Privacy Policy
Last updated
Who we are
In this policy, “Rasket”, “we” and “us” mean the company that operates the Rasket service.
Rasket is an API and dashboard for sending and receiving email. This policy covers the website, the dashboard, the API, and the email our customers send through us. It explains what we collect, why, how long we keep it, and who helps us run the service.
Our role
For your Rasket account, your use of the website and the dashboard, and billing, we decide how personal data is used.
For the email a customer sends or receives through Rasket, and for the contacts, recipients and content that go with it, the customer decides and we process that data on their behalf to provide the service. If you received email from a Rasket customer, see If you received email sent through Rasket.
What we collect
Your account
Your email address and, if you give one, your name. We store your password only as an Argon2id hash. If you sign in with Google or GitHub we receive your account identifier, your verified email address and your name from that provider; if your team uses single sign-on, we receive the same from your organisation’s identity provider. If you turn on two-factor authentication, its secret is stored encrypted.
Sign-in and security records
Each session records the IP address, the browser’s user agent and when it was last used. Changes made in a team — keys created, domains added, settings changed — are written to an audit log with who made them, when, and from which IP address.
Billing
Payments are handled by Stripe. We never see or store your card number: we keep your Stripe customer identifier, whether a payment method is on file, and its brand and last four digits, together with your plan, usage and invoices.
API requests
For each API request we log the method, path, response status, IP address, user agent and timing, with the request body after credentials are removed and attachment content is replaced by its name, size and hash.
Email, contacts and content
To deliver and report on a customer’s email we store the sender, recipients, subject, HTML and text bodies, attachments and the delivery events that follow (such as delivered, bounced or complained). Where a customer receives email through Rasket, we store the messages and attachments sent to them. Customers can also store contacts, contact properties, topic subscriptions, templates, broadcasts and automations.
AI assist
AI assist is off until a team admin turns it on. When it is used, the text needed for the task is sent to Anthropic: the brief and template for a subject line or draft, or, to diagnose a message, its subject, sending domain, statuses, event timeline and each recipient’s domain — never a recipient’s address. We keep a record of each request (its kind, model, token counts, timing and status, and the stored result of a diagnosis), not the prompt text.
Support
When you write to us from the dashboard’s help panel, your message and any files you attach are emailed to our support team.
The website
The website runs no analytics, advertising or third-party tracking scripts. Our hosting provider keeps request logs, such as the IP address and the page requested, to operate and secure the service.
If you received email sent through Rasket
The customer who sent it decides who receives their email and what it says; we deliver it for them. To deliver it we process your email address, the message itself and what happened to it — whether it was delivered, bounced, or reported as spam.
- Open and click tracking is off unless the sender turns it on for their domain. When it is on, opening the email or clicking a link in it records the time, your IP address and your user agent (and, for a click, the link), and passes them to the sender.
- If you unsubscribe or change your preferences on our hosted page, we record what you chose, when, your IP address and your user agent, alongside a hash of your email address. That record is how the sender shows they respected your choice.
- An address that bounces permanently or reports a message as spam is added to the sender’s suppression list, and Rasket does not send to it for that sender while it stays there.
To access, correct or delete what a sender holds about you, contact the sender. To report email sent through Rasket that you did not ask for, write to info@rasket.com.
How we use it
- To provide the service: accept, send, receive and report on email.
- To keep accounts secure and prevent abuse: checking messages for phishing and malware patterns, and watching bounce and complaint rates so that a sender who harms other senders’ delivery is restricted.
- To bill for paid plans and usage.
- To answer support requests and send the email the service needs, such as address verification and password resets.
- To meet legal, tax and accounting obligations.
How long we keep it
Retention is set per plan and enforced by a nightly deletion job. Email data is deleted, not just hidden, when its window ends.
| Data | Kept for |
|---|---|
| Email metadata, bodies, attachments and events; received email; API request logs; webhook deliveries | 30 days on every self-serve plan; Enterprise teams can agree a different window |
| Contact import files | 7 days after the import completes |
| AI assist records, automation run history, raw delivery notifications from Amazon SES, platform metrics | 90 days |
| Unsubscribe and consent records | 3 years after the consent expires |
| Audit logs, the usage ledger and billing records | 7 years |
| Your account, team, domains, contacts, templates and suppression list | Until you delete them, or the team is deleted |
| Sign-in sessions | 30 days at most, and 7 days without use |
Deleted data can remain in database backups for up to 90 days. Backups are used only to recover from a disaster, never to answer a customer request. We may keep a team’s data beyond these periods while it is subject to a legal dispute, a lawful request or an abuse investigation.
Who helps us run the service
These companies process personal data for us, only to provide the service.
| Provider | What they do | Where |
|---|---|---|
| Vercel | Hosts the website, dashboard and API; runs background jobs; stores attachments, raw messages and exports in private file storage (Vercel Blob) | United States (Washington, D.C.) |
| Neon | Hosts the database | United States (AWS us-east-1) |
| Amazon Web Services | Sends and receives email (Amazon SES and SNS) | The region chosen for each domain: US East, EU (Ireland), South America (São Paulo) or Asia Pacific (Tokyo) |
| Stripe | Takes payments and runs the billing portal | Stripe’s infrastructure |
| Anthropic | Answers AI assist requests, when a team has turned it on; requests may reach it through Vercel’s AI Gateway | Anthropic’s infrastructure |
| Google, GitHub | Sign-in, if you choose to use them | Their infrastructure |
| Cloudflare | Looks up DNS records when a domain is verified, and applies DNS records if you connect a Cloudflare account | Cloudflare’s infrastructure |
Our application and database run in the United States, so personal data from other countries is transferred there.
Security
- Connections to Rasket, and from Rasket to its database and storage, use TLS.
- The database is encrypted at rest, and every team’s rows are separated by row-level security in the database as well as by the application.
- Passwords are hashed with Argon2id; API keys are shown once and stored only as hashes.
- Webhook signing secrets, DKIM private keys, two-factor secrets and single sign-on client secrets are encrypted with AES-256-GCM, each under its own data key.
- Every member can turn on two-factor authentication, and teams can require OpenID Connect single sign-on on the Scale plan (as an add-on) and Enterprise.
- Our logs leave out credentials, cookies and email bodies.
Your choices and rights
- You can reset your password from the sign-in page and turn two-factor authentication on or off in the dashboard.
- A team decides whether AI assist is on, and whether open and click tracking is on for each of its domains. Both are off by default.
- Customers can delete a contact through the dashboard or the API; its personal data is removed and only the hashed consent record remains.
- A copy of a team’s data, deletion of a team, or deletion of your account are available on request: write to info@rasket.com from the account’s email address.
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how it is used, and to complain to a data protection authority. Write to us to use any of them.
Cookies
Rasket sets no cookies for a visitor who does not sign in, and none for analytics or advertising. The cookies we do set are needed to sign you in:
| Cookie | Purpose | Lasts |
|---|---|---|
| rsk_session | Keeps you signed in | 30 days, or 7 days without use |
| rsk_mfa | Carries you from your password to your two-factor code | 5 minutes |
| rsk_oauth | Protects a Google or GitHub sign-in | 10 minutes |
| rsk_sso | Protects a single sign-on sign-in | 10 minutes |
The website also remembers a few display choices in your browser’s local storage, such as the code language you picked in the documentation.
Changes to this policy
When this policy changes we update the date at the top of this page. The Terms of Service describe what you agree to when you use Rasket.
Contact
Questions about this policy or your data: info@rasket.com.