MailPulse
Privacy notice
How MailPulse handles personal data, both yours as a customer and that of the people you send email to.
Who we are
MailPulse is operated by Royal Bengal, 208 Mayfair Drive Northeast, Leesburg, Virginia, United States. You can reach us about anything on this page at support@royalbengal.ai.
There are two different relationships in this notice and it matters which one applies. For your own account details we decide what happens to the data, so we are the controller. For the contacts you upload and the people you send campaigns to, you decide what happens and we act on your instructions, so you are the controller and we are your processor. The GDPR page sets that out in more detail.
What we collect about you
Your email address and, if you set one, your name. Your workspace name. Which plan you are on and your billing history. If you sign in with Google, the email address and name Google gives us, and nothing else from your Google account.
We do not store your card. Payments go to Stripe and we keep only the customer and subscription identifiers Stripe gives back.
We keep a record of significant changes to your workspace, such as plan changes and member changes, so that you and we can see what happened and when.
What we hold on your behalf
The contacts you import: their email address, any name fields you provide, and whether they are subscribed, unsubscribed or suppressed after a hard bounce or a spam complaint.
One record per email you send, holding the recipient address, when it was sent, and what happened to it: delivered, bounced, or reported as spam.
If you switch tracking on for a campaign, whether each recipient opened it and which links they clicked. Tracking is off unless you turn it on, and it is per campaign.
We do not use your contacts for anything except sending the email you asked us to send. We do not sell them, share them, or use them to train anything.
How long we keep it
Contacts, campaigns and templates stay until you delete them or close your workspace.
Delivery records, meaning the individual row that says a message was sent to an address and what happened to it, are kept for as long as the workspace that sent them exists. Records of when webhook notifications were delivered to your endpoints are kept for three months. Our internal audit records are kept for one year.
Records of payments are kept for as long as tax and accounting rules require, which is longer than the periods above and is the one thing we cannot delete on request.
When you close a workspace, its contacts, campaigns and delivery records are deleted. Deleting a single campaign also deletes the delivery records for it.
Deleting a contact removes them from your audience and from every list. The delivery records for messages already sent to them remain, and those records include the address the message was sent to.
Who else touches the data
Four services, and no others. Amazon Web Services, which actually delivers the email and tells us what happened to it. Supabase, which hosts the database and handles sign-in. Railway, which runs the application. Stripe, which takes payments.
Each of them is bound by its own contract with us to process data only on our instructions. The GDPR page lists them again with what each one does and where.
Where it is held
Email is sent through Amazon Web Services in the us-east-1 region, in the United States. The database is hosted by Supabase. If you are in the UK or the European Economic Area, that means your data is transferred outside it, and those transfers rely on the standard contractual clauses in our agreements with those providers.
Cookies
MailPulse sets cookies to keep you signed in and nothing else. There is no advertising, no analytics that follows you between sites, and no third-party tracking on this website.
Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. You can export your contacts and your engagement data from the dashboard at any time without asking.
If somebody you have emailed contacts us directly about their data, we will tell them to contact you, because you are the controller of that data and we cannot act on it without you. Write to support@royalbengal.ai either way.
If you think we have handled your data badly, you can complain to your data protection regulator.
If you are in the United States
Several states now give residents rights over their personal data, among them Virginia, California, Colorado and Connecticut. Where one applies to you, it generally gives you the right to know what we hold, to have it corrected, to have it deleted, and to opt out of it being sold or used for targeted advertising.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising. There is nothing to opt out of, which is why there is no "do not sell my information" link on this site.
The rights above are exercised the same way as any other request on this page: write to support@royalbengal.ai. We will not charge you for it or treat you differently for asking.
Changes
This notice took effect on 31 July 2026. If we change it in a way that matters, we will tell account holders by email rather than quietly changing the page.
Written to describe what MailPulse actually does rather than to cover everything a lawyer would cover. If something here does not match what you see in the product, the product is the thing that is wrong and we want to hear about it: support@royalbengal.ai.
