Legal

Privacy Policy.

What we collect, why we collect it, who we share it with, and what you can ask us to do about it.

Last updated September 2026

What we collect

Account information

  • Name, email address, and organization name.
  • Billing information, collected and stored by Stripe. We keep a card fingerprint and the last four digits to detect duplicate accounts.
  • Authentication credentials, stored as salted hashes.

Usage data

  • API request logs and metadata.
  • Delivery events and statistics for email and SMS.
  • Dashboard activity.

Advertising data

  • Google Ads click identifiers when you arrive from an ad.
  • Pages visited on transmit.dev, used with those identifiers to measure a paid subscription.

Message data

  • Email content and attachments, kept for 30 days.
  • SMS content, kept for 30 days.
  • Recipient email addresses and phone numbers.

What we do with it

We do

  • Deliver your messages and show you what happened to them.
  • Keep the service reliable.
  • Prevent abuse, including screening messages and detecting accounts created to evade a suspension.
  • Measure advertising so we know which ads lead to a paid subscription.
  • Comply with legal obligations.

We do not

  • Sell your data.
  • Use your content for advertising.
  • Train models on your message content.
  • Share data beyond what the service needs.
  • Read your messages, except to resolve a support request you've opened.

Your rights

These rights apply wherever you are. Some are specifically guaranteed by GDPR, CCPA, or other law.

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Request correction of inaccurate or incomplete data.
  • Deletion. Request deletion of your personal data.
  • Portability. Receive your data in a machine-readable format.
  • Objection. Object to processing for certain purposes.
  • Restriction. Request that processing be restricted in certain circumstances.

To exercise any of these, write to support@transmit.dev. We respond within 30 days.

Cookies

  • Essential. Sign-in, security, and core functionality. Cannot be disabled.
  • Functional. Preferences such as theme and dashboard layout. Optional.
  • Advertising. Google Ads and X Ads conversion cookies, set after you click an ad, so a later sign-up or paid subscription can be reported as a conversion. Blocking them does not affect the product. We also store a first-party cookie with the campaign tags from the landing URL so we can attribute a workspace to that visit.

Who we share it with

We share data with the providers that run the service, and with Google and X for advertising measurement. Processors are bound by a data processing agreement:

ProviderPurpose
Amazon Web ServicesEmail delivery through SES
TelnyxSMS delivery
StripePayment processing
VercelApplication hosting and background processing
PlanetScaleDatabase hosting
TigrisFile and attachment storage
CloudflareBot check at signup. Receives the visitor's IP address and the challenge token.
GoogleAdvertising measurement. The Google tag and a conversion event when a paid subscription starts. Receives the ad click identifier and pages visited on transmit.dev. Not message content, API keys, or recipient addresses.
XAdvertising measurement. The X pixel and a server conversion when an account is created and when a paid subscription starts. Receives the ad click identifier, a SHA-256 hash of the account email, and pages visited on transmit.dev. Not the email address itself, message content, API keys, or recipient addresses.

When you verify a domain we look up its registration record through public RDAP servers. Only the domain name is sent.

Retention

WhatKept for
Email and SMS content30 days
Delivery metadata and logs365 days
Account data after closure30 days
Payment records7 years, for tax and legal compliance
Acquisition tags from the landing visitFor the life of the account

International transfers

Transmit is headquartered in the United States. Your data may be processed in the US and in other countries where our providers operate. We rely on EU Standard Contractual Clauses and data processing agreements with every processor.

Children

Transmit is not intended for anyone under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us data, write to support@transmit.dev and we will delete it promptly.

Automated decisions

We use automated systems for these purposes, and a person reviews any decision you dispute:

  • Message screening. Checking content before it's sent to protect recipients and your reputation.
  • Abuse detection. Identifying accounts created to evade screening or a suspension, including by payment identity.
  • Rate limiting. Throttling to protect the service.
  • Bounce processing. Handling bounces, complaints, and suppression lists automatically.

We do not collect or process biometric data.

Contact

Privacy questions and data requests: support@transmit.dev. Put "URGENT" in the subject for a security matter. Transmit.dev is a service of WeWill3C, LLC, a Texas limited liability company.

Changes to this policy

When we make material changes we will give at least 30 days notice by email to your account address and post a summary here. You may close your account if you disagree. The date at the top of this page shows when it was last revised.