views, page leaves, and automatically captured interactions such as clicks on buttons and links. Analytics events carry an application identifier, the release version, the environment, the page path, and, once you are signed in, your internal Sendly user ID and the ID of the project you are working in. We never use your email address as the identifier that links these systems together.

Error reports

When something breaks, we record the error, the page path, your internal user ID, and correlation IDs that let us match the error to the analytics session and to any support message you send about it. Error reports are scrubbed of credentials and other sensitive values before they are stored.

Customer Data

Contacts, segments, email content, recipient addresses, and engagement events that you upload or generate. We process this only to provide the Service and according to your instructions.

Communications

Messages you send us, such as support requests and feedback on AI answers.

3. Cookies, analytics, and session recording

We use three categories of cookie, and only the first is set without asking you.

Essential cookies

Sign-in and session cookies, and the cookie that remembers your cookie choice itself. These are required to operate the Service and are not covered by consent.

Analytics cookies (consent required)

Nothing in this category loads until you accept it in the cookie banner. If you ignore the banner, or reject it, no analytics script is loaded at all and no analytics cookie is set.

  • PostHog — product analytics, self-hosted by Devino Solutions at posthog.devino.ca. It records page views, page leaves, and automatic interaction capture, and sets a first-party cookie scoped to sendly.now so that one visit spanning the marketing site, the app, and the documentation is counted once rather than three times.
  • Google Analytics 4 — loaded from googletagmanager.com on the marketing and documentation sites only. This is a third-party tag operated by Google. It is not loaded in the application, and we do not run advertising or remarketing pixels anywhere.
  • Attribution — where you arrive from a campaign link or an external referrer, we store the campaign parameters and the referring site's origin (never its full URL) in a first-party cookie so that a later signup can be attributed to how you first found us. This cookie is also gated on your consent.
  • Referral links — where you arrive through a referral or partner link, we store the click identifier from that link in a first-party cookie named dub_id, scoped to sendly.now, for 90 days, so that a later signup or subscription can be credited to the person who referred you. The identifier and your account's internal id (never your name or email address) are shared with Dub, our referral-tracking processor. This cookie is gated on your consent, and rejecting analytics means no referral is recorded.

Session recording

Where session recording is enabled it is configured to mask every text node and every form input, and to exclude file inputs, embedded frames and canvases entirely. A recording therefore shows layout, navigation, and where a click landed, but not what was typed or displayed. The same masking applies to the recordings attached to error reports.

Withdrawing consent

You can change your choice at any time from the "Manage cookie preferences" panel at the bottom of this page. Because the choice is stored once for all Sendly sites, turning analytics off there turns it off on the marketing site, the app, and the documentation. You can also block or delete cookies in your browser settings.

4. AI features

The in-app assistant sends your messages, and the data it needs to answer them, to OpenRouter, which routes them to the underlying model provider. We do not use your prompts or the assistant's answers to train models.

We record technical traces of assistant activity — timing, token counts, cost, which model answered, and which agent ran — in PostHog. Prompt text, model responses, and the contents of tool results are stripped from those traces before they leave our servers.

Where you rate an answer with the thumbs control, we record the rating, the message and conversation identifiers, and any explanation you choose to write.

5. Automated content scanning

To protect deliverability and to prevent our infrastructure being used for phishing, a sample of outbound message content is scanned by an automated classifier before it is sent. The scan runs through OpenRouter, and a message that is classified as phishing can result in a project being disabled. This applies to Customer Data, so we mention it explicitly rather than leaving it inside "security".

Inbound mail to Sendly-hosted mailboxes is classified for spam by the same mechanism.

6. How we use information

  • To provide, operate, secure, and improve the Service.
  • To process payments and manage your subscription.
  • To provide support and respond to your requests.
  • To protect deliverability and prevent abuse, fraud, and spam.
  • To send service and transactional notices about your account, including in-app and push notifications.
  • To understand which parts of the product and the marketing site are used, where consent allows it.
  • To comply with our legal obligations.

We do not sell your personal information, and we do not use Customer Data for our own marketing.

7. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases: performance of our contract with you for operating the Service and billing; our legitimate interests in securing the Service, preventing abuse, and debugging failures; your consent for analytics and session recording; and compliance with legal obligations.

Analytics and session recording rely on consent alone. Withdrawing it stops that processing going forward and does not affect anything that happened while consent was in place.

8. How we share information

We share personal information with service providers (subprocessors) who help us run the Service, when required by law or to protect rights and safety, and in connection with a merger, acquisition, or other business transfer. We share only what is necessary, under appropriate confidentiality and data-protection terms.

9. Subprocessors

This list reflects the integrations the Service actually runs today.

  • Amazon Web Services — cloud hosting and email delivery (SES), across EU and US regions.
  • Stripe — payment processing and subscription billing.
  • Devino Solutions — self-hosted product analytics (PostHog) and error monitoring (Sentry), and the infrastructure the Service runs on.
  • Google — Google Analytics 4 on the marketing and documentation sites, and Google Sign-In where you choose it.
  • Apple — Sign in with Apple where you choose it.
  • OpenRouter — model routing for the in-app assistant and for automated content scanning.
  • Notifly — in-app and push notifications.
  • DoDomain — guided DNS setup when you connect a sending domain.
  • Dub — referral and partner-link tracking, where you arrive through such a link and consent to analytics.

Each is bound by data-processing terms. We will post material changes to this list here.

10. International data transfers

Customer Data is hosted in the EU by default, with US regions available on request. Where personal data is transferred across borders, we use appropriate safeguards, such as standard contractual clauses, where required.

11. Data retention

We retain account information for as long as your account is active and as needed to meet legal, accounting, or reporting obligations. Customer Data is retained while your account is active and is deleted or returned after termination, subject to a short export window. Operational logs, analytics events, and error reports are kept for a limited period.

12. Security

We protect personal information with encryption in transit and at rest, access controls, least-privilege practices, and ongoing monitoring. No method of transmission or storage is completely secure, but we work continuously to safeguard your data.

13. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal information, and to object to certain processing. Residents of California and other jurisdictions have additional rights, including the right to know and to delete, and the right not to have personal information sold, which we do not do.

To exercise these rights, email support@sendly.now. If your request concerns Customer Data held by a Sendly customer, please contact that customer, who is the controller of that data; we will assist them as their processor.

14. Children's privacy

The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us personal information, contact us and we will delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email, and where the change affects what analytics collect we will ask for your consent again. The date above reflects the most recent revision.

16. Contact

For privacy questions or to exercise your rights, write to support@sendly.now. Sendly is an independent email platform, postmarked in Halifax, Nova Scotia, Canada.

Questions about this page? Write to us at support@sendly.now — we answer our own email.