Docs Navigation
Security & Privacy

Your data is safe with us

We take your privacy and the security of your client information seriously. Here's exactly what we protect, how we keep things secure, and what controls you have.

🏆

Your data belongs to you

The client information you upload — names, email addresses, messages — is yours. We do not sell it, share it with advertisers, or use it for any purpose other than sending the emails you approve.

What we protect

Your Client Data

All information you upload is stored securely and only accessible to your account. We never share it with third parties.

Your Email Connection

When you connect Gmail or Outlook, we only use it to send messages you've approved. We never read your inbox.

Your Approval Decisions

Only you can approve, edit, or cancel emails. No one at QubrixMail can send emails on your behalf — ever.

How we keep it secure

🔒

Encrypted data

All your data is encrypted — both when it's being transferred and when it's at rest on our servers.

🔑

Secure login

Your account is protected by a secure login. Use a strong, unique password to keep it safe.

🤝

Standard authorisation

Your email connection uses industry-standard OAuth — we never see or store your email password.

🌐

HTTPS everywhere

All web traffic between your browser and QubrixMail is protected with HTTPS encryption.

Your controls

You are always in control of your data.

Delete uploads

Remove any uploaded file and all its associated scheduled emails at any time.

Cancel scheduled emails

Prevent any pending email from being sent — before you've approved it.

Disconnect your email

Revoke QubrixMail's access to your email account from Settings → Email Account.

Request data deletion

Contact us to permanently delete your account and all associated data.

Team & Role Security

If you are on the Business plan with team members:

Each team member has their own account with their own credentials — no shared passwords
Role permissions are enforced server-side — they cannot be bypassed from the browser
Viewers cannot approve or take any action on emails, even if they have direct access to task URLs
All team actions (approvals, rejections, role changes) are logged in the audit trail
Removing a team member immediately revokes their access

How to stay safe as a user

Use a strong, unique password for your QubrixMail account
Only connect your own business email — not a personal or shared account
If you suspect unusual activity, contact contact@qubrixmail.com immediately
When leaving a role or company, disconnect your email before handing over the account

API Key Protection

If you are on Standard or Business plan and use your own email provider:

  • Your API key is encrypted with AES-256-GCM before storage
  • It is never visible in plain text in any UI or response
  • Only the last 4 characters are shown after saving
  • Keys are decrypted in server memory only, at send time
  • You can revoke access anytime by deleting the key at your provider and adding a new one in Settings

See API Key Security in our documentation for full technical details.

Questions about our security practices?

contact@qubrixmail.com

Can't find what you need?

Visit our Help Centre or contact the support team — we respond within one business day.