Privacy Policy

Effective: July 22, 2026

This Privacy Policy explains how EmailTemplateEngine (“we,” “us,” or “our”) collects, uses, stores, and shares your personal data when you use our API-first email template rendering service (“the Service”).

1. Data We Collect

Account Data: When you register via Clerk authentication, we receive your email address, name, and profile picture (if provided). This is necessary to operate your account and authenticate API requests.

Template Content: You store email template content (HTML, CSS, variables, version history) in our database. This data belongs to you entirely.

Usage Data: We log API request metadata (endpoint, timestamp, response time, status code) for rate limiting, monitoring, and service improvement. Request payloads are not logged permanently.

Payment Data: If you subscribe to a paid tier, payment processing is handled by Stripe. We do not store credit card numbers. Stripe's privacy policy applies to payment data.

AI Prompts: When using AI generation features, your prompt text is sent to OpenRouter and the selected LLM provider (Gemini, GPT, Claude, or DeepSeek) for processing. Prompts are not used for model training. See OpenRouter's privacy policy for their data handling practices.

2. How We Use Your Data

  • To provide, maintain, and improve the Service
  • To authenticate API requests via Clerk JWT tokens
  • To enforce rate limits and prevent abuse
  • To communicate service updates, billing notices, and policy changes
  • To render templates according to your API requests

We do not sell your personal data to third parties. We do not use your template content for advertising or profiling.

3. Third-Party Services

We use the following third-party services that process data:

  • Clerk — Authentication and user management. Stores your identity data securely.
  • MongoDB — Database. Stores your templates, versions, and account data with encryption at rest.
  • Stripe — Payment processing. Handles subscription billing and invoicing.
  • OpenRouter — AI model routing. Processes AI generation prompts when you use that feature.
  • Upstash — Redis for rate limiting. Minimal ephemeral data, no persistent storage.

Each service operates under its own privacy and security policies.

4. Cookies & Local Storage

We use minimal cookies and local storage:

  • Clerk session cookie (essential) — Required for authentication. Without it, you cannot log in.
  • Theme preference (localStorage) — Stores your dark/light mode preference. Not a cookie.

We do not use analytics cookies, tracking pixels, fingerprinting, or third-party marketing cookies.

5. Data Retention

We retain your template data for as long as your account is active. If you delete a template, it is removed from our database within 24 hours. Upon account deletion, all associated data is permanently deleted within 30 days. Anonymized usage logs may be retained for up to 90 days for analytical purposes.

6. Data Security

We implement industry-standard security measures:

  • All API traffic is encrypted via TLS 1.3
  • Database is encrypted at rest
  • Clerk handles authentication with bcrypt+hash password storage
  • API keys are hashed and not retrievable after creation
  • Regular security audits of dependencies

7. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Export your data in a portable format
  • Withdraw consent for processing where applicable
  • Opt out of the sale of your data (we do not sell data)

To exercise these rights, email privacy@theboomer.dev. We respond to all requests within 30 days.

8. International Data Transfers

Your data is stored on servers in the European Union (EU). If you access the Service from outside the EU, data may be transferred to and processed in the EU. We rely on Standard Contractual Clauses (SCCs) for data transfers where applicable.

9. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal obligations. Material changes will be notified via email or through the Service. The “Effective” date at the top indicates when the policy was last updated.

10. Contact

Data Protection Officer contact: privacy@theboomer.dev

General inquiries: hello@theboomer.dev