EmailOnSteroids

Legal

Privacy policy

What personal data EmailOnSteroids processes, on what legal basis, and for how long. The German version is the legally binding one.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

<Vorname Nachname>
<Straße und Hausnummer>
<PLZ> Berlin
Germany
Email
hello@emailonsteroids.com

No data protection officer has been appointed. The thresholds in Art. 37 GDPR and § 38 BDSG are not met: fewer than 20 people are permanently engaged in automated processing, and our core activity does not require large-scale regular and systematic monitoring of individuals.

2. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Any consent you have given can be withdrawn at any time with effect for the future.

An informal message to hello@emailonsteroids.com is enough for all of these. Most of this information is also visible in your account, where you can delete your data yourself.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is the Berlin Commissioner for Data Protection and Freedom of Information, but you may equally approach the authority where you live.

3. Visiting the website

When you open a page, our hosting provider processes the connection data the request needs: IP address, timestamp, requested resource, HTTP status, bytes transferred, referrer and user agent.

Purpose
delivering the page, keeping it stable, and defending against attacks
Legal basis
Art. 6(1)(f) GDPR — legitimate interest in secure operation
Retention
short-term, then deleted

Fonts are served from our own origin. There is no connection to Google Fonts or any other content delivery network, and your IP address is not disclosed to a third party in the process.

4. Waiting list

If you request an invite we store the email address you enter and the time of the request.

Purpose
to notify you when an invite becomes available
Legal basis
Art. 6(1)(a) GDPR — consent
Retention
until you are invited, until you withdraw, or 24 months after the request at the latest

The form's confirmation message is deliberately identical for a new address and one already stored, so it does not reveal whether an address is on the list.

5. Account and sign-in

For an account we process your email address, authentication data, the ingest address assigned to you, and plan and usage data.

Purpose
providing the service and controlling access
Legal basis
Art. 6(1)(b) GDPR — performance of the contract
Retention
for as long as the account exists; after deletion only where statutory retention periods require it

6. Test content and email ingest — our role as processor

The core of the service is rendering emails you supply. You can paste HTML, forward a message to your personal ingest address, or submit content through the API. That content regularly contains personal data of third parties — recipient names, salutations, addresses, personalised links.

For that content you are the controller and we are a processor within the meaning of Art. 28 GDPR. We process it solely to produce the previews and analyses you asked for, never for our own purposes. A data processing agreement is available on request and is required for business use.

Inbound messages are received by Cloudflare Email Routing and passed to us with a signature. When rendering, external images are not fetched where that is technically avoidable.

Do not send the service emails containing special categories of personal data under Art. 9 GDPR — health, religious or trade-union data among them. The service is not designed for it.

7. Previews and share links

Screenshots are stored encrypted and are reachable only through your account. When you create a share link, the page is reachable by anyone who knows the link: the link itself is the credential.

Share links carry a lifetime you choose, are excluded from search engines, and are deleted together with their files when they lapse. An expired link answers with status 410 (Gone).

8. Payments

Payments are handled by Stripe. Your payment details — card number, bank details — are processed by Stripe alone and never reach our servers. From Stripe we receive a customer identifier, the subscription status, the plan and the term.

Legal basis
Art. 6(1)(b) GDPR for performing the contract; Art. 6(1)(c) GDPR for tax retention
Retention
invoice data for 10 years under § 147 AO and § 257 HGB

9. Cookies and local storage

We set no analytics, advertising or tracking cookies, and we embed no service that does. There is therefore no consent banner: under § 25(2) no. 2 TDDDG no consent is required for strictly necessary storage, and a banner asking for it anyway would be misleading.

NamePurposeLifetime
Supabase sessionkeeps you signed inthe session, or until you sign out
eos_localeremembers the language you chose1 year
Theme preferenceremembers light or dark rendering (stored locally in the browser)until you clear it

The language cookie contains only “en” or “de” and no identifier that could be used to recognise you.

10. Recipients and international transfers

We use the processors below. There are no other recipients; your data is not sold and not passed on for advertising.

ProviderTaskData processed
Vercel Inc.hosting and deliveryconnection data, request contents
Supabase Inc.database, authentication, file storageaccount data, test content, previews
Stripe Payments Europe, Ltd.payment processingpayment and subscription data
Cloudflare, Inc.receiving inbound emailinbound messages and their envelope data

Some of these companies are established in the United States or rely on group companies there. Transfers are based on standard contractual clauses under Art. 46(2)(c) GDPR and, where the provider is certified, additionally on the adequacy decision for the EU-US Data Privacy Framework.

11. Changes to this policy

We update this policy when the service or the law changes. The version published here is the one that applies, and the date of the last change is shown at the foot of the page. For material changes we additionally notify signed-in users by email.

Last updated: 14 August 2026