Privacy policy
What MailMint processes, where the bytes sit, who else receives them, and when they are deleted. Short version: MailMint itself runs on one server in Finland (EU), the only AI service that sees email content is Chutes (processing location not fixed, see below), there are no tracking cookies, and raw email is deleted on a fixed per-plan schedule.
Who operates MailMint #
MailMint (mailmint.app.mintapis.com) is operated by:
productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG
Reichenbergerstr. 2, 94036 Passau, Germany
Represented by Florian Standhartinger ·
info@productivity-boost.com · +49 178 1981631
Amtsgericht Passau, HRB 8453 · VAT ID DE296812612
Where the service runs #
The application, its PostgreSQL database and the inbound mail server all run on one server located in Finland (EU), rented from Hetzner Online GmbH, a German hosting company. Your account data, the emails sent to your MailMint addresses, the parsed results and the application logs all live on that host.
What is processed #
- Account data: the email address you register with, used to sign you in, to send password-reset links and to reach you about your account.
- Inbound email: messages sent to your MailMint addresses are received by our own mail server, stored as raw email, parsed into structured fields, and delivered to the webhook endpoints you configure. Attachments are stored as separate binary objects.
- Usage and configuration: the mailboxes, parsing schemas, webhook endpoints and API keys you create, plus the records needed to count usage against your plan.
Processors & recipients #
Hetzner Online GmbH — hosting
Runs the single server in Finland (EU) described above. Everything the service stores is stored there.
Chutes — AI field extraction
Email content may be sent to Chutes (llm.chutes.ai) for AI field
extraction: when rules alone cannot fill every field of your schema, the message (or the relevant parts
of it) is passed to a large language model hosted on Chutes. Chutes is the only LLM processor by
default. Gemini and OpenAI would be used only if the operator explicitly enabled them
(MAILMINT_LLM_EXTRA_PROVIDERS) — that is currently not enabled.
Where Chutes processes it: Chutes runs models on a distributed network of GPU
servers and does not publish a fixed processing location, so a request may be processed outside
the EU. MailMint only uses Chutes models whose names end in -TEE; Chutes describes
these as running inside trusted execution environments (Intel TDX, NVIDIA Protected PCIe). Chutes' own
privacy policy states that for its public LLM API it does not log,
store or persist the content of requests or responses. When a Chutes model is overloaded, MailMint
tries another Chutes model instead; email content is not sent to a different provider because of that.
Stripe — billing
Paid plans are billed through Stripe. Stripe processes the payment data you enter at checkout; MailMint never sees or stores your card number — only the plan you are on and the identifiers Stripe gives us about your subscription.
Google — mail delivery
Password-reset emails are relayed through Google's mail servers (smtp.gmail.com), so your
account email address and the password-reset link pass through Google when a reset is requested.
Web fonts on this website #
The fonts used on this website (Inter and JetBrains Mono, both under the SIL Open Font License) are served from MailMint's own server. When you open any page, your browser fetches the fonts from us only — the website makes no request to Google or any other font provider, and loads no third-party resources.
Server logs #
Every API and web request is logged with your IP address to the application's container log. Logs are kept for operating and securing the service (debugging, abuse and intrusion detection). The log is rotated at 10 MB with at most three files kept, and it is deleted entirely when the application is redeployed.
Retention #
Stored data is deleted on a fixed schedule that depends on your plan. These are the values the production configuration enforces:
| What | Free | Starter | Pro | Scale |
|---|---|---|---|---|
| Raw email | 30 days | 90 days | 180 days | 365 days |
| Attachment blobs | 7 days | 30 days | 60 days | 90 days |
| What | Kept for |
|---|---|
| Webhook events | 7 days |
| Delivered job rows | 30 days |
Visitor statistics #
We count page views, sign-ups and paid upgrades in our own database on our own server. For statistics, no cookie is set, nothing is stored on your device, and no script or pixel runs on your device — the counting happens on our server, for the page request your browser makes anyway. There is no third-party tracker involved.
Your IP address and user agent are read only to filter automated and internal
traffic; they are neither stored nor hashed for statistics. What is
stored are daily totals per page and per referring host name — the host name
only, never a full URL and never query parameters. A “visit” is a page load arriving
from outside this site; a page reached from within the site counts only as a view. Because no
identifier is derived, unique visitors are not measured. Requests carrying
Sec-GPC: 1 or DNT: 1 are not counted. Sign-up, trial-start and
paid-upgrade events are stored with the internal number of the account concerned. All statistics
totals are deleted after 13 months.
In our assessment, this counting requires no consent under § 25 TDDDG, because nothing is stored on or read from your device for it; the legal basis for the short-lived processing of the request headers on our server is Art. 6(1)(f) GDPR (our legitimate interest in understanding how our own site is used). You can object by switching on Global Privacy Control or Do Not Track in your browser — those requests are then not counted — or by emailing info@productivity-boost.com.
Requests & deletion #
Questions about your data, and requests to access, correct or delete your account and the data stored for it, go to info@productivity-boost.com. Account deletion is honoured on request.