Back to Help

Security & privacy

Data, privacy & GDPR

Spamless.dev is built and operated with EU data-protection rules in mind. The service is operated by Codius Kft. (Budapest, Hungary) — see the imprint.

Where your mail is processed

Mail is processed in real time inside the EU (AWS eu-west-1, Ireland). We only store messages that are quarantined — and those are kept encrypted at rest for a configurable period (30 days by default) and then automatically deleted. Clean mail is relayed onward and not retained.

What we collect

  • Email data needed to filter (headers, body, attachments, metadata) — processed in real time.
  • Account info you provide (name, email, company).
  • Usage/log data (API requests, admin activity, IPs, timestamps) to run and secure the service.

We never sell or profile your data. Payment is handled by Stripe — we don't store card numbers.

Your GDPR rights

You can access, rectify, erase, restrict or port your personal data, object to processing, and withdraw consent at any time. Contact privacy@spamless.dev (or our data-protection contact dpo@spamless.dev). The Hungarian supervisory authority (NAIH) is named on the imprint page.

  • Privacy Policy — what we collect and why.
  • Data Processing Agreement (DPA) — for business customers; lists our sub-processors: AWS (hosting, storage, SES), Stripe (payments), MaxMind (IP geolocation), Spamhaus (domain/IP reputation), abuse.ch (malware hashes), Sentry (error monitoring) and Crisp (live chat).
  • Cookie Policy — strictly necessary cookies plus optional, consent-gated monitoring (Sentry) and live-chat (Crisp) cookies. You can change your choice any time via Cookie settings in the footer.
  • Acceptable Use Policy and Terms round out the set. Report abuse to abuse@spamless.dev, security issues to security@spamless.dev.

All legal pages are available in English, Hungarian and German from the site footer.

Transport security

Our inbound gateway mx.spamless.dev has a publicly trusted TLS certificate and accepts STARTTLS, so senders can deliver to you over TLS — and you can publish an MTA-STS policy for your domain that names our MX. Spamless.dev's own domain publishes MTA-STS in enforce mode with TLS reporting.

Can’t find what you need? Email us at hello@spamless.dev