Cookie Policy
How mailkube uses cookies and similar tracking technologies.
Effective date: September 20, 2026
What is a Cookie
Cookies are files with a small amount of data which may include an anonymous unique identifier. They are sent to your browser from a website and stored on your device.
How mailkube Uses Cookies
mailkube uses cookies and similar technologies like local storage to track activity on our Service and hold certain information.
We distinguish between two categories of cookies and similar technologies:
- Essential: strictly necessary to provide the service you have asked us for, such as keeping you logged in, protecting our forms from abuse, or remembering a choice you have made. These are always active.
- Non-essential: used for analytics, product measurement, and session replay so we can understand usage and improve the Service. These do not run unless you consent to them.
Non-essential analytics and session replay are switched off by default and only run after you accept them. On this website the banner governs one purpose only, audience measurement. Any other non-essential tool carries its own control at the point you use it, so accepting the banner never turns anything else on. In the application dashboard you can change or withdraw your choice at any time, through the cookie preferences control there. On this website your choice is stored in your own browser, and you change it by clearing the data this site has stored, from your browser settings. Essential cookies are not consent-gated: they are limited to functionality you have asked for, and they are not used to track you or to build a profile of you.
The Cookies We Set
We use cookies provided by our internal identity and access management system when you are logged in, in order to maintain your authenticated session. This prevents you from having to log in every time you visit a new page. These cookies are removed or invalidated when you log out, ensuring that protected features are only accessible to authenticated users.
We do not set any cookie to decide which prices to show you. Our edge network works out which region your connection comes from, using the country our content-delivery provider reports for it, and puts the answer into the page it sends you so that the pricing page can show the right band and currency instead of defaulting to US dollars. That happens once per page, on our side, and nothing is stored on your device for it. We describe the handling of your connection details, including your IP address, in our Privacy Policy.
Alongside cookies, this website keeps three small values in your browser’s local storage. Each one records a choice you made, none of them is sent to us, and none is used to track you or to build a profile of you: your answer to the cookie banner, so we do not ask again and so we know whether analytics may run; the language you picked with the language switcher; and whether you last looked at monthly or yearly prices, so the pricing page opens the way you left it. They stay until you clear your browser storage.
Third-Party Cookies and Connections
Some cookies and similar technologies are set by third parties we rely on. Some third parties receive your connection details without storing anything on your device at all, and we list those here too, because the effect on your privacy is the same. We group them below by where they run and whether they are essential.
On our website
- Google Analytics 4 (analytics, non-essential): measures how visitors use our website. It is loaded through Google Consent Mode and stays disabled until you accept analytics cookies.
- Cloudflare Turnstile (security, essential): protects our contact, careers, job-application, signup, and waitlist forms from spam and automated abuse. It replaced Google reCAPTCHA Enterprise in August 2026. It sets no cookies and stores nothing on your device; what it receives is your IP address, the technical fingerprint of your connection, your browser’s user-agent string, and the identifier of the form. It is always active rather than consent-gated, for three reasons: protecting a form from unbounded automated submission is strictly necessary to the service you asked for, and securing the site is a purpose that needs no consent in its own right; the signals serve only the job of telling a person from a script, with no advertising or profiling attached; and Cloudflare already runs the network this website is served through, so it receives that same connection data on every page you load in any case. Nothing loads until you begin filling in a form.
- Atlassian Statuspage (service status, essential): hosts our public status page. It loads only on that page, where your browser fetches the current status directly from mailkube.statuspage.io, so Atlassian receives your IP address and request metadata as the recipient of that request. It is not consent-gated because nothing is stored on your device for it and nothing already stored there is read: the request is a plain cross-origin fetch with no cookie, so there is no storage or access on your device for which consent could be asked. Atlassian still receives your address, which is why the service is listed here.
- Stripe (payments, essential): takes payment when you buy a subscription. Nothing from Stripe loads on our pages and nothing is stored on your device for it here. When you start a purchase we send you to Stripe’s own checkout page at checkout.stripe.com, which is Stripe’s site and not ours, so what it stores on your device there and what it receives are governed by Stripe’s own policy rather than this one. It is listed here because Stripe receives your connection details at that point, and so that the redirect is not a surprise. For more information, see the Stripe Privacy Policy.
On the sign-in and registration pages
These pages are served from a separate address to the rest of the website, and until August 2026 nothing in this policy described them. Two things run there.
- Cloudflare Turnstile (security, essential): protects the registration form from automated account creation, on the same terms as the website forms above. It loads on that one page. The sign-in, password-reset and one-time-code pages do not load it.
- Sign in with Google (authentication, essential): only if you choose it. Selecting it sends you to Google to authenticate, and Google then tells us who you are. Nothing reaches Google unless you pick that option; signing in with an email address and password involves it not at all.
In the app dashboard
- Amplitude (product analytics, non-essential): measures how you, as the account holder, use the dashboard so we can improve it. It is limited to your own account activity and stays disabled until you accept analytics.
- Firebase (Google) (realtime updates, essential): delivers realtime change notifications to the logged-in dashboard, so that a counter or a list updates as soon as the underlying record does. Your browser connects directly to Google’s servers, which therefore receive your IP address and device signals as the recipient of that connection. The documents it carries hold only internal record identifiers and counters, never message content, recipient data, or personal details. Two things happen here and they have separate answers. The realtime channel itself stores nothing on your device and reads nothing already stored there. Signing the dashboard in to that channel does store a token on your device, and that token is exempt from consent because it does one job only, authenticating you to the service you asked for; it is not used for measurement or for anything else.
- Sentry (error monitoring): captures error diagnostics so we can detect and fix problems. Basic error capture is essential and always active; optional session replay is non-essential and only runs after you accept it.
Google (Google Analytics and Firebase), Amplitude, Sentry, Atlassian, and Cloudflare are US-linked providers; the resulting transfers are covered by appropriate safeguards as described in our Privacy Policy.
Email Open and Click Tracking
This policy covers our website and dashboard. It does not cover the open and click tracking in emails our customers send through the Service.
Where a sending customer enables tracking, opening a message or following a link in it records that it happened, at a time, and the link followed. Two further per-domain settings, both off unless the sending customer turns them on, add the recipient’s IP address and the country it resolves to, and the recipient’s browser or mail client. That tracking is configured by the customer sending the message, and it is the customer, not mailkube, who is responsible for having any consent that applies where their recipient is located. mailkube processes all of it on the customer’s behalf under our Data Processing Addendum and for no purpose of its own; the full position is set out in the notice for email recipients. If you received a message and want it to stop, contact the sender or use the unsubscribe link in the message.
Contact
For questions about this policy, contact us at privacy@mailkube.com.