Privacy Policy
Last updated: May 5, 2026
Postlark is operated by Horizon Analytic Studios, LLC ("we," "us," or "our"). This Privacy Policy describes how we collect, use, and protect your personal information when you use the Postlark website at postlark.io and the Postlark email verification API.
Information We Collect
- Account information — your email address and authentication credentials when you sign up for Postlark.
- API usage data — request metadata (timestamp, hashed API key, endpoint, response status, request id) for support and abuse-prevention purposes.
- Email addresses you submit for verification — see "Verification Data" below.
- Billing information — payment is processed by Stripe. We never see or store full card numbers; we receive limited information from Stripe (last 4 digits, brand, expiration) for display in the dashboard.
- Server logs — standard web server logs including IP addresses, browser type, and pages visited.
Verification Data
Email addresses you submit to the Postlark API for verification are processed for the purpose of returning a verification verdict. Verdicts are stored in a short-lived cache (default 7 days) so that repeat lookups for the same address don't incur additional API calls or third-party requests; after that window, cached entries are purged. We do not retain the contents of any messages you send or receive — only the address itself, which is hashed for cache lookup.
We do not sell, share, or otherwise disclose verification data to third parties for marketing or any purpose unrelated to providing the Postlark service.
How We Use Your Information
- To provide and maintain the Postlark service
- To process payments and manage subscriptions (via Stripe)
- To send transactional emails (account confirmation, password reset, billing notifications)
- To respond to support inquiries
- To detect and prevent abuse, fraud, and policy violations
- To comply with legal obligations
Data Sharing
We do not sell, trade, or rent your personal information. We share information with the following service providers, each subject to appropriate data-protection agreements:
- Stripe — payment processing, billing, and subscription management.
- Postmark — sending transactional emails.
- Amazon Web Services (AWS) — hosting, storage, and infrastructure.
- Cloudflare — DNS and DDoS protection.
We may also disclose information when required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Horizon Analytic Studios, our users, or others.
Data Security
We implement reasonable technical and organizational measures to protect your information: encryption in transit (TLS 1.2+), encryption at rest (AWS-managed KMS), API keys hashed at rest using Argon2id, isolated production credentials, and the principle of least privilege for internal access.
Data Retention
- Account data — retained while your account is active; deleted on account closure.
- Verification cache — TTL of 7 days, then purged.
- Audit log — API request metadata retained for 90 days for support and abuse prevention.
- Billing records — retained as required by tax and accounting law.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, port, or delete your personal information. You may exercise these rights by signing in to your account and using the dashboard, or by emailing info@postlark.io.
Account deletion is available from the dashboard and is immediate and irreversible — your account, API keys, billing records, and any cached verification results are removed.
Children's Privacy
Postlark is not directed to children under 13, and we do not knowingly collect information from children under 13. If we learn we have collected such information, we will delete it.
International Data Transfers
Postlark is operated from the United States. By using the service from outside the U.S., you consent to your information being transferred to and processed in the U.S.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and reflected in the "Last updated" date above.
Contact
For questions about this Privacy Policy or our data practices, contact us at info@postlark.io or via our contact form.