Draft: not yet final
This page is a working draft and hasn't been reviewed. Details still to be filled in: operator, postalAddress, governingLaw, liabilityFloor.
Legal
Privacy Policy
Last updated 3 October 2026
This explains what Ops-Free SES (www.opsfree.in) collects when you use it, why, who else handles it, how long we keep it, and what you can do about it. We’ve tried to say plainly what actually happens.
1. Who we are
[OPERATOR: your legal name or company] runs Ops-Free SES and decides how the personal data described here is used. Contact: support@opsfree.in, [POSTAL ADDRESS].
2. What we collect
- Your account. Your email address and password. The password goes to our sign-in provider and is stored there in hashed form; we don’t keep it ourselves.
- Your AWS connection. If you connect with one click: the name (ARN) of the IAM role created in your account, the region, and a random identifier we generated for your connection. No secret is stored. If you connect with an access key: the access key ID, the region, and the secret access key, where the secret is encrypted (AES-256-GCM) before it is stored and is never shown again. We never ask for your AWS login.
- API keys. Only a one-way hash of each key and a short display prefix. The full key is shown to you once and can’t be recovered.
- Records of your email. For each message: the sender and recipient addresses, the subject, status and timestamps, any error text, tags you set, and the delivery, bounce and complaint events AWS reports (in a reduced form, with message headers and subjects removed).
- Message content. The body of each email passes through our queue until it is sent (see how long we keep it). We don’t store message bodies in our database. The exception is templates you save, which we store so you can use them.
- Setup data. Your domains and verified sender addresses, DNS check results, your blocked-address list, and, if you use the production-access assistant, your answers to its questions.
- Technical data. Server logs with a request ID, your account ID and outcome (not message bodies, and never credentials); IP addresses, which our host sees and which we use briefly for rate limiting; and error reports sent to our error-monitoring service, in which email addresses and key-like strings are redacted and database values are removed.
3. How we use it
- To provide the service: sign you in, send your email through your AWS account, show you what happened to it.
- To keep it secure and fair: rate limiting, abuse prevention, finding and fixing bugs.
- To support you, and to tell you about important changes to the service or these documents.
- To meet legal obligations.
We don’t sell your data, and we don’t use it for advertising.
4. Your recipients’ data
When you send email, the addresses and content are your recipients’ personal data and you decide what to send and to whom. We handle them on your behalf, only to deliver the email and show you the result. You are responsible for having the right to email them, as set out in our Terms.
6. How long we keep it
- Account, settings and records of your email: until you ask us to delete your account. We don’t currently delete email records automatically. If we add a retention period we will tell you first.
- Message content in the queue: removed about 24 hours after a message is sent. If a message fails permanently, its content is kept for up to 14 days so you can investigate and retry it.
- Backups and logs: kept by our providers for their own periods. Deleted data can remain in backups until they roll over.
- Deleting your account removes your account and the data tied to it. Ask at support@opsfree.in; we aim to do it within 30 days.
7. How we protect it
- Connections are encrypted in transit (HTTPS).
- AWS secrets are encrypted before storage (a one-click connection stores no secret), and API keys are stored only as hashes.
- Each customer’s data is kept separate, and the database isn’t exposed to the public.
- Requests are rate limited, and logs are filtered so they don’t carry message bodies or credentials.
No system is perfectly secure. If a breach affects your data, we will tell you without undue delay. To limit the damage of any exposure, connect with one click (no secret is stored) or give us a dedicated IAM user with only the permissions we show you, and you can delete the role or user in AWS at any time.
9. Your choices and rights
- You can ask us for a copy of your personal data, to correct it, or to delete it. Email support@opsfree.in.
- You can revoke our access to your AWS account at any time by deleting the CloudFormation stack or role, or the access key or IAM user.
- You can revoke API keys, remove domains and clear blocked addresses in the dashboard.
- Depending on where you live, the law may give you further rights, for example under India’s Digital Personal Data Protection Act, 2023, or the GDPR, including the right to complain to a data-protection authority. We will respect the rights that apply to you.
10. Children
The service is for people 18 and over. We don’t knowingly collect data from children.
11. Changes
We may update this policy. For material changes we will tell you by email or in the dashboard before they take effect. The date at the top shows when it was last changed.
12. Contact
[OPERATOR: your legal name or company]
[POSTAL ADDRESS]
support@opsfree.in
See also our Terms of Service and Privacy Policy.