Skip to content
pharos
featuresdeliverabilitypricingdocsblog
sign in start free
featuresdeliverabilitypricingdocsblog sign in

Legal

Acceptable Use PolicyTerms of ServicePrivacy Policy

On this page

1 · Who we are2 · Controller and processor3 · Account data4 · Message data5 · Website and cookies6 · How long we keep things7 · Who else processes it8 · International transfers9 · Your rights10 · Security11 · Changes

Privacy Policy

Version 1.0· Effective 12 September 2026· Last updated 12 September 2026

This policy describes what Pharos does with personal data. It covers two quite different things — the data we hold about you as a customer, and the data inside the messages you send through us — and the distinction matters, so they are in separate sections.

Where something is not true yet, this document says so rather than leaving it out.

1 · Who we are

Pharos, LLC operates the Pharos transactional email gateway and the pharos.email website.

For anything in this policy, including a request about your own data, write to privacy@pharos.email. A person reads it.

2 · Controller and processor

For account data, Pharos is the controller. We decide what we collect about you as a customer and why — your registration details, your billing relationship, your support correspondence.

For message data, Pharos is a processor and you are the controller. When you send a message through us, the recipient's address and whatever personal data your message contains belong to your relationship with that recipient, not ours. We process them on your instructions — the instruction being the API call or SMTP submission — for the purpose of delivering the message and reporting what happened to it. We do not decide what you send, to whom, or why, and we do not use message data for our own purposes.

There is no published Data Processing Addendum yet. If you need one for your own compliance, write to privacy@pharos.email and we will tell you exactly where it stands rather than sending you a template we have not stood behind.

3 · Account data

To give you an account we collect:

  • Identity and contact details — your name and email address.
  • Authentication data — a hashed password, and the API keys issued to your account.
  • Sending domains — the domains you verify, and the DNS records we check to verify them.
  • Usage data — how much you have sent against your plan allowance.
  • Billing data — your plan, invoices, and the billing identifiers our payment processor gives us. We do not receive or store your card number. The card goes to the payment processor and stays with them.
  • Support correspondence — what you write to us and what we write back.
  • Technical records — IP addresses and timestamps from sign-ins and API calls, kept for security and abuse investigation.

We use this to run your account, bill you, answer you, keep the service secure, and send you the operational notices the Terms require — such as telling you when your sending moved you up a tier. Our basis for it is performing our contract with you, and our legitimate interest in securing the service and preventing abuse.

We do not sell your personal data. We do not share it for anyone else's advertising.

4 · Message data

When you send a message we process what you give us: the recipient address, the sender address, the subject, the body, any headers and attachments, and the metadata the delivery itself produces — timestamps, the receiving server's response, and whether the message was delivered, bounced, deferred or complained about.

We process it to deliver the message, to show you what happened to it in your event log, to maintain your suppression list, and to investigate abuse reports about your sending. Nothing else.

If you enable open or click tracking, we record those events against the message and the recipient. That is your choice and your responsibility to disclose to your own recipients — it is their personal data, and you are its controller.

5 · Website, cookies and analytics

This site sets one cookie, and it is the one recording your answer to the consent banner. It is called pharos_consent, it holds a single word — whether you accepted or rejected — and it lasts 90 days so you are not asked again on every visit. It is a first-party cookie, it contains no identifier for you, and it is never sent anywhere.

If you reject, analytics does not load. Nothing is recorded about your visit beyond the ordinary server request. If you accept, we load a privacy-focused analytics provider that counts page views without cookies of its own, without a persistent identifier for you, and without following you to other websites.

There is no advertising network on this site, no cross-site tracking, and no third-party cookies at all.

If you submit the contact or signup form, we receive what you typed and the email address you gave us, and we use it to reply to you.

6 · How long we keep things

Delivery events are retained for 120 days, on every plan including the free one. That is the window in which you can see, search and export what happened to a message.

Message content is kept only as long as it is needed to deliver the message and to support the delivery record. We are describing this in general terms deliberately: we would rather say less than publish a specific number we cannot yet stand behind. When we have established and verified a precise window, it will be stated here as a figure.

Suppression lists persist for the life of your account. That is the point of them — an address that hard-bounced or complained stays suppressed so you do not send to it again.

Account and billing records are kept while your account is open, and afterwards for as long as we need them to meet tax, accounting and legal obligations, or to resolve a dispute.

The consent cookie lasts 90 days, after which the banner asks again. Clearing your browser's cookies for this site removes it and resets the question.

Deleted data may persist in backups for a period after deletion before those backups age out.

7 · Who else processes it

Running the service means other companies process some of this data on our behalf. We use them in these categories:

  • Outbound email delivery — the infrastructure that transmits your messages to recipient mail servers.
  • Hosting and infrastructure — the servers the application runs on.
  • Edge networking and TLS — the network in front of the website and the application.
  • Payments — the processor that handles cards and invoices.
  • Website analytics — the cookieless provider described in section 5.

Each is bound to process data only on our instructions. We do not publish the individual company names. If you need the full list for a procurement or security review, ask at privacy@pharos.email and we will provide it under a confidentiality agreement.

We will also disclose data where the law requires it — a valid court order, subpoena or lawful government request — or where disclosure is necessary to protect the rights or safety of Pharos, our customers or the public. Where we are permitted to tell you about such a request, we will.

If Pharos is acquired or merges with another company, customer data would transfer as part of the business, and this policy would continue to apply to it until you were told otherwise.

8 · International transfers

Pharos, LLC is a United States company, and data is processed in the United States and in Europe depending on the part of the service.

We do not currently offer guaranteed EU data residency. If in-region processing is a requirement for you, tell us before you sign up — it affects whether Pharos is the right choice for you, and we would rather say so early.

9 · Your rights

Depending on where you live, you may have the right to ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict or object to how we process it, or provide it in a portable form. You may also withdraw consent where we relied on it, and you have the right to complain to your data protection authority.

Write to privacy@pharos.email. Tell us what you want and enough detail to find it. We will respond within 30 days.

If you are a recipient rather than a customer — you got an email sent through Pharos and want your data removed — the sender is the controller of that data, not us. Contact them. We will pass a request on to the relevant customer if you cannot reach them, and if the mail itself broke our rules, report it at abuse@pharos.email and we will act on that separately.

10 · Security

The API is HTTPS only and the relay requires STARTTLS. Outbound delivery uses TLS wherever the receiving server offers it. API keys are scoped per sending domain, shown once at creation and individually revocable. Access to production systems is restricted to the people who need it.

Being specific about what we do not hold is part of the point of this page. Pharos holds no SOC 2, no ISO 27001 and no HIPAA certification. There is no published Data Processing Addendum, no guaranteed EU data residency, and no contractual uptime SLA. Anyone claiming otherwise at this stage would be describing an intention.

If you find a security problem, write to security@pharos.email. We will acknowledge it and tell you what we are doing about it.

11 · Changes

We may update this policy. The version number and date at the top of this page change when we do. Where a change materially affects how we handle your data, we will email the address on your account before it takes effect.


Questions about this document: legal@pharos.email

pharos

The lighthouse for transactional email.

Product featuresdeliverabilitypricing
Developers documentationapi referencesmtp relay
Company aboutblogcontact
Legal termsprivacyacceptable use
© 2026 Pharos status.pharos.email

We use cookies to improve your experience on our site. By using our site, you consent to cookies. Privacy Policy