Privacy Policy
Last updated
Who we are
In this policy, “Rasket”, “we” and “us” mean the company that operates Rasket.
Rasket is an API and dashboard for sending and receiving email. This policy covers the website, the dashboard, the API, and the email our customers send through us. It explains what we collect, why, how long we keep it, and who helps us run the service.
Our role
For your Rasket account, your use of the website and the dashboard, and billing, we decide how personal data is used.
For the email a customer sends or receives through Rasket, and for the contacts, recipients and content that go with it, the customer decides and we process that data on their behalf to provide the service. If you received email from a Rasket customer, see If you received email sent through Rasket.
What we collect
Your account
Your email address and, if you give one, your name. We store your password only as an Argon2id hash. If you sign in with a third-party account we receive your account identifier, your verified email address and your name from that provider; if your team uses single sign-on, we receive the same from your organisation’s identity provider. If you turn on two-factor authentication, its secret is stored encrypted.
Sign-in and security records
Each session records the IP address, the browser’s user agent and when it was last used. Each sign-in attempt, successful or not, is recorded with its time, IP address, country, browser and whether a second factor was used. We use these records to protect your account and to spot accounts that belong together. Changes made in a team — keys created, domains added, settings changed — are written to an audit log with who made them, when, and from which IP address.
When you create an account with a password we record where the sign-up came from: the IP address, the country our hosting provider reports for it, the browser’s user agent, the result of our automated check for scripted sign-ups, and whether we sent the confirmation email. We also keep a one-way hash of your email address, which lets us recognise the same inbox again but is still personal data. We use this to stop automated sign-ups and to avoid emailing people who never asked for an account.
Billing
Payments are handled by our payment processor. We never see or store your card number: we keep your customer identifier with the processor, whether a payment method is on file, and its brand and last four digits, together with your plan, usage and invoices. We also keep a one-way hash of the card fingerprint the processor gives us, so we can tell when two accounts pay with the same card.
API requests
For each API request we log the method, path, response status, IP address, user agent and timing, with the request body after credentials are removed and attachment content is replaced by its name, size and hash.
Email, contacts and content
To deliver and report on a customer’s email we store the sender, recipients, subject, HTML and text bodies, attachments and the delivery events that follow (such as delivered, bounced or complained). Where a customer receives email through Rasket, we store the messages and attachments sent to them. Customers can also store contacts, contact properties, topic subscriptions, templates, campaigns and automations.
If you use Rasket Inbox, we store the mail your mailboxes receive and send — including attachments — until you delete it or close the mailbox. A closed mailbox is kept for 30 days so it can still be exported, and is then deleted. You can export a mailbox at any time. An admin administers the list of addresses; no admin can read another person’s own mailbox.
AI assist
AI assist is off until a team admin turns it on. When it is used, the text needed for the task is sent to a third-party AI provider: the brief and template for a subject line or draft, or, to diagnose a message, its subject, sending domain, statuses, event timeline and each recipient’s domain — never a recipient’s address. We keep a record of each request (its kind, model, token counts, timing and status, and the stored result of a diagnosis), not the prompt text.
Support
When you write to us from the dashboard’s help panel, your message and any files you attach are emailed to our support team.
When you use the contact form on our website, we keep the name, email address and company you give us and your message as a support conversation, so that a person can reply to you by email. We use them only to answer you, and we delete them if you ask.
The website
We use a third-party web analytics provider on our website (the public pages, the documentation and the sign-in pages, never the dashboard or the Inbox) to learn how people find the site and which pages and steps they use. It records the pages you visit, the site or campaign that sent you, your browser and device type, an approximate location derived from your IP address, and steps such as choosing a plan or starting a checkout. We do not send it your name or email address, and we strip sign-in and invitation links of their tokens before anything is sent. The provider keeps this data for 14 months.
If you are in the European Economic Area, the United Kingdom or Switzerland, or we cannot tell where you are, website analytics is not loaded and sets no cookie until you choose Accept in the cookie banner; if you decline, it is never loaded. Elsewhere it loads when you visit, unless your browser sends a Global Privacy Control signal. You can change your choice at any time with “Cookie settings” at the bottom of the website. The provider’s advertising features are always off: the data is not used for ads, remarketing or ad personalisation.
When a browser that allowed analytics creates an account, signs in, or becomes the account that pays for a plan, sends its first email or verifies its first domain, our servers tell the analytics provider that the step happened. They send the random identifier from that browser’s analytics cookie, which we keep with your account for this, a one-way hash of your account identifier, and the step’s own details: the sign-in method, or for a payment the invoice number, amount, currency and plan. A browser that declined sends nothing of this, and signing in from it removes the identifier we kept.
We also use a third-party tag manager on our marketing pages and documentation, never on the sign-in pages, the dashboard or the Inbox, to load measurement tags without changing the website. It is loaded under the same choice as website analytics: in the European Economic Area, the United Kingdom and Switzerland, or where we cannot tell where you are, only after you choose Accept, and if you decline it is not loaded again. Its advertising features stay off.
The website runs no advertising or other third-party tracking scripts. Our hosting provider keeps request logs, such as the IP address and the page requested, to operate and secure the service.
If you received email sent through Rasket
The customer who sent it decides who receives their email and what it says; we deliver it for them. To deliver it we process your email address, the message itself and what happened to it — whether it was delivered, bounced, or reported as spam.
- Open and click tracking is off unless the sender turns it on for their domain. When it is on, opening the email or clicking a link in it records the time, your IP address and your user agent (and, for a click, the link), and passes them to the sender.
- If you unsubscribe or change your preferences on our hosted page, we record what you chose, when, your IP address and your user agent, alongside a hash of your email address. That record is how the sender shows they respected your choice.
- An address that bounces permanently or reports a message as spam is added to the sender’s suppression list, and Rasket does not send to it for that sender while it stays there.
To access, correct or delete what a sender holds about you, contact the sender. To report email sent through Rasket that you did not ask for, write to info@rasket.com.
Mailboxes
Your team’s admins decide who can read what. A shared channel is visible to the members they choose; a personal mailbox is visible only to the member it belongs to. An admin cannot read a personal mailbox that is not theirs. When a personal mailbox is closed, an admin can download an archive of it so the team keeps the correspondence, and that download is recorded.
Rasket staff do not read your mail. We open a message only when you report it to us, when our checks stop it, or when we have to in order to keep the service running — and each time is recorded against the person who did it, with their reason.
We give mail to a public authority only when the law requires it, and we tell the team unless we are not allowed to.
Reports you send to abuse@rasket.com, or file with Report on a message, are kept with the message they concern for 12 months.
Connected apps and AI assistants
You can connect an app to your Rasket team: an AI assistant such as Claude or ChatGPT through our MCP server, or any other app that signs in to Rasket with OAuth. Nothing is shared with an app until an admin of the team approves it on Rasket’s consent screen, which names the app, the team it will act for and every permission it asks for.
- An approved app receives an access token for that one team, carrying only the permissions the admin approved. It never receives your password or an API key.
- What it can see or do depends on those permissions — for example, reading the email your team has sent and how it was delivered, reading your contacts, or sending email from your verified domains. Each permission is described in the OAuth documentation.
- No permission lets an app create or revoke API keys, change your plan, billing or team members, delete sent mail, or manage which apps are connected.
- What an app reads from Rasket goes to that app and to whoever runs it — for an AI assistant, the company that provides it. From then on, that company’s own terms and privacy policy decide what happens to it.
- Requests an app makes are logged like any other API request, and kept for the same 30 days.
To disconnect an app, go to Settings → Team → Authorized apps in the dashboard, which lists every app that can act for the team, and choose Revoke. Every token the app holds stops working at once. An access token lasts an hour and a refresh token 30 days, so an app the team stops using loses access on its own. A revoked or expired token is deleted 30 days later, and the record of the approval — which app, which permissions, when — 90 days after it is revoked.
If your team connects a team chat app for alerts, Rasket keeps the workspace’s name and id, an encrypted access token, the channel each alert goes to, and which people there are which members of your team. It posts the alerts your team chooses to the channels you pick: names and numbers, never the content of an email. The chat app is a destination you choose, not a provider that works for us, and its own terms and privacy policy cover what is posted there. Alerts are deleted from Rasket a week after they are posted, and everything else when your team disconnects the app.
If your team connects a website builder, Rasket keeps an encrypted access token, the name of the person who approved it, and each connected site’s name, domains and form names. It receives the submissions of the forms your team turns on and, if your team turns store orders on, new orders, and keeps what your team’s settings say to keep: contacts, their consent records and store events. It adds its script to your sites. The token is deleted when your team disconnects the website builder or removes the app there.
We do not sell personal data, and we do not give a connected app anything its permissions do not cover.
How we use it
- To provide the service: accept, send, receive and report on email.
- To keep accounts secure and prevent abuse: checking messages for phishing and malware patterns, and watching bounce and complaint rates so that a sender who harms other senders’ delivery is restricted.
- To bill for paid plans and usage.
- To answer support requests and send the email the service needs, such as address verification and password resets.
- To meet legal, tax and accounting obligations.
How long we keep it
Retention is set per plan and enforced by a nightly deletion job. Email data is deleted, not just hidden, when its window ends.
| Data | Kept for |
|---|---|
| Email metadata, bodies, attachments and events; API request logs; webhook deliveries | 30 days on every self-serve plan; Enterprise teams can agree a different window |
| Mail your mailboxes receive and send | Until you delete it or the mailbox is full; a closed mailbox is kept 30 days for export, then deleted |
| Contact import files | 7 days after the import completes |
| AI assist records, automation run history, raw delivery notifications from our email delivery provider, platform metrics | 90 days |
| Unsubscribe and consent records | 3 years after the consent expires |
| Messages sent through the website’s contact form | Until you ask us to delete them |
| Audit logs, the usage ledger and billing records | 7 years |
| Your account, team, domains, contacts, templates and suppression list | Until you delete them, or the team is deleted |
| An account whose email address was never confirmed and that was never used, with its empty team | May be deleted 7 days after sign-up |
| Sign-in sessions | 30 days at most, and 7 days without use |
| Sign-up records | 90 days, even if the account is deleted sooner |
| Sign-in records and the card fingerprint hash | 1 year |
Deleted data can remain in database backups for up to 90 days. Backups are used only to recover from a disaster, never to answer a customer request. We may keep a team’s data beyond these periods while it is subject to a legal dispute, a lawful request or an abuse investigation.
Third parties that help us run the service
We use trusted third-party providers to run Rasket. They process personal data for us only to provide the service, and only the data their part of it needs. Our Data Processing Addendum covers the data we process for customers.
| Kind of provider | What they receive | Why |
|---|---|---|
| Hosting and file storage | Everything the website, dashboard and API handle, including attachments, raw messages and exports | To run the service and store its files |
| Database hosting | The data the service stores | To keep the service’s database |
| Background jobs | Each job’s message and result until it has run | To queue and schedule the work that sends, receives and reports on email |
| Email delivery | Messages, their senders and recipients, and delivery events; received messages briefly until processed | To send and receive email, including over SMTP |
| Payments | Billing details, payment method and invoices | To take payments and run the billing portal |
| Sign-in | Your account identifier, email address and name | Only if you choose to sign in with another account |
| DNS | Your domain names and their DNS records | To verify domains, and to apply records if you connect a DNS provider |
| AI features | The text needed for the task, never a recipient’s address | To answer AI assist requests when a team has turned it on, and help-assistant questions |
| Website analytics | Pages visited on our website, how you arrived, device and browser type, approximate location, an analytics identifier, and the account steps listed above, never your name or email address | To learn how people find and use the website, only with your consent where the law asks for it |
Each provider is bound by a contract, including data processing terms, that limits what it may do with the data, requires it to keep the data confidential and secure, and forbids it to use the data for its own purposes. We do not sell personal data. We do not name our providers here. The current list is available on request: Request more information, or write to info@rasket.com.
Our application and database run in the United States, so personal data from other countries is transferred there, and some providers process it in other countries too. Where the law that applies to you requires it, we protect those transfers with the Standard Contractual Clauses approved by the European Commission, or the equivalent mechanism that law recognises.
Security
- Connections to Rasket, and from Rasket to its database and storage, use TLS.
- The database is encrypted at rest, and every team’s rows are separated by row-level security in the database as well as by the application.
- Passwords are hashed with Argon2id; API keys are shown once and stored only as hashes.
- Webhook signing secrets, DKIM private keys, two-factor secrets and single sign-on client secrets are encrypted with AES-256-GCM, each under its own data key.
- Every member can turn on two-factor authentication, and teams can require OpenID Connect single sign-on on the Scale plan (as an add-on) and Enterprise.
- Our logs leave out credentials, cookies and email bodies.
Your choices and rights
- You can reset your password from the sign-in page and turn two-factor authentication on or off in the dashboard.
- A team decides whether AI assist is on, and whether open and click tracking is on for each of its domains. Both are off by default.
- Customers can delete a contact through the dashboard or the API; its personal data is removed and only the hashed consent record remains.
- A project’s admin can download a copy of the project’s data, or delete the project, from Settings → Data in the dashboard. The export is a file of the project’s data that can be downloaded for 7 days. Deleting a project stops its sending immediately and erases its data 30 days later, and any admin can cancel it until then. These are how you use your rights of access, portability and erasure for a project’s data.
- Deleting your own account is available on request: write to info@rasket.com from the account’s email address.
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how it is used, and to complain to a data protection authority. Write to us to use any of them.
Cookies
Rasket sets no advertising cookies. The cookies below that are needed to sign you in are set only when you sign in. The analytics cookies are set only as described above: after you accept them, or, outside the European Economic Area, the United Kingdom and Switzerland, unless you decline. We remember your choice in one more cookie.
| Cookie | Purpose | Lasts |
|---|---|---|
| rsk_session | Keeps you signed in | 30 days, or 7 days without use |
| rsk_theme | Remembers whether you chose the light or the dark appearance | 1 year |
| rsk_mfa | Carries you from your password to your two-factor code | 5 minutes |
| rsk_oauth | Protects a sign-in with a third-party account | 10 minutes |
| rsk_sso | Protects a single sign-on sign-in | 10 minutes |
| Website analytics cookies | Set by our website analytics provider: tell one browser from another with a random identifier, and keep track of the current visit | Up to 2 years |
| rasket_consent | Remembers whether you accepted or declined analytics cookies | 1 year |
The website also remembers a few display choices in your browser’s local storage, such as the code language you picked in the documentation.
To learn more about the cookies our providers set, Request more information.
Changes to this policy
When this policy changes we update the date at the top of this page. The Terms of Service describe what you agree to when you use Rasket, and the Acceptable Use Policy says what you may send.
Contact
Questions about this policy or your data: info@rasket.com. For help with your account: support@rasket.com. To report abuse from a Rasket mailbox or a message sent through Rasket: abuse@rasket.com.