legal
Privacy Policy
This policy explains what information PostMe processes when you use https://www.postme.dev, create an account, set up an Intake, or submit a form that posts to our service.
Last updated September 3, 2026
This page is provided for transparency about how PostMe works. It is not legal advice. If you need advice for your situation, consult a qualified attorney.
Overview
PostMe (postme.dev) is a form-to-email service for static sites and simple HTML forms. We receive form submissions, deliver them to destinations you configure (email, webhook, Discord, or visitor auto-reply), store Inbox events for account holders, and keep only what we need to operate the service, bill paid plans, prevent abuse, and enforce usage limits.
Accounts
Creating an account uses Clerk for authentication. You may sign in with email, a password, or a third-party identity provider Clerk supports. We store a linked user record (name, email, Clerk user id, and plan) so we can show the console, apply plan limits, and contact you about the service.
Information we collect
Depending on how you interact with PostMe, we may process:
- Account identity — name, email, and authentication identifiers from Clerk.
- Billing information — subscription status and plan. Card details are processed by Stripe via Clerk Billing; we do not store full card numbers.
- Recipient email addresses — inboxes you register for confirmation and delivery.
- Form field contents — names, messages, and other fields submitted through your form, forwarded to your destinations and stored in Inbox for account-owned Intakes.
- Destination configuration — webhook URLs, Discord incoming webhook URLs, sending-domain DNS records, auto-reply templates, and webhook signing secrets.
- Technical metadata — timestamps, Origin/Referer, optional form configuration (subject, redirects), delivery outcomes, and pipeline logs.
- Network information — IP addresses used for rate limiting, abuse prevention, and confirmation-email throttling.
- Usage counts — per-user, per-endpoint, per-email-domain, and per-IP counters to enforce plan and anti-abuse limits.
Public /submit endpoints do not require an account. First use of a new inbox still requires email confirmation before we forward submissions. Account Intakes store events in Inbox; public submit traffic is not listed there.
How we use information
- Deliver form submissions to confirmed email destinations, HTTPS webhooks, Discord, and (on Pro) auto-reply from your sending domain.
- Send confirmation emails when an inbox is first used, and limit-reached notices when a monthly quota is exhausted.
- Operate the console: Intakes, destinations, Inbox, CSV export, and sending-domain setup.
- Process Hobby and Pro subscriptions through Clerk Billing and Stripe.
- Enforce monthly sending limits, rate limits, origin allowlists, and honeypot fields.
- Operate, secure, and improve the service — including debugging delivery issues and monitoring for abuse.
We do not sell your personal information. We do not use form submission content for advertising profiles.
Legal bases (EEA/UK visitors)
If you are in the European Economic Area or United Kingdom, we rely on: performance of a contract (providing the service you request); legitimate interests (security, abuse prevention, billing, and service improvement); and consent where applicable (for example, when you voluntarily submit a form on a third-party site that uses PostMe).
Service providers
We use trusted infrastructure partners to run PostMe. They process data on our behalf and only as needed to provide the service:
- Convex — application database and serverless backend hosting.
- Resend — transactional email delivery (confirmations, submission notifications, auto-reply, and limit notices).
- Vercel — website and API edge hosting for the public site and form endpoints.
- Clerk — authentication and subscription billing.
- Stripe — payment processing for paid plans (via Clerk Billing).
These providers may process data in the United States or other countries. We choose vendors with appropriate safeguards for production use.
Retention
We retain account records, endpoint records, Inbox events, delivery logs, and usage counters for as long as needed to operate the service, comply with law, resolve disputes, and enforce limits. Hobby Inbox rows are kept for a published number of days; Pro Inbox rows are kept until you delete them. We may delete or anonymize older data when it is no longer required for these purposes.
Security
We use industry-standard measures including encrypted transport (HTTPS), hashed verification tokens, HMAC signatures on console webhook destinations, rate limiting, and access controls on production systems. Origin allowlists use browser Origin/Referer headers and are not a complete security boundary. No method of transmission or storage is 100% secure; use Intakes instead of putting your inbox in a public URL, and monitor destinations for unexpected traffic.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. To make a request, email hi@postme.dev from the address concerned or describe the endpoint in question. We may need to verify your control of the inbox or account before acting on endpoint-related requests.
If you submitted a form on someone else's website, contact that site owner first — they control the form and how your message is used.
Children
PostMe is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children.
Changes
We may update this policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated by email or a site notice where appropriate.
Contact
Questions about privacy: hi@postme.dev. Website: https://www.postme.dev.