Privacy Policy

Information the service uses

SpamCatcher uses an account email, framework-protected password credentials, subscription references, reserved addresses, limited message metadata, sanitized message content and supported embedded images, controlled-forwarding attachment data, domain-compatibility reports, and operational audit records to provide the service.

What is not kept

Raw message content is not retained by the application after safe transformation; Postfix may hold queued raw mail while delivery is pending. Supported embedded images are retained with their message and deleted on the same schedule. Remote image URLs are preserved, but remote images are fetched by your browser only when you choose Load images. Loading them can disclose your IP address and an open to the image host.

Supported scanned PDFs are retained with their message for download and optional forwarding, under size/count limits, and follow the message deletion schedule. All images are removed from forwarded content, including embedded coupons, barcodes, and QR codes. View images in your SpamBox using Load images. Links remain and may contain tracking parameters.

Retention and deletion

Ordinary messages expire 30 days after receipt and are removed from active storage by bounded cleanup jobs. Required preservation holds may override deletion. Minimal HMAC tombstones prevent retired names from being reassigned.

Encrypted account and configuration backups are kept for 30 days and exclude inbox message bodies, embedded images, and PDF attachment contents. Inbox content is therefore not recoverable from these backups after a storage loss. Legacy full backups created before the backup-policy change on September 10, 2026 may contain message content and expire within seven days of their creation. Queued raw mail is temporary delivery state and is not included in backups. Offsite backup setup is pending.

Copies you forward or download are outside SpamCatcher's deletion controls. Deleting a message or account, or reaching the 30-day expiry, does not delete those copies; your email provider and local storage have their own retention.

Access and providers

Your inbox is private to your authenticated account. Routine operator screens show operational metadata rather than message bodies. Postmark delivers account notices and controlled account-email forwards. Stripe handles billing. No advertising pixels or message-content marketing analytics are used.

First-party product measurement

When browser privacy preferences permit it, a first-party cookie lasting up to 90 days links public page visits and signup actions. We record the landing path, referring hostname, and campaign parameters. We do not use advertising pixels or browser fingerprinting. Do Not Track and Global Privacy Control suppress public-site tracking.

For service activation, we count accepted messages and up to three distinct observed sender domains. The analytics record uses account-specific keyed hashes, not message bodies, subjects, or sender addresses. Funnel events are retained for up to two years; unlinked visitor records for 90 days. Account activation totals and reminder records remain until account deletion. Campaign links associated with an account remain with that account.

Service providers and security checks

Cloudflare Turnstile helps prevent automated signup abuse. Signup verification sends a challenge response and your IP address to Cloudflare. Hosting and database providers process service data on our behalf; Stripe processes payment information and Postmark processes the recipient address and contents of account notices and the sanitized messages and optional supported PDFs you choose to forward. Your account-email provider also receives those copies. Their own privacy policies also describe their processing. We do not store raw payment-card numbers.

Your choices and requests

You can delete individual messages and request account deletion from your account settings. Account deletion removes account contact and login credentials and retires activated addresses; required preservation holds can delay deletion. Limited subscription, security, audit, and permanent address-claim records may remain after account deletion. Backup copies expire on the schedule above. Deleting a SpamCatcher account does not erase records Stripe or other providers must retain independently.

For privacy questions or access, correction, or deletion requests, use https://account.thespamcatcher.com/abuse and select Privacy. We may need to verify account ownership before acting. Do not submit passwords, payment details, or private message contents.

Operator and updates

SpamCatcher is operated by OneStage Solutions LLC, PO Box 125, Cusick, WA 99119, United States. This policy was updated September 16, 2026. Changes will be reflected on this page; material changes affecting an existing account will be communicated as appropriate.

Billing request history

We retain refund and cancellation records, the selected survey reason, optional comments, payment references, and purchase-review decisions for billing support and abuse prevention. These records can remain after account deletion. Do not include sensitive information in survey comments. The operator receives billing outcome and exception notices. Refund and cancellation alone do not delete your account.