Privacy Policy
How Render25 collects, protects, and respects your data. We build developer infrastructure with strict cryptographic guarantees and zero email payload monetization.
Zero Content Selling
We will never sell, rent, or monetize your email contents, recipient addresses, or telemetry data. We do not use your emails to train AI models.
Ephemeral Processing
Render25 processes email bodies transiently in memory for dispatch. Raw payloads are not retained past MTA transmission handshakes unless requested.
Cryptographic Isolation
Enforced TLS 1.3 transport encryption, AES-256-GCM secret storage, and cryptographic DKIM tenant separation across all outbound relays.
1. Overview & Entity Information
This Privacy Policy applies to the services, websites, REST APIs, SMTP relays, SDKs, and developer tooling provided by Render25 (operated by Kingdom Corporation, founded by Ren Lysea), collectively referred to as “Render25”, “we”, “us”, or “our”.
When you create a project, configure a domain, or transmit an email message via Render25, we act as a Data Controller for your account registration, billing, and developer credential details, and as a Data Processor (or Service Provider under CCPA) with respect to the email message payloads and recipient addresses you submit for transmission.
2. Information We Collect
We collect data across three principal categories:
A. Account & Profile Data (Provided by You)
- Identity Credentials: Name, business email address, organization name, and cryptographically hashed password authentication hashes.
- Billing & Invoicing: Payment method references, billing address, VAT/tax identifiers, and transaction history. Payment card numbers are tokenized directly by our PCI-DSS Level 1 payment processor and never touch Render25 core application servers.
- Workspace Configuration: Project titles, team collaborator emails, custom sending domains, and DNS verification records (SPF, DKIM, MX).
B. Developer & Platform Telemetry
- API Keys & Authentication: Scoped API tokens, IP allowlists, rate limiting tokens, and audit logs of administrative changes.
- Network Telemetry: Origin IP addresses for API invocations, user-agent headers, timestamped request rates, and TLS cipher negotiation details for security audits.
C. Transmission Metadata & Recipient Data
When utilizing our REST endpoints or Anycast SMTP relays, your applications transmit sender identity headers, recipient email addresses, subject lines, message headers, and body contents (HTML/Text/Attachments).
3. Email Transmission & Processing
Render25 processes email payloads strictly to fulfill your outbound transmission instructions, perform cryptographic DKIM signing, route through optimal MTA pathways, and generate delivery event telemetry (Delivered, Bounced, Opened, Clicked).
- Zero Content Monetization: We do not sell email addresses or content to data brokers, advertising networks, or third-party marketers.
- No AI Model Training: Your email bodies, attachments, recipient lists, and telemetry are strictly excluded from any machine learning, large language model (LLM), or algorithmic training datasets.
- Automated Spam & Abuse Filtering: Outbound emails pass through automated heuristic scans to detect credential stuffing, phishing, ransomware links, and protocol spoofing in order to protect our sending IP reputation and the global email ecosystem.
4. Legal Bases for Processing (GDPR & International Law)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, our processing of your personal data relies on established lawful bases under Article 6 of the General Data Protection Regulation (GDPR):
- Performance of a Contract: Providing SMTP relays, dashboard controls, API access, and customer support per our Terms of Service.
- Legitimate Interests: Protecting platform integrity, preventing distributed denial-of-service (DDoS) attacks, detecting unauthorized relay usage, and calculating aggregate deliverability health.
- Compliance with Legal Obligations: Retaining financial and tax documentation, responding to lawful government subpoenas, or enforcing sanctions compliance.
5. Data Retention & Deletion
| Data Category | Default Retention | Purpose |
|---|---|---|
| Email Message Bodies | Ephemeral (≤ 72h queuing) | MTA queue transmission; purged once delivered |
| Delivery Event Logs | 7 Days (Free) / 30 Days (Pro) | Telemetry inspection, bounce debugging |
| Suppression List (Bounces) | Until user removal | Reputation protection & anti-spam compliance |
| Account & Billing Data | Duration of account + statutory period | Tax compliance & account authentication |
You may purge your message logs, delete domains, or terminate your entire project workspace at any time directly through the Render25 Dashboard or via our REST API. Upon account termination, all active credentials, DKIM private keys, and cached logs are permanently deleted within 14 calendar days.
6. Infrastructure & Subprocessors
To deliver sub-100ms global Anycast delivery and redundant mail routing, Render25 partners with tier-1 cloud and infrastructure providers subject to strict Data Processing Agreements (DPAs):
- Cloudflare, Inc.: Anycast edge routing, DDoS mitigation, and global edge network proxying.
- Amazon Web Services (AWS) & Google Cloud: Secure compute clusters, managed PostgreSQL instances, and backup relays.
- Stripe, Inc.: PCI-DSS Level 1 compliant payment processing and recurring subscription invoicing.
All subprocessors maintain SOC 2 Type II, ISO 27001, or equivalent global security certifications.
7. Security & Cryptographic Standards
- In-Transit Encryption: Mandatory TLS 1.3 / 1.2 negotiation for REST API requests and outbound Opportunistic/Enforced TLS for MTA-to-MTA mail transfer.
- At-Rest Encryption: Database stores, key caches, and backups encrypted with AES-256-GCM.
- Key Management: Customer API keys are salted and hashed using Argon2id/SHA-256; raw secrets are never viewable once generated. DKIM private keys are isolated in hardware security modules or dedicated secret vaults.
- Network Protection: Edge rate limiting, automatic brute-force throttling, and isolation between workspace projects.
8. International Data Transfers
Render25 operates globally distributed Anycast edge nodes. When personal data originates within the European Union, United Kingdom, or Switzerland and is transferred across borders, we implement recognized transfer mechanisms:
- European Commission Standard Contractual Clauses (SCCs).
- UK International Data Transfer Addendum.
- Industry-standard supplementary technical measures including pervasive transport encryption and pseudonymization.
9. Your Rights (GDPR, CCPA/CPRA & Global Privacy)
Depending on your jurisdiction, you are entitled to exercise statutory privacy rights:
- Right of Access & Portability: Request an export of your account metadata and transmission logs.
- Right to Rectification: Correct inaccurate contact or organizational details via the dashboard.
- Right to Erasure (“Right to be Forgotten”): Permanently delete your Render25 account, associated domains, and logs.
- Right to Restriction & Objection: Object to specific processing activities based on legitimate interest.
- CCPA/CPRA Non-Discrimination: We do not sell your personal information, and we will never discriminate against you for exercising your privacy rights.
To exercise any of these rights, email our team at privacy@render25.com. We respond to verified data subject requests within 30 days.
11. Policy Modifications
We may periodically revise this Privacy Policy to reflect architectural updates, regulatory developments, or new platform features. When material changes occur, we will notify registered workspace owners via email or through prominent notifications in the Render25 Dashboard at least 14 days prior to their effective date.
12. Contact Legal & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy or our security practices, please contact our Data Protection team:
Entity: Render25 / Kingdom Corporation
Founder & CEO: Ren Lysea
Privacy Inquiries: privacy@render25.com
Legal & Compliance: legal@render25.com
Security Disclosures: security@render25.com
Official Website: https://render25.com