Legal
Privacy Policy
This policy explains what personal data Refresh handles, why, for how long, and what you can do about it. It is written to be read, not skimmed.
Effective September 30, 2026
1. Who we are
Refresh is operated by Obsidian Heron, 30 N Gould St Ste R, Sheridan, WY 82801 (“we”, “us”). We provide an email sending platform: a console and an API through which organizations send transactional and marketing email from domains they own. Questions about this policy go to hello@f5send.com.
2. Two roles, two kinds of data
We handle personal data in two different capacities, and the rules differ.
- Account data — we are the controller. Information about the people who use the console and the API: name, e-mail address, sign-in provider identifier, organization membership and role, billing details, IP addresses and the actions taken in the console. We decide how this data is used, and this policy governs it.
- Customer content — we are the processor. Everything an organization puts into the platform to send mail: recipient addresses, message content, contact lists and their properties, suppression lists, templates and inbound replies. The organization decides why this data is processed; we process it only on their instructions, under our Data Processing Addendum. If you received an email sent through Refresh, the sender is the controller of your data and their privacy notice applies. We can help you reach them.
3. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name, e-mail address, Google account identifier | Create and secure your account; sign you in; send security and service notices | Performance of the contract |
| Organization membership and role | Decide what you may see and do in each organization | Performance of the contract |
| Billing name, address and payment method (held by Stripe; we store only a customer and subscription reference) | Charge for the service; issue invoices; comply with tax law | Performance of the contract; legal obligation |
| Console and API activity: actions, timestamps, API key used, IP address | Audit trail for your organization; abuse and fraud prevention; debugging | Legitimate interest in a secure, accountable service |
| Support correspondence | Answer your request | Performance of the contract |
| Customer content (as processor) | Deliver the mail you ask us to send; record delivery events; enforce suppressions and unsubscribes | Your organization’s instructions under the DPA |
We do not sell personal data. We do not use customer content to train models, to build profiles, or for advertising. We do not run third-party advertising or analytics scripts on the console.
4. Cookies
The console sets a session cookie after sign-in and a short-lived cookie that remembers a plan chosen on the pricing page until you have signed in. Both are strictly necessary. This website sets no cookies of its own.
5. Recipients of email sent through the platform
If you received an email from an organization that uses Refresh:
- We store your address, the subject, and delivery events (delivered, bounced, opened, clicked, complained, unsubscribed) for the sender’s chosen retention period. Message content is kept for the sender’s body retention period, which can be zero.
- Open and click tracking, when the sender enables it, records the time of the event and the link clicked. Tracking links resolve on a host the sender controls.
- Every marketing message carries a one-click unsubscribe. Using it adds your address to the sender’s suppression list, and we will not send you further marketing mail from that sender.
- Requests to access or delete your data should go to the sender. If you cannot reach them, write to hello@f5send.com and we will forward the request.
6. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account. Deleted when the last organization you belong to is deleted, or on request. |
| Message content | The organization’s body retention setting: 0 to 90 days. At 0 the content is removed the moment the message is sent. |
| Message metadata and delivery events | The organization’s event retention setting: 1 to 3650 days. |
| Audit log | For the life of the organization. |
| DMARC aggregate reports | 13 months. |
| Database backups | Point-in-time recovery window of our database provider, then overwritten. |
When an organization is deleted, its domains, keys, messages, contacts, broadcasts, automations, webhooks and alert rules are removed at once. Its dedicated encryption key is scheduled for deletion and becomes unusable after 30 days, after which any remaining copy of its encrypted data cannot be read. Object storage is emptied by a lifecycle rule within 90 days.
7. Security
Data moves over TLS on every hop. Signing keys, webhook secrets and alert targets are encrypted at the application layer before storage, with keys managed in AWS Key Management Service. Client organizations receive a dedicated encryption key. Access to production systems is limited to named operators, protected by multi-factor authentication, and reviewed quarterly. When an operator opens a session against production data, an entry naming the reason is written to the affected organization’s audit log. The full description is in our data protection guide.
8. Who else sees the data
We use these providers to run the service. Each processes data only to provide its function to us.
| Provider | Function | Location |
|---|---|---|
| Amazon Web Services, Inc. | Mail delivery (SES), key management (KMS), object storage (S3), audit logging | United States (us-east-1; us-west-2 for failover) |
| Netlify, Inc. | Hosting of the console, the API and this website | United States |
| Prisma Data, Inc. | Database hosting (Prisma Postgres) | United States (US East) |
| Upstash, Inc. | Queue and cache (Redis) | United States |
| Cloudflare, Inc. | DNS for the platform's own domains and delivery of this website | United States |
| Stripe, Inc. | Billing and payment processing | United States |
| Google LLC | Sign-in (Google OAuth), Postmaster Tools reputation data, and checking links in outgoing mail against Web Risk | United States |
| Anthropic, PBC | Automated review of outgoing mail for phishing, fraud and impersonation | United States |
We may also disclose data when the law requires it, to protect the rights and safety of users or the public, or as part of a merger or acquisition, in which case this policy continues to apply to the transferred data until it is changed with notice.
9. International transfers
The service runs in the United States. If you use it from outside the United States, your data is transferred to and processed there. Where the law of your country requires a transfer mechanism, our Data Processing Addendum incorporates the Standard Contractual Clauses.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to its processing, and to complain to a supervisory authority. For account data, write to hello@f5send.com; we answer within 30 days. Organization admins can export and delete their organization’s data from the console at any time. For customer content, contact the sending organization; we assist them under the DPA.
11. Children
The service is for businesses and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has provided data to us, write to us and we will delete it.
12. Changes
We will post changes to this policy on this page and update the effective date. For material changes we will e-mail organization admins at least 14 days in advance.
13. Contact
Obsidian Heron, 30 N Gould St Ste R, Sheridan, WY 82801. hello@f5send.com. This policy is governed by the laws of Wyoming, United States.