Security & Privacy

Security is built into the Mailisk testing platform from day one. Learn how we protect your QA workflows with transparent hosting, rapid data deletion, and customer-only use.

Data retention

Emails automatically deleted when they expire.

Every email, attachment, and SMS record disappears automatically at expiry.

Region transparency

Data stored in EU-based servers (GDPR compliant).

Processing stays inside EU hardware so retention and privacy controls match your compliance needs.

Customer-only data use

Email & SMS content exists solely to power your QA workflows.

Your data powers QA workflows only—we never repurpose messages beyond what your tests require.

Security fundamentals

Here’s a deeper look at our core commitments: short retention, EU residency, and keeping every message dedicated solely to your QA workflows.

  • Emails and attachments are automatically deleted when they expire.
  • SMS content is stored internally and deleted when it expires.
  • Data stored on EU-based Hetzner servers.
  • Attachments stored in Backblaze B2 buckets.
  • Payments are handled by Paddle, a PCI DSS SAQ A compliant payment processor.

Payment information

All payments are handled by Paddle, which is compliant with PCI DSS SAQ A standards. This means we never collect or store your card or payment details ourselves. Instead, your payment information is securely encrypted and sent straight to Paddle, where it is processed safely.

User identification and authorization

Passwords are hashed and salted before they are stored, and we use secure session cookies inside the app to keep you signed in without exposing credentials. If you authenticate via GitHub, we store only the minimum required data, which is your email address, to link the login to your account.

Internal access controls

Data workflows stay automated, so team members only view customer content when resolving a specific account or support issue. Role-based permissions keep servers restricted to specific individuals, multi-factor auth is enforced on every login, and access logs are reviewed to quickly spot suspicious activity.

Ready to start testing emails?
Create a free account.

Get started