Deploy and scale any app with Harbur Cloud: zero-config Git deployments
LEGAL / PRIVACY POLICY

Privacy Policy

How Render25 collects, protects, and respects your data. We build developer infrastructure with strict cryptographic guarantees and zero email payload monetization.

Last Updated: September 3, 2026Effective Date: September 3, 2026Version: 2.2 (Global)

Zero Content Selling

We will never sell, rent, or monetize your email contents, recipient addresses, or telemetry data. We do not use your emails to train AI models.

Ephemeral Processing

Render25 processes email bodies transiently in memory for dispatch. Raw payloads are not retained past MTA transmission handshakes unless requested.

🛡️

Cryptographic Isolation

Enforced TLS 1.3 transport encryption, AES-256-GCM secret storage, and cryptographic DKIM tenant separation across all outbound relays.

1. Overview & Entity Information

In Plain English: Render25 is built and operated by Kingdom Corporation, founded by Ren Lysea. This document outlines how we treat your account details and customer transmission data.

This Privacy Policy applies to the services, websites, REST APIs, SMTP relays, SDKs, and developer tooling provided by Render25 (operated by Kingdom Corporation, founded by Ren Lysea), collectively referred to as “Render25”, “we”, “us”, or “our”.

When you create a project, configure a domain, or transmit an email message via Render25, we act as a Data Controller for your account registration, billing, and developer credential details, and as a Data Processor (or Service Provider under CCPA) with respect to the email message payloads and recipient addresses you submit for transmission.

2. Information We Collect

In Plain English: We only collect information required to verify your identity, process billing, manage API authorization, and ensure deliverability.

We collect data across three principal categories:

A. Account & Profile Data (Provided by You)

  • Identity Credentials: Name, business email address, organization name, and cryptographically hashed password authentication hashes.
  • Billing & Invoicing: Payment method references, billing address, VAT/tax identifiers, and transaction history. Payment card numbers are tokenized directly by our PCI-DSS Level 1 payment processor and never touch Render25 core application servers.
  • Workspace Configuration: Project titles, team collaborator emails, custom sending domains, and DNS verification records (SPF, DKIM, MX).

B. Developer & Platform Telemetry

  • API Keys & Authentication: Scoped API tokens, IP allowlists, rate limiting tokens, and audit logs of administrative changes.
  • Network Telemetry: Origin IP addresses for API invocations, user-agent headers, timestamped request rates, and TLS cipher negotiation details for security audits.

C. Transmission Metadata & Recipient Data

When utilizing our REST endpoints or Anycast SMTP relays, your applications transmit sender identity headers, recipient email addresses, subject lines, message headers, and body contents (HTML/Text/Attachments).

3. Email Transmission & Processing

In Plain English: Your emails are yours. We do not read them, sell them, scan them for ad profiling, or train AI models with them.

Render25 processes email payloads strictly to fulfill your outbound transmission instructions, perform cryptographic DKIM signing, route through optimal MTA pathways, and generate delivery event telemetry (Delivered, Bounced, Opened, Clicked).

  • Zero Content Monetization: We do not sell email addresses or content to data brokers, advertising networks, or third-party marketers.
  • No AI Model Training: Your email bodies, attachments, recipient lists, and telemetry are strictly excluded from any machine learning, large language model (LLM), or algorithmic training datasets.
  • Automated Spam & Abuse Filtering: Outbound emails pass through automated heuristic scans to detect credential stuffing, phishing, ransomware links, and protocol spoofing in order to protect our sending IP reputation and the global email ecosystem.

5. Data Retention & Deletion

In Plain English: Message contents are discarded post-delivery. Delivery logs are kept for 7 to 30 days depending on your project tier and can be purged on demand.
Data CategoryDefault RetentionPurpose
Email Message BodiesEphemeral (≤ 72h queuing)MTA queue transmission; purged once delivered
Delivery Event Logs7 Days (Free) / 30 Days (Pro)Telemetry inspection, bounce debugging
Suppression List (Bounces)Until user removalReputation protection & anti-spam compliance
Account & Billing DataDuration of account + statutory periodTax compliance & account authentication

You may purge your message logs, delete domains, or terminate your entire project workspace at any time directly through the Render25 Dashboard or via our REST API. Upon account termination, all active credentials, DKIM private keys, and cached logs are permanently deleted within 14 calendar days.

6. Infrastructure & Subprocessors

To deliver sub-100ms global Anycast delivery and redundant mail routing, Render25 partners with tier-1 cloud and infrastructure providers subject to strict Data Processing Agreements (DPAs):

  • Cloudflare, Inc.: Anycast edge routing, DDoS mitigation, and global edge network proxying.
  • Amazon Web Services (AWS) & Google Cloud: Secure compute clusters, managed PostgreSQL instances, and backup relays.
  • Stripe, Inc.: PCI-DSS Level 1 compliant payment processing and recurring subscription invoicing.

All subprocessors maintain SOC 2 Type II, ISO 27001, or equivalent global security certifications.

7. Security & Cryptographic Standards

In Plain English: All traffic is encrypted in flight (TLS 1.3) and at rest (AES-256). API keys and DKIM keys are stored with strict cryptographic boundaries.
  • In-Transit Encryption: Mandatory TLS 1.3 / 1.2 negotiation for REST API requests and outbound Opportunistic/Enforced TLS for MTA-to-MTA mail transfer.
  • At-Rest Encryption: Database stores, key caches, and backups encrypted with AES-256-GCM.
  • Key Management: Customer API keys are salted and hashed using Argon2id/SHA-256; raw secrets are never viewable once generated. DKIM private keys are isolated in hardware security modules or dedicated secret vaults.
  • Network Protection: Edge rate limiting, automatic brute-force throttling, and isolation between workspace projects.

8. International Data Transfers

Render25 operates globally distributed Anycast edge nodes. When personal data originates within the European Union, United Kingdom, or Switzerland and is transferred across borders, we implement recognized transfer mechanisms:

  • European Commission Standard Contractual Clauses (SCCs).
  • UK International Data Transfer Addendum.
  • Industry-standard supplementary technical measures including pervasive transport encryption and pseudonymization.

9. Your Rights (GDPR, CCPA/CPRA & Global Privacy)

Depending on your jurisdiction, you are entitled to exercise statutory privacy rights:

  • Right of Access & Portability: Request an export of your account metadata and transmission logs.
  • Right to Rectification: Correct inaccurate contact or organizational details via the dashboard.
  • Right to Erasure (“Right to be Forgotten”): Permanently delete your Render25 account, associated domains, and logs.
  • Right to Restriction & Objection: Object to specific processing activities based on legitimate interest.
  • CCPA/CPRA Non-Discrimination: We do not sell your personal information, and we will never discriminate against you for exercising your privacy rights.

To exercise any of these rights, email our team at privacy@render25.com. We respond to verified data subject requests within 30 days.

10. Cookies & Tracking Technologies

We believe in minimal tracking. Render25 does not use intrusive third-party cross-site advertising cookies.

  • Essential Cookies: Session tokens, CSRF protection, and project workspace context required for you to log into and operate the platform.
  • Aggregated Telemetry: Privacy-preserving analytics that measure anonymized page load speeds, documentation search quality, and system health without tracking you across third-party domains.

11. Policy Modifications

We may periodically revise this Privacy Policy to reflect architectural updates, regulatory developments, or new platform features. When material changes occur, we will notify registered workspace owners via email or through prominent notifications in the Render25 Dashboard at least 14 days prior to their effective date.

12. Contact Legal & Data Protection Officer

If you have questions, feedback, or concerns regarding this Privacy Policy or our security practices, please contact our Data Protection team:

Entity: Render25 / Kingdom Corporation

Founder & CEO: Ren Lysea

Privacy Inquiries: privacy@render25.com

Legal & Compliance: legal@render25.com

Security Disclosures: security@render25.com

Official Website: https://render25.com