Security
Last updated October 4, 2026
MailQL reads email that businesses forward to it, so it's built on the assumption that every email is from a stranger. Here's what happens to yours, and what we've done to keep it yours.
When an email arrives
- Each mailbox has its own address with 6 random characters in it, so nobody can find yours by guessing.
- Mail to an address that doesn't exist, or to a paused mailbox, is dropped before anything is stored.
- Mail flagged as a virus is dropped. Mail flagged as spam is set aside with only its sender and subject kept, and is never read into your table.
- A mailbox accepts at most 500 emails an hour, so a flood can't run up your usage.
- MailQL never sends or forwards mail from your mailboxes, so an address can't be used to send spam.
Where it's kept
- Everything runs on Amazon Web Services in the US (Ohio, us-east-2).
- The raw email is stored encrypted (AES-256) and deleted automatically after 30 days.
- What's read from it, your rows, is stored encrypted in Amazon Aurora DSQL until you delete it. Deleting a mailbox deletes its emails, rows, saved views and outputs.
- Webhook signing secrets and Google sign-in tokens are encrypted a second time, with AES-256-GCM, using a key that lives only in the application's environment.
- The site is HTTPS only, with HSTS.
The AI that reads your email
- MailQL uses Anthropic's Claude, through Anthropic's API, to fill in your columns. The email's text and attachments (PDFs and images) are sent to Anthropic for that.
- Under Anthropic's commercial terms, inputs and outputs aren't used to train its models by default. Anthropic deletes them within 30 days, except where it must keep them longer to enforce its Usage Policy or to comply with the law.
- The call that reads an email has no tools and can only return your columns. An email that tries to give the AI instructions can at worst put a wrong value in its own row, and values the AI wasn't sure of are marked for you to check.
- Questions you ask are answered by having Claude write a database query from your column names and a few sample values. It never sees your emails for this. The query runs on a separate, read-only copy of that one mailbox's rows, in its own process, which is stopped after 5 seconds. It can't reach anyone else's data, or anything else of yours.
Sending rows elsewhere
- Webhooks are HTTPS only and signed (HMAC-SHA256), so your receiver can check that a request came from MailQL. Redirects aren't followed. Private and internal network addresses are refused, both when you add a URL and every time it's called.
- Google Sheets uses Google's narrowest permission: MailQL can see and edit only the spreadsheets it creates, nothing else in your Drive. Values are written as plain values, so text in an email can never become a spreadsheet formula.
Your account
- There are no passwords. You sign in with a code or link sent to your email, which works once, for 15 minutes. Codes stop working after 5 wrong tries.
- Sign-in links and sessions are stored only as one-way hashes, so a copy of the database can't be used to sign in.
- The session cookie is HttpOnly, Secure and SameSite=Lax, and forms check their origin.
- Pages load no third-party scripts, analytics or trackers, and a strict content security policy stops anything from sending your data to another site.
- Payments go through Stripe. Card numbers never reach MailQL.
Reporting a problem
If you think you've found a security issue, email security@mailql.com. We'll reply within two business days and keep you posted while we fix it. Please don't access other people's data or disrupt the service while testing.