MAAC GO EMAIL

Privacy Policy

This describes what MAAC GO Email actually stores and who touches it. It is written from the running system rather than from a template, so it is specific — and it will be updated when the system changes.

Last updated 1 September 2026 · Operated by Crescendo Lab (漸強實驗室)

Two kinds of people are involved

You are our customer: you sign in and send email. The people on your contact list are your recipients — we process their data on your instructions, as a service provider. You decide who is on your list and what you send them; you are responsible for having permission to contact them.

What we store about you

What we store about your recipients

Open and click tracking — who does it

We do not inject tracking pixels or rewrite links ourselves. Open and click data reaches us from our mail delivery provider (Resend), which performs that measurement as part of delivering the message, and reports it back to us by webhook. If you would rather your recipients were not measured this way, that is a provider-level setting and you should contact us before sending.

Cookies on this website

There is no third-party analytics on this site — no Google Analytics, no advertising pixels, no session recording. We set exactly two things in your browser:

Who else processes this data

ProcessorWhat forWhat they see
ResendDelivering emailRecipient addresses, subject and body of messages you send, delivery and engagement events
Google CloudHosting, database, image storageEverything above, at rest. Application and database run in asia-east1 (Taiwan)
Google Identity"Continue with Google" sign-inYour email address and name, if you choose that sign-in method
StripePrepaid credit top-upsYour payment details, directly — they never pass through us
SlackOur internal signup notificationsYour account email and sign-in method

Images you upload for your emails are stored in a Google Cloud bucket and served from a public, unguessable URL — mail clients fetch images anonymously, so they cannot be access-controlled. Do not put anything confidential in an email image.

How long we keep it

Contacts, campaigns and delivery records are kept for as long as your account exists, because they are the record of what you sent. Login codes are deleted a day after they expire. Suppression entries are kept deliberately — deleting them would let a previously unsubscribed person be mailed again.

Deletion and access

You can delete individual contacts and campaigns yourself in the app. To delete your whole account and everything in it, email info@cresclab.com from your account address; we remove the account, its contacts, campaigns, delivery records and uploaded images.

If you are a recipient rather than a customer: the sender controls your data. Every campaign carries a one-click unsubscribe link, which stops that sender from mailing you immediately. For anything else, contact the sender directly — or us, and we will pass it on.

Security

Traffic is HTTPS only. Sessions are signed tokens. API keys are stored as bcrypt hashes behind a short lookup prefix, so a database dump does not yield working keys. Secrets live in Google Secret Manager, not in code.

Contact

Crescendo Lab (漸強實驗室) — info@cresclab.com · cresclab.com

Home Pricing Transactional API MCP Privacy Terms 中文 Crescendo Lab · Contact