Privacy Policy
Last updated
This policy explains what personal data BooleanPress (“we”, “us”) handles when you visit booleansmtp.com, including its documentation at booleansmtp.com/docs/, and developers.booleansmtp.com, when you use the BooleanSMTP WordPress plugin, and when your site uses the BooleanSMTP OAuth relay at oauth.booleansmtp.com. BooleanPress is based in the United States.
The short version: the plugin runs on your own site and sends us no usage data or email. Google and Microsoft sign-in can pass through our OAuth relay, which handles the sign-in data described below without storing it. Our websites set no cookies.
Our websites
booleansmtp.com and developers.booleansmtp.com are static sites hosted by Cloudflare. They set no cookies, have no accounts or forms, and embed no third-party content.
- Hosting. Like any web server, Cloudflare processes your IP address and request details (the page, your browser) to deliver the page and protect the sites from abuse. Cloudflare handles this data under its ownprivacy policy.
- Analytics. We use Cloudflare Web Analytics, which is cookieless and does not track you across sites or build a profile of you. It tells us aggregate figures: page views, referring sites, and visitors’ countries and browsers.
- Email to us. If you write to contact@booleansmtp.com, we keep your address and message to reply and to follow up on your request.
The BooleanSMTP plugin
BooleanSMTP is software you install and run on your own WordPress site. It collects no usage data, and the free plugin never contacts a licensing server. For the email your site sends, you (the site owner) decide what is sent and where; we never receive it. Google and Microsoft sign-in can pass through our OAuth relay, as described below. The free plugin's Google and Microsoft connections can use local redirects instead.
The plugin contacts a service only when you configure it to:
- Mail providers. When your site sends an email through a connection you created, the message (recipients, subject, body, headers, attachments) and the credentials you entered for that connection go to the provider you chose, which handles them under its own terms: Google (Gmail, Google Workspace) (terms, privacy), Microsoft (Microsoft 365, Outlook) (terms, privacy) and Amazon Web Services (Amazon SES) (terms, privacy). A Custom SMTP connection sends to the server you enter, under its operator’s terms, such as Zoho Mail (terms, privacy), SendGrid (Twilio) (terms, privacy), Mailgun (terms, privacy), Postmark (ActiveCampaign) (terms, privacy), Brevo (terms, privacy), SparkPost (Bird) (terms, privacy), MailerSend (terms, privacy), Mandrill (Mailchimp) (terms, privacy), Netcore (terms, privacy), SendLayer (terms, privacy), SMTP2GO (terms, privacy), SMTP.com (terms, privacy) and Elastic Email (terms, privacy). A SendGrid or Postmark connection imported from another SMTP plugin becomes a Custom SMTP connection to that provider.
- Alert channels. If you enable Slack, Discord or Telegram alerts, the plugin posts a short notice to the webhook or bot you configured: when a message finally fails (recipient, subject, provider, the delivery source such as wp_mail or queued sending, its log and connection IDs when available, and a link to your site’s logs), and when a connection fails its health check or can no longer refresh its sign-in (the connection’s name and provider). Saving an alert sends nothing; a test sends one notice. Raw error messages, credentials and message bodies are never included. Each service handles the notice under its own terms: Slack (terms, privacy), Discord (terms, privacy) and Telegram (terms, privacy).
What stays on your site. Email logs, including message bodies, are stored in your own WordPress database and pruned by the retention period you set (30 days by default). Passwords, API keys and OAuth tokens are encrypted before they are stored. Debug log files are off by default. Deleting the plugin removes its log files and scheduled tasks; your connections, email logs and settings are kept for a reinstall unless you turn onSettings → Delete data on uninstall first.
If you run a site with BooleanSMTP, you are responsible for the personal data of the people your site emails, and for telling them about the mail provider you use.
The OAuth relay
For the free plugin’s Google and Microsoft OAuth connections, the provider sends a one-time sign-in code (or an error) and the state value your site created to oauth.booleansmtp.com. The state includes your site’s address, the connection’s ID, the provider, a timestamp and, when applicable, the admin screen to return to. It is signed so your site can detect changes, but it is not encrypted. The relay immediately redirects your browser back to your site with the code and state, or the provider’s error. In this flow, it receives no client secret or token; your site exchanges the code with the provider directly.
For the Pro Microsoft One Click connection, the relay also receives your site’s address, callback address and connection ID. It exchanges Microsoft’s sign-in code using its own client credentials, receives an access token and redirects that token to your site. The relay stores no sign-in codes or tokens and keeps no request logs. Cloudflare processes relay requests as the host, as for our websites. For the free plugin’s Google and Microsoft connections, you can bypass the relay by defining BOOLEANSMTP_USE_LOCAL_OAUTH_REDIRECTS as true in your site’s wp-config.php.
Why we process data
We process the limited data above to run and secure our websites and the relay, to understand how the documentation is used so we can improve it, and to answer you. Under the GDPR and UK GDPR, our legal basis is our legitimate interest in doing those things, and, when you write to us, taking steps you ask for. We do not sell or share personal information, and we do not use it for advertising.
Your rights
Depending on where you live, you may have the right to access, correct or delete personal data we hold about you, to object to or restrict how we use it, and to data portability. Residents of the EU, the UK and California, among others, have these rights by law. Email contact@booleansmtp.com and we will respond within one month. You may also complain to your local data protection authority.
Where data is processed
We are in the United States. Cloudflare serves our sites from its global network, so requests may be processed in other countries, under Cloudflare’s safeguards for international transfers.
Children
Our websites and software are meant for people who run websites, not for children, and we do not knowingly collect children’s data.
Changes
When this policy changes, we update the date at the top of this page. If a change is significant, such as when BooleanSMTP Pro and its licensing launch, we will say so on this page before it takes effect.
Contact
BooleanPress, United States. Email: contact@booleansmtp.com.