What we collect, where it goes, and how long it stays. This page covers the hosted e2a service operated by Mnexa, Inc. — the dashboard at e2a.dev, the API at api.e2a.dev, the MCP server at api.e2a.dev/mcp, and the mail path (agents.e2a.dev, mx.e2a.dev, send.e2a.dev).
Last updated 2026-09-27.
Everything below lives in one managed PostgreSQL database. e2a does not use a separate object store — attachment bytes are stored inline with the message row.
Message-ID, In-Reply-To,
References) that hold a conversation together.
We run a self-hosted Umami instance at
umami.tokencanopy.com to understand aggregate traffic to known
public marketing pages on e2a.dev, including the pricing page.
It is cookieless, does not run advertising or session replay, and does not
track visitors across websites. The signed-in dashboard, OAuth consent
page, privacy page, and unknown routes are excluded.
For a public page view, Umami receives the page path and title without URL query strings or fragments, a reduced referrer, browser language and screen size, browser/operating-system/device categories, and approximate location (country or region derived from the request IP). Umami uses the IP address and user agent to create an anonymous session identifier; it does not store the raw IP address or set a browser cookie. We use these records only to measure page traffic and improve public content. They live in a separate Google Cloud PostgreSQL database in the United States and are not joined to e2a accounts, agents, or messages.
The application and its database run on Google Cloud infrastructure in the
United States (us-central1): a Compute Engine VM and a managed
Cloud SQL for PostgreSQL 16 instance. The application connects to the
database over TLS. Traffic to our domains passes through Cloudflare, which
terminates TLS at the edge and sees standard connection metadata.
Email is a federated protocol, so some of your content necessarily leaves our systems — that is what sending mail means.
us-east-2), which processes the full
message in order to deliver it, and then on to the recipient's mail
provider. Mail is DKIM-signed — on your own domain once you have verified
it, otherwise on our shared relay domain.
Mail arriving for your agents is screened before it is delivered, so that a hostile message cannot quietly become instructions your agent follows. Flagged or blocked mail is quarantined — stored, but not served to your agents. We record the disposition of each flagged message and the reason for it.
Today that screening is entirely deterministic — pattern and heuristic checks that run inside our own systems. No message content leaves for model inference, because the model-based detector that exists in the open-source code is not enabled on the hosted service.
When we enable model-based screening, it will use Google Gemini. At that point the content of inbound messages will be sent to Google's Gemini API for the screening check itself — not for any other purpose. The bodies of outbound mail are never sent to a model provider; the separate abuse-detection check may see outbound subject lines and agent names only. We will use the paid Gemini API tier, under which Google's API terms state that Google does not use prompts or responses to improve its products and does not subject them to human review for that purpose; Google's handling is otherwise governed by the Google Privacy Policy. We will add Gemini to the sub-processor list and revise the date on this page before the change takes effect.
A hosted mail service attracts people who want to send phishing and scams from someone else's infrastructure, so we look for accounts that misuse it. This section says what data that uses.
What we examine: signals about the account and its sending, not the mail itself — account and payment details as reported by Stripe (outcomes and a one-way card fingerprint, never the card number), sending volumes and timing, recipient domains, the names and addresses of your agents, the subject lines of the messages they send, delivery, bounce, complaint, and inbound-screening outcomes, and coarse connection metadata stored as one-way digests. Never examined for this purpose: message bodies, attachments, or recipient addresses.
How decisions are made. Automated scoring we operate ourselves can hold a message for review or pause sending on its own, because waiting for a person to look would let a phishing run finish. Suspending or closing an account for abuse is decided by a person, and any automated hold or pause is reviewed by a person if you contest it: email us and we will tell you what was found, within the limit of not tipping off an active abuser.
Today none of these signals leave our systems. We may later send two kinds of signal to a model provider for the detection check itself: outbound subject lines and agent names to Google's Gemini API, on the same paid tier and no-training terms described under Inbound screening; and numeric signals only — no text of any kind — to typesafe.ai's Jev model. We will add each provider to the sub-processor list and revise the date on this page before it takes effect.
What we keep and share. Signals are kept for 90 days, scores for one year, and a confirmed determination of abuse — never message content — for two years, alongside the deletion records under How long we keep it. When an account is used for phishing or fraud we may share the abusive messages and the sending account's details with the parties targeted, with hosting, domain, and payment providers, and with law enforcement.
e2a exists to be driven by agents, so it is worth being precise about which direction content flows.
e2a does not send your mail to an AI model. You do. When you connect an AI client — Claude through our MCP server, or your own agent through the API or an SDK — that client reads the messages it asks for. What happens to the content after that is governed by the terms and privacy policy of the client you connected, not by this page.
These are the third parties that process data on our behalf:
| Provider | Location | What it processes |
|---|---|---|
| Google Cloud | US | Application hosting, database, and log storage — all stored data. |
| Amazon Web Services (SES / SNS) | US | Outbound mail relay and delivery-feedback events. |
| Cloudflare | US | DNS, CDN, and edge TLS — connection metadata. |
| Stripe | US | Payments for paid plans. Checkout is hosted by Stripe; we never receive or store card numbers. We store only your Stripe customer and subscription identifiers. |
| WorkOS | US | Sign-in, if you use a Token Canopy account. See tokencanopy.com/privacy. |
| GitHub | US | Only if you submit in-product feedback — see below. |
| Google Gemini (not currently enabled) | US | Inbound message content for model-based screening, and outbound subject lines and agent names for abuse detection — each only if and when we enable it. See Inbound screening and Abuse detection. |
| typesafe.ai (Jev) (not currently enabled) | US | Numeric account and sending signals only — no text and no message content — for abuse scoring, if and when we enable it. See Abuse detection. |
Business customers who need a signed Data Processing Agreement can request one at the contact below.
If you use the in-product feedback form, your submission is filed as an issue in our public GitHub repository and emailed to our support inbox. Do not put anything confidential in it.
permanent=true; an agent or sent
message that emailed external recipients in the last 14 days stays in
the trash until its 30 days are up instead.
permanent=true erases
the content immediately instead — except when the account sent email to
recipients outside its own agents and inbox in the last 14 days: then
the account stays in the trash until its 30 days are up, so bounce and
complaint reports that arrive after a send can still be attributed to
it. You can still restore it during that window.
permanent=true, otherwise at the end of the trash window —
but may persist in a backup until it ages out.
Both are self-serve, and both are complete:
GET /v1/account/export returns a
single machine-readable JSON document containing your user record,
domains, agents, API key metadata, messages (including attachments),
suppressions, screening events, usage records, and OAuth connections.
API key plaintexts are never stored and cannot appear in it; session and
OAuth tokens are excluded as credential material.
DELETE /v1/account?confirm=DELETE moves your account to a
30-day trash: credentials are revoked and sending stops immediately, and
everything the account owns is purged after 30 days unless you sign in
and restore it (or choose to erase it then and there). Adding
permanent=true erases the account and everything it owns
immediately, returning a receipt with per-table row counts; that cannot
be undone. Either way, the short-lived deletion records described under
How long we keep it remain until they expire.
Deleting your e2a account does not by itself delete a Token Canopy account you used to sign in with; that layer is covered by tokencanopy.com/privacy. If you would rather we ran a deletion for you, email us.
Mnexa, Inc. is the data controller for your e2a account. Where your agents exchange mail with other people, you are the controller of that correspondence and we process it on your behalf. If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR / UK GDPR gives you the rights below; we honour them for all users regardless of location.
You may exercise the rights of access, rectification, erasure, restriction,
portability, and objection, and you may lodge a complaint with your local
supervisory authority. Access is available immediately through the export
endpoint above, and erasure through the deletion endpoint — immediately
with permanent=true, otherwise when the 30-day trash window
ends. Deleting your account yourself without permanent=true
is a restorable trash you chose; an erasure request you email us is
carried out as an immediate erasure, without the trash window. The
deletion records described above are kept on the basis of our legitimate
interest in preventing fraud and abuse. For
anything else, email us. We respond within 30 days. Automated abuse
scoring can hold a message or pause sending on its own; suspending or
closing an account for abuse is decided by a person, and you can contest
any automated action by emailing us, after which a person reviews it. We
make no other decisions about you by automated means.
Our infrastructure and sub-processors are in the United States, so your data is transferred to and stored in the US. Where that involves EEA/UK personal data, the transfer relies on the EU-U.S. / UK Data Privacy Framework certifications of our sub-processors and/or the European Commission's Standard Contractual Clauses.
e2a is a developer tool and is not directed at children. You must be 13 or older to hold an account.
We will update this page when the data flow changes, and revise the date at the top. For a change that materially expands what we collect or who receives it, we will give notice before it takes effect.
Questions, data-export or deletion requests, DPA requests, or anything else privacy-related: [email protected]. Security reports: [email protected] — please give us a chance to fix an issue before disclosing it.