agent·herald
Terms Privacy Acceptable Use Security Subprocessors

Legal

Privacy Policy

Effective 20 August 2026 · MB Tafe

We are established in Lithuania, so the GDPR is the regime this policy is written to. It covers two different relationships: our own, with the people who hold accounts, and our role handling message data on their behalf.

On this page
1. Who we are 2. Two roles 3. Account data 4. Message data 5. Technical data 6. Cookies and the website 7. How long we keep things 8. Who else sees it 9. International transfers 10. If you received mail 11. Your rights 12. Security 13. Changes 14. Contact

1. Who we are

MB Tafe, registration code 308026391, Laisvės al. 85E-5, Kaunas, Lithuania, operates Agent Herald at agentherald.dev.

For privacy questions, write to [email protected].

2. Two roles

This distinction runs through everything below, so it is worth stating first.

We are a controller for data about the people who hold accounts with us — your name, your email address, your billing details, how you use the service. We decide what to collect and why, and this policy governs it.

We are a processor for the contents of the mail you send and receive. The recipients of your mail are your contacts, not ours. We hold that data because you instructed us to send or receive it, we act on your instructions, and we do not use it for our own purposes. Your obligations to those people are yours; ours are to you, and are set out in our Terms.

We do not sell personal data. We do not use message content to train machine learning models, our own or anyone else's. We do not build advertising profiles.

3. Account data

WhatWhyLegal basis
Email addressIdentifying your account, sending sign-in codes, service noticesPerformance of a contract
Name, where givenAddressing youPerformance of a contract
Domains you add and their DNS recordsVerifying you control the domain you send fromPerformance of a contract
API keys, hashedAuthenticating your requestsPerformance of a contract
Provider credentials you supplySending through your own provider account, where you choose thatPerformance of a contract
Audit log of account actionsSecurity, abuse investigation, answering "who changed this"Legitimate interests
Sending statisticsShowing you your numbers, enforcing deliverability thresholdsLegitimate interests

Our legitimate interests above are keeping the platform secure and keeping its sending reputation intact. We think these are interests you share, since the alternative is a platform that does not deliver mail.

4. Message data

When you send a message we process its sender, recipients, subject, body, attachments and headers, together with delivery events returned by the sending provider — accepted, delivered, bounced, complained, deferred.

When you receive a message on a domain you have configured for inbound mail, we process the raw message and the parsed version of it.

We hold this because you instructed us to. The legal basis for your own processing of it — your relationship with your recipients — is yours to establish, and our Acceptable Use Policy requires you to be able to.

We access message content only to operate and debug the service, to respond to a support request you have made, or where we are investigating a specific abuse report or legal obligation. Access is logged.

5. Technical data

Our servers keep operational logs — IP address, timestamp, endpoint, response status, user agent — for security, debugging and abuse investigation, on the basis of our legitimate interests. Application logs record events, not message bodies.

6. Cookies and the website

The site sets a session cookie and a CSRF token cookie. Both are strictly necessary to keep you signed in and to prevent request forgery, so neither requires consent and there is no cookie banner to click.

We run no analytics, no advertising pixels and no third-party trackers. Nobody is measuring your scroll depth.

Webfonts are served by fonts.bunny.net, a privacy-focused font host that does not log requests or set cookies. If it is unreachable, the pages fall back to your system fonts and nothing else changes.

7. How long we keep things

WhatKept for
Message content — bodies, attachments, raw inbound mail30 days, then deleted
Message metadata — recipients, subject, delivery events365 days, then deleted
Suppression entriesFor the life of the account — deleting them would mean mailing people who asked you to stop
Audit logsFor the life of the account
Account dataUntil you close the account, then deleted within 30 days except where we must keep records to meet a legal obligation

Content retention is short by design. The less message content we hold, the less there is to lose.

8. Who else sees it

A short list of vendors, each named with what they do and where they are, is maintained at Subprocessors. We self-host our database, queues, authentication and webhook delivery rather than buying them, which is why that list is shorter than you might expect.

We otherwise disclose personal data only where we are legally compelled to, and where we may lawfully tell you about it, we will.

9. International transfers

Message content, message metadata and application data are stored in the European Union — our infrastructure runs in Ireland and our host is Lithuanian.

Some vendors on the subprocessor list have parent companies outside the EU. Where a transfer outside the EEA occurs, it is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, as noted against each entry.

10. If you received mail sent through us

If a message reached you via Agent Herald and you want it stopped, corrected or deleted, the person to ask is the sender — they decided to write to you, and under the GDPR they are the controller of that decision. Their identity is in the message.

If you cannot reach them, or the mail should not have been sent at all, write to [email protected] with the message headers. We will suppress your address so nothing further reaches you from that account, and act under the Acceptable Use Policy if the mail broke it.

11. Your rights

Under the GDPR you may request access to your personal data, correction of it, erasure, restriction of processing, portability of data you gave us, and you may object to processing we base on legitimate interests. Where processing rests on consent, you can withdraw it at any time without affecting what came before.

Write to [email protected]. We respond within one month, and will say so if a request is complex enough to need the extension the GDPR allows. We do not charge for this.

If you are unhappy with how we handled it, you may complain to the Lithuanian supervisory authority, the Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), or to the authority where you live.

12. Security

The controls we run are described in detail on the Security page, including what we have not yet done.

Where a personal data breach is likely to result in a risk to people's rights, we notify the supervisory authority within 72 hours of becoming aware of it, and affected customers without undue delay.

13. Changes

When this policy changes materially we update the effective date at the top and notify account holders by email before it takes effect. Minor corrections happen without notice.

14. Contact

MB Tafe
Laisvės al. 85E-5, Kaunas, Lithuania
[email protected]

agent·herald

Transactional email and an MCP server for AI agents.
agentherald.dev

MB Tafe
Registration code 308026391
Laisvės al. 85E-5, Kaunas, Lithuania

Report abuse: [email protected]

Product
Capabilities Setup MCP Install Limits
Account
Create an account Log in
Legal
Terms of Service Privacy Policy Acceptable Use Security Subprocessors