Security
How SpringMail handles access, data, and sending. Short version: OAuth, not passwords.
OAuth API only
Google Workspace and Microsoft 365 connect through official OAuth APIs. No consumer Gmail, no app passwords, no SMTP login. We never ask for a mailbox password.
Secrets stay encrypted
DNS provider tokens and other operational secrets are encrypted at rest. Payments run through Stripe. Account authentication is handled by Neon Auth.
What we store
Workspace accounts, contact lists, campaign content, and domain/inbox metadata needed to run outbound. We do not sell personal information.
Sending path
Campaigns send through Google and Microsoft APIs. Deliverability events and health scores stay in your workspace so you can pause before reputation damage spreads.
In transit
Traffic to the app uses TLS. Access to workspaces is gated by authenticated sessions and role-based dashboard permissions.
Billing
Card data is processed by Stripe. We store customer and subscription IDs, not full card numbers.
Details live in our Privacy Policy and Terms. Questions: support@springmail.ai.
