Privacy Policy
Effective 4 October 2026
In short: we collect what we need to run your account and keep it secure. We pass your emails through to you but don't store their content. We don't sell data, don't use advertising or analytics trackers, and only set a login cookie.
1. Who we are
GhostParse is operated by WILDYE LIMITED, a company registered in England and Wales ("WILDYE LIMITED", "we", "us"). For personal data about our users (described in section 2) we are the controller. Contact us about privacy at hello@wildye.com.
For personal data inside the emails our customers receive through the Service, the customer is the controller and we act as their processor (see section 4). If you are the sender or recipient of such an email, please contact the organisation that sent or received it.
2. What we collect about our users
| Data | Why |
|---|---|
| Company or project name, email address, role in a team | To create and run your account and team |
| Password (stored only as a salted scrypt hash) | To let you log in |
| Two-factor authentication secret (encrypted) and recovery codes (hashed) | To protect your login if you turn on 2FA |
| Login sessions: a hashed session identifier, IP address, browser user agent | To keep you logged in and detect suspicious access |
| Domains, DNS verification status, webhook URL, encrypted webhook secret and DKIM keys, hashed API keys | To provide receiving |
| Audit log entries: who did what and when, with IP address and user agent, e.g. logins, setting changes, invitations (including the invited email address) | Security, abuse prevention and to show you your account's activity |
| Delivery log entries for inbound email: when it arrived, the outcome (delivered, refused and why, retried), the recipient addresses at your own domain, the sender's domain (not their address), the Message-ID, size, spam score and your webhook's response | To show you what happened to your email and to alert you when deliveries fail |
| Email we send you: verification, password reset and team invitations | To operate your account |
| Billing: your plan, usage counts (how many emails and AI extractions, never their content), and your Stripe customer reference. Card details, billing name and address and VAT number are collected and held by Stripe, not us. | To charge for paid plans, keep tax records and enforce plan limits |
| If your account was set up by a reseller (for example your hosting company): which reseller, and your reference with them | So the reseller can manage your account, as agreed between you and them |
| Server logs: IP addresses, requested URLs, timings and errors | To keep the Service running and secure |
If CAPTCHA is enabled on our signup page, the CAPTCHA provider processes information about your browser and IP address to tell humans from bots (see section 5 and our Cookie Policy).
3. Our legal bases (UK GDPR)
- Contract: to provide the Service you signed up for (account, login, domains, API keys, webhooks, emails we send you).
- Legitimate interests: to secure the Service, prevent abuse and enforce our Terms (for example the transactional-only rule), keep audit logs, and fix problems. We balance these against your rights and keep the data to what's needed.
- Legal obligation: where we must keep or disclose data by law.
4. Emails passing through the Service
When we receive an email for a customer's domain, we parse it in memory, check its SPF, DKIM and DMARC authentication, and deliver it as JSON to the customer's webhook. We do not store the content of these emails (body, subject or attachments) once they have been delivered or rejected. Limited metadata (the Message-ID, the sender's domain, the recipient addresses at the customer's own domain, size, spam score and the delivery outcome) is kept in the customer's delivery log for 90 days.
If spam or virus scanning is enabled, messages are scanned in memory by software running on our own servers; they are not sent to a third party for scanning. If a customer chooses to receive the original message or attachments, they are sent only to that customer's webhook.
Integrations (optional). A customer can send emails on to services they choose, such as Slack, Microsoft Teams, Google Sheets, Zapier, Make, n8n or another webhook, and can set routing rules that decide which emails go where. We send each email only to the services the customer set up, and we don't keep a copy. Once it arrives, that service holds the email under the customer's own agreement with it.
We process this data only on the customer's instructions, as described in section 7 of our Terms.
5. Who we share data with
We do not sell personal data or share it for advertising. We share it only with:
- Stripe, which processes payments for paid plans. Stripe acts as an independent controller for payment data; see Stripe's privacy policy.
- Service providers who host and run the Service for us, such as our hosting and database provider, our outbound email relay (for the account emails we send you), (if enabled) our CAPTCHA provider. They act on our instructions under contract.
- Your team: other members of your account can see your email address, role, 2FA status, last login, and your actions in the audit log (owners and admins).
- Professional advisers, regulators, law enforcement or courts where required by law or to protect our rights, users or the public.
- A buyer or successor if our business is reorganised or sold, under equivalent protections.
The sub-processors that handle email passing through the Service are listed in our Data Processing Agreement.
6. International transfers
Email passing through the Service is processed on servers in the United Kingdom. Some of our providers may process data outside the UK. Where they do, we use safeguards recognised under UK data protection law, such as adequacy regulations or the UK International Data Transfer Agreement or Addendum.
7. How long we keep data
| Data | Kept for |
|---|---|
| Account, team, domain and API key data | Until your account or the item is deleted |
| Login sessions | Up to 14 days, or until you log out |
| Email verification and password reset links | 48 hours and 1 hour respectively |
| Team invitations | 7 days unless accepted |
| Audit log entries | 90 days |
| Delivery log entries (inbound email metadata) | Your plan's delivery log period (up to 90 days) |
| Invoices and payment records | Six years, as UK tax law requires |
| Email content passing through the Service | Not stored |
| Server logs | A limited period for security and troubleshooting |
We may keep data longer where the law requires it or to deal with a dispute or abuse investigation.
8. Security
Connections are encrypted in transit. Passwords, API keys, session identifiers and recovery codes are stored only as hashes; webhook secrets, DKIM private keys and 2FA secrets are encrypted at rest. Access is restricted by role, 2FA is available (and can be required for your team), and account activity is audit-logged. No system is perfectly secure, but we work to protect your data and will tell you without undue delay about any breach that affects you.
9. Your rights
Under UK data protection law you can ask to access, correct, delete or receive a copy of your personal data, and to restrict or object to how we use it. To make a request, email hello@wildye.com. We will respond within one month. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ico.org.uk), though we'd appreciate the chance to help first.
10. Children
The Service is for businesses and developers and is not intended for anyone under 18.
11. Changes
We may update this policy. We will post the new version here with its effective date and, for significant changes, let you know by email or in the dashboard.
12. Contact
WILDYE LIMITED, a company registered in England and Wales. Email: hello@wildye.com.