Egret

Privacy Policy

Effective September 18, 2026

Egret (“we”) operates https://egretmail.dev. This policy describes how we handle information when you use the website, dashboard, MCP server, and Stripe App.

What we collect

  • Account identity from Clerk (name, email, user id) when you sign in.
  • Billing identity from Stripe Checkout and the Customer Portal (customer id, subscription status). We do not store card numbers.
  • Stripe account identity when you install the Egret Stripe App. We receive a signed payload (`user_id`, `account_id`) via fetchStripeSignature so we never ask you to paste API keys.
  • Settings you save (website URL, from name, reply-to). Website fetch and email content come later; until then we store the URL only.
  • MCP API keys (stored hashed). Requests to /mcp are authenticated with those keys and may include prompts your AI client sends.

How we use Stripe data

The Stripe App uses OAuth to read subscription, customer, and invoice data on the installing account so Egret can attach trial drips to the right people. We store OAuth tokens in Stripe Secret Store (account scope) in later milestones; we never ask you to paste a restricted key. We process Stripe data only to operate Egret for that installing account.

Email sending

When sending is enabled, we send through Resend on your behalf. We record send counts against your monthly 5,000-email cap. Recipients can unsubscribe; we honor CAN-SPAM and applicable anti-spam law.

MCP access

Your MCP URL and API key let AI clients you control call Egret tools and read skills. Anyone with the key can act as you. Revoke keys in the dashboard if they leak.

Contact

Questions: ryan@seaotter.dev. You can delete your account by emailing us; we will remove Clerk, Stripe customer, and Neon records we hold.