Privacy Policy
Last updated 23 August 2026
Ravenhook holds email that other systems send to your namespace. That mail can contain personal data belonging to people who have never heard of us, so this page is specific rather than reassuring: what we store, for how long, who else touches it, and how to make it go away.
The short version
- Messages are deleted automatically within 24 hours. We do not archive them.
- We never see your card details. Payments are handled by Lemon Squeezy.
- Your API key is stored only as a digest; we cannot read it back.
- We do not use tracking cookies, analytics, or advertising on this site.
- We do not sell data, and we do not use message content for anything except returning it to you.
Who is responsible
Emanuel Hasbun operates Ravenhook and is the controller for the account data described below. Contact: support@ravenhook.dev.
For the contents of messages sent to your namespace, you are the controller and we act as a processor on your instructions. You decide what systems send mail there; we only receive it and hand it back.
What we store
Account data
Your email address and subscription identifier, received from Lemon Squeezy when you subscribe; the namespace allocated to your account; and a SHA-256 digest of each API key. We keep this while your subscription is active, because losing it would log you out permanently.
Message data
When mail arrives at an address in your namespace we store:
- the sender and recipient addresses;
- the subject and the message headers;
- the plain text and HTML bodies;
- attachment metadata — filename, media type and size.
Attachment contents are not stored. We record that a file was attached and what it was called; the file itself is discarded.
Operational logs
Connection and request logs used to run the service and investigate abuse: timestamps, IP addresses, and whether a request succeeded. These do not contain message bodies.
How long we keep it
| Data | Retention |
|---|---|
| Message content | Deleted automatically 24 hours after arrival, or sooner once a namespace exceeds 500 stored messages |
| Account records and key digests | While the subscription is active |
| Operational logs | Short lived, retained only as long as needed to operate the service |
| Billing records | Held by Lemon Squeezy for as long as tax law requires |
Deletion is automatic and unconditional. There is no archive, no backup of message content, and no way for us to retrieve a message once it has expired — including for ourselves.
Account records are backed up off-site so that a hardware failure does not log every customer out permanently. Those backups contain namespaces, subscription identifiers and key digests. They contain no message content.
Mail about people who are not our customers
This is the part that deserves attention. Mail sent to your namespace may contain personal data about people who have no relationship with us — a name in a signup confirmation, an address in a receipt.
Ravenhook is for receiving mail generated by systems you own or are authorised to test. Our Terms of Service prohibit directing another person's correspondence here, and prohibit publishing an address under your namespace where the public could mail it. Short, automatic deletion is the main technical control: nothing accumulates.
Who else processes data
| Provider | Purpose |
|---|---|
| Lemon Squeezy | Payments, invoicing and tax, as merchant of record |
| Hostinger | Servers running the API and mail receiver |
| Cloudflare | DNS, and off-site storage of account backups |
Servers are located in the United States, and we are based in Costa Rica. If you are in the European Economic Area or the United Kingdom, your data is therefore transferred outside it. For those transfers we rely on the data processing terms and standard contractual clauses published by the providers above.
Legal bases
- Performing our contract — account data and message handling, without which the service cannot work.
- Legitimate interests — operational logs, security and abuse prevention.
- Legal obligation — billing and tax records.
Security
- Every API request requires an API key and is served over TLS.
- API keys are stored as SHA-256 digests, never in plain text.
- A request for an address outside your namespace returns exactly what an empty one returns, so the API cannot be used to discover other customers.
- HTML bodies are sanitised before being returned.
- Inbound mail is accepted over STARTTLS where the sending server supports it.
No system is perfectly secure. If we discover a breach affecting your data we will tell you promptly and describe what happened.
Cookies and this website
We set no tracking cookies and run no analytics or advertising scripts.
When you start a subscription, your browser generates a random secret and stores it locally so that it can collect your API key after payment. Only a hash of that secret ever reaches us. It stays in your browser and is not used to identify or track you.
Your rights
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data, and to object to it. Email support@ravenhook.dev and we will respond within 30 days.
Message content generally expires before such a request could be answered. If you want it gone sooner, cancelling stops new mail immediately and what is stored expires within 24 hours.
If you are in the EEA or UK you also have the right to complain to your data protection authority.
Changes
We will update this page when our practices change, and will email account holders before a material change takes effect.