Refresh

Legal

Privacy Policy

This policy explains what personal data Refresh handles, why, for how long, and what you can do about it. It is written to be read, not skimmed.

Effective September 30, 2026

1. Who we are

Refresh is operated by Obsidian Heron, 30 N Gould St Ste R, Sheridan, WY 82801 (“we”, “us”). We provide an email sending platform: a console and an API through which organizations send transactional and marketing email from domains they own. Questions about this policy go to hello@f5send.com.

2. Two roles, two kinds of data

We handle personal data in two different capacities, and the rules differ.

  • Account data — we are the controller. Information about the people who use the console and the API: name, e-mail address, sign-in provider identifier, organization membership and role, billing details, IP addresses and the actions taken in the console. We decide how this data is used, and this policy governs it.
  • Customer content — we are the processor. Everything an organization puts into the platform to send mail: recipient addresses, message content, contact lists and their properties, suppression lists, templates and inbound replies. The organization decides why this data is processed; we process it only on their instructions, under our Data Processing Addendum. If you received an email sent through Refresh, the sender is the controller of your data and their privacy notice applies. We can help you reach them.

3. What we collect and why

DataPurposeLegal basis
Name, e-mail address, Google account identifierCreate and secure your account; sign you in; send security and service noticesPerformance of the contract
Organization membership and roleDecide what you may see and do in each organizationPerformance of the contract
Billing name, address and payment method (held by Stripe; we store only a customer and subscription reference)Charge for the service; issue invoices; comply with tax lawPerformance of the contract; legal obligation
Console and API activity: actions, timestamps, API key used, IP addressAudit trail for your organization; abuse and fraud prevention; debuggingLegitimate interest in a secure, accountable service
Support correspondenceAnswer your requestPerformance of the contract
Customer content (as processor)Deliver the mail you ask us to send; record delivery events; enforce suppressions and unsubscribesYour organization’s instructions under the DPA

We do not sell personal data. We do not use customer content to train models, to build profiles, or for advertising. We do not run third-party advertising or analytics scripts on the console.

4. Cookies

The console sets a session cookie after sign-in and a short-lived cookie that remembers a plan chosen on the pricing page until you have signed in. Both are strictly necessary. This website sets no cookies of its own.

5. Recipients of email sent through the platform

If you received an email from an organization that uses Refresh:

  • We store your address, the subject, and delivery events (delivered, bounced, opened, clicked, complained, unsubscribed) for the sender’s chosen retention period. Message content is kept for the sender’s body retention period, which can be zero.
  • Open and click tracking, when the sender enables it, records the time of the event and the link clicked. Tracking links resolve on a host the sender controls.
  • Every marketing message carries a one-click unsubscribe. Using it adds your address to the sender’s suppression list, and we will not send you further marketing mail from that sender.
  • Requests to access or delete your data should go to the sender. If you cannot reach them, write to hello@f5send.com and we will forward the request.

6. How long we keep data

DataRetention
Account dataFor the life of the account. Deleted when the last organization you belong to is deleted, or on request.
Message contentThe organization’s body retention setting: 0 to 90 days. At 0 the content is removed the moment the message is sent.
Message metadata and delivery eventsThe organization’s event retention setting: 1 to 3650 days.
Audit logFor the life of the organization.
DMARC aggregate reports13 months.
Database backupsPoint-in-time recovery window of our database provider, then overwritten.

When an organization is deleted, its domains, keys, messages, contacts, broadcasts, automations, webhooks and alert rules are removed at once. Its dedicated encryption key is scheduled for deletion and becomes unusable after 30 days, after which any remaining copy of its encrypted data cannot be read. Object storage is emptied by a lifecycle rule within 90 days.

7. Security

Data moves over TLS on every hop. Signing keys, webhook secrets and alert targets are encrypted at the application layer before storage, with keys managed in AWS Key Management Service. Client organizations receive a dedicated encryption key. Access to production systems is limited to named operators, protected by multi-factor authentication, and reviewed quarterly. When an operator opens a session against production data, an entry naming the reason is written to the affected organization’s audit log. The full description is in our data protection guide.

8. Who else sees the data

We use these providers to run the service. Each processes data only to provide its function to us.

ProviderFunctionLocation
Amazon Web Services, Inc.Mail delivery (SES), key management (KMS), object storage (S3), audit loggingUnited States (us-east-1; us-west-2 for failover)
Netlify, Inc.Hosting of the console, the API and this websiteUnited States
Prisma Data, Inc.Database hosting (Prisma Postgres)United States (US East)
Upstash, Inc.Queue and cache (Redis)United States
Cloudflare, Inc.DNS for the platform's own domains and delivery of this websiteUnited States
Stripe, Inc.Billing and payment processingUnited States
Google LLCSign-in (Google OAuth), Postmaster Tools reputation data, and checking links in outgoing mail against Web RiskUnited States
Anthropic, PBCAutomated review of outgoing mail for phishing, fraud and impersonationUnited States

We may also disclose data when the law requires it, to protect the rights and safety of users or the public, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data until it is changed with notice.

9. International transfers

The service runs in the United States. If you use it from outside the United States, your data is transferred to and processed there. Where the law of your country requires a transfer mechanism, our Data Processing Addendum incorporates the Standard Contractual Clauses.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to its processing, and to complain to a supervisory authority. For account data, write to hello@f5send.com; we answer within 30 days. Organization admins can export and delete their organization’s data from the console at any time. For customer content, contact the sending organization; we assist them under the DPA.

11. Children

The service is for businesses and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has provided data to us, write to us and we will delete it.

12. Changes

We will post changes to this policy on this page and update the effective date. For material changes we will e-mail organization admins at least 14 days in advance.

13. Contact

Obsidian Heron, 30 N Gould St Ste R, Sheridan, WY 82801. hello@f5send.com. This policy is governed by the laws of Wyoming, United States.