Privacy
Minimum data. Clear purpose.
This notice explains how OVP Alternative Solutions SRL processes personal data for the MailBridge AI private preview.
MailBridge AI is invite-only. Read access and send access are separately authorized, destructive mailbox actions remain unavailable, and public billing is not enabled.
1. Controller and contact
The controller is OVP Alternative Solutions SRL, Romania, CUI 48007925. Privacy and support contact: contact@ovidiuvirgilpopescu.ro.
2. Data we process
- Account data: name, account email, authentication/session records and account status.
- Mailbox connection data: mailbox label, provider/host configuration, mailbox username/address, encrypted IMAP credentials and optional encrypted account-owned SMTP credentials/settings needed to connect and send through the mailbox you authorize.
- Mailbox content requested by you: message metadata and message content retrieved from your upstream mailbox when you ask MailBridge AI to list/read messages, plus recipient, subject and body data required to send or reply when you explicitly request an authorized outbound action.
- Authorization data: scoped OAuth/MCP authorization state and short-lived authentication artifacts required to connect a compatible AI client.
- Execution evidence: account/mailbox identifiers, request key, a keyed message fingerprint, timestamps, bounded outcome codes and transport/RFC message identifiers. These records prevent duplicate sends and distinguish provider acceptance from verified receipt; they contain no recipient, subject or body.
- Minimal product telemetry: account-scoped event names for account creation, mailbox connection success/failure, AI authorization, successful MCP list/read operations and send/reply success or failure. Outbound telemetry may include the bounded transport provider/failure code but not recipient, subject or message body.
- Operational logs: limited technical logs and error codes used to keep the service reliable and secure.
3. What we deliberately do not store as product telemetry
Product telemetry does not store message subjects, message UIDs, senders/recipients, message bodies, attachment names/content, mailbox passwords, OAuth access tokens, invite/reset tokens, IP addresses or arbitrary conversation payloads.
The MailBridge application database does not persist email message bodies. Message content is fetched from the upstream mailbox on demand and returned for the user-authorized request.
4. Why we process data
- to create and secure your account and provide the requested service;
- to connect the mailbox you explicitly authorize;
- to return mailbox information to the compatible AI client you authorize and, when separately authorized, to submit an email send/reply you explicitly request;
- to prevent abuse, investigate failures and maintain service security;
- to measure whether the private-preview onboarding and core product path actually work.
The primary legal bases are performance of a contract or steps requested before entering one, legitimate interests in operating and securing the service, and compliance with legal obligations where applicable.
5. Recipients and service providers
Data may be processed by infrastructure providers used to operate MailBridge AI, including the hosting/database provider, transactional/outbound email transport when enabled, your existing email provider, and the compatible AI platform you choose to authorize. Mailbox content is disclosed only as needed to fulfill the user-authorized tool request.
Current application hosting and database infrastructure is on Render in the Frankfurt region. Outbound message data is submitted to the configured delivery transport only after a user-authorized send/reply request.
6. International transfers
Some service providers may process data from jurisdictions outside Romania or the European Economic Area. Where required, OVP Alternative Solutions relies on the safeguards offered by the relevant provider and applicable data-protection law. Provider choices and safeguards are reviewed as the service moves from private preview to public production.
7. Retention
- Mailbox message bodies: not persisted in the MailBridge application database.
- Billing: customer and subscription identifiers, verified subscription state, and minimal processed-event IDs; Stripe processes payment details. MailBridge stores no card details.
- Account and mailbox connection records: retained while the account/connection is active and removed from the active service when the connection or account is deleted.
- Invite links: expire after their configured invitation period and are single-use; stale invite records are subject to cleanup.
- Password-reset links: expire after one hour.
- AI authorization grants: expire after 30 days or stop immediately when revoked. Refresh credentials are stored as hashes; access tokens expire within 12 hours.
- Minimal execution records: retained while the account can retry prior operations, so old request keys cannot produce duplicate sends after restart. Account-deletion requests include a review of these records; message bodies and recipients are not retained in them.
- Product activation telemetry: retained for up to 180 days for validation and reliability analysis.
- Current hosting logs: retained according to the hosting workspace plan; the current Render Hobby log-retention window is up to 7 days.
8. Your controls and rights
You can disconnect a mailbox without deleting or modifying the upstream mailbox. You may request access, correction, deletion, restriction or portability of personal data where applicable, and may object to processing based on legitimate interests. You may also lodge a complaint with the competent supervisory authority, including the Romanian data-protection authority.
To exercise a privacy right or request account deletion, email contact@ovidiuvirgilpopescu.ro. Never send a mailbox password, API key, MFA code or reset token by email.
9. Automated decisions and marketing
MailBridge AI does not currently use personal data for automated decisions that produce legal or similarly significant effects. The private preview does not use mailbox content for advertising or marketing profiles.
10. Changes
Material changes to data processing will be reflected in this notice before the changed processing is introduced where required. Last updated: 9 October 2026.