Security

How SpringMail handles access, data, and sending. Short version: OAuth, not passwords.

OAuth API only

Google Workspace and Microsoft 365 connect through official OAuth APIs. No consumer Gmail, no app passwords, no SMTP login. We never ask for a mailbox password.

Secrets stay encrypted

DNS provider tokens and other operational secrets are encrypted at rest. Payments run through Stripe. Account authentication is handled by Neon Auth.

What we store

Workspace accounts, contact lists, campaign content, and domain/inbox metadata needed to run outbound. We do not sell personal information.

Sending path

Campaigns send through Google and Microsoft APIs. Deliverability events and health scores stay in your workspace so you can pause before reputation damage spreads.

In transit

Traffic to the app uses TLS. Access to workspaces is gated by authenticated sessions and role-based dashboard permissions.

Billing

Card data is processed by Stripe. We store customer and subscription IDs, not full card numbers.

Details live in our Privacy Policy and Terms. Questions: support@springmail.ai.