Mailbox.bot — Outbound Mail API for AI Agents, Businesses, and Developers
Operated by Golden Ratio, LLC, a Utah Limited Liability Company
Effective Date: February 7, 2026 · Last Updated: May 2, 2026
Golden Ratio, LLC ("Company," "we," "us," "our"), the operator of Mailbox.bot, is committed to protecting the privacy and security of your personal information. The Platform's currently live offering is an outbound mail API: you (or your AI agent, MCP client, or REST consumer) submit a document, recipient, and service class, and we print, envelope, stamp, and tender the piece to the carrier on your behalf. Inbound mailbox and physical-package services are in restricted private beta and are not generally available. We take seriously the responsibility you place in us when you transmit documents, recipient data, agent rules, and credentials to the Platform.
This Privacy Policy applies to all information collected through the Mailbox.bot website (mailbox.bot), the Mailbox.bot REST API, the MCP server, the Agent-to-Agent (A2A) endpoint, OpenClaw integrations, the Operator Dashboard, Agent profile pages, and any related services, tools, or communications (collectively, the "Platform").
By using the Platform, creating an account, joining the waitlist, or interacting with our services in any way, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Platform.
We collect information that you voluntarily provide to us, including:
When you access or use the Platform, we automatically collect:
In the course of providing our services, we generate and collect:
We may receive information about you from third-party sources, including:
We use your information to operate, maintain, and improve the Platform, including:
We use your information to protect the Platform and our users, including:
We use your information to communicate with you about your account, service updates, security alerts, and other transactional communications. We will never send you unsolicited marketing emails without your explicit opt-in consent.
We use your information to comply with applicable laws, regulations, and legal processes, including responding to lawful subpoenas, court orders, and law enforcement requests (see Section 6).
We use aggregated, anonymized data to improve our services, analyze usage patterns, and develop new features. This data cannot be used to identify you individually.
We disclose your personal information only in the following circumstances:
We do not provide your name, email address, phone number, physical address, or any other personal information to third parties for the purpose of sending you marketing communications, targeted advertising, or promotional materials. If this ever changes, we will obtain your explicit, affirmative opt-in consent before any such sharing occurs.
We work with the following categories of third-party service providers to operate the Platform:
Stripe Identity — We use Stripe Identity for KYC identity verification. When you verify your identity, Stripe processes your government-issued ID and biometric selfie. Stripe's handling of this data is governed by Stripe's Privacy Policy. We receive only the verification result (verified/rejected), a session identifier, and extracted identity fields. We do not store copies of your identity documents on our servers after verification is complete.
Stripe Payments — All payment processing is handled by Stripe. Your credit card number, CVV, and full payment details are transmitted directly to Stripe and are never stored on our servers. We receive only a tokenized reference, last four digits, expiration date, and transaction status. Stripe is PCI DSS Level 1 certified.
Outbound mail is fulfilled directly through facilities operated by or contracted with the Company. The PDF you submit, the recipient address, the return address, and any agent-supplied metadata are transmitted to the assigned facility's production system, where the piece is printed, enveloped, weighed, postage-applied, and tendered to the selected carrier (USPS, FedEx, or UPS at published retail rates). We do not transmit the contents of your document to any third-party print-and-mail service such as Lob, PostGrid, or any similar SaaS print broker.
Carrier-generated tracking numbers and delivery scans are received from the carrier and surfaced to you via the dashboard, REST API, MCP, and webhooks. Once a mail piece has been handed off to USPS or another carrier, the carrier's privacy practices govern the in-transit handling of the piece and its tracking events.
If you submit a non-PDF document (DOCX, XLSX, RTF, image formats, etc.) and the Outbound Mail cloud-conversion feature is enabled for your account, the file is transmitted to CloudConvert for conversion to PDF prior to printing. CloudConvert deletes uploaded files automatically per its privacy policy. Submissions in PDF, JPG, PNG, or TXT format are converted locally on our infrastructure and are never sent to a third-party converter.
Supabase — Our application database is hosted on Supabase, which provides PostgreSQL with row-level security, encryption at rest, and SOC 2 Type II compliance. Data is stored in secure, access-controlled environments.
Upstash — We use Upstash Redis for rate limiting and Upstash QStash for asynchronous job processing (webhook delivery, outbound mail dispatch, billing sweeps, notifications). QStash signs every job with our signing keys and never receives the contents of your documents.
Resend — Transactional email (verification, security alerts, owner notifications) is sent via Resend. Resend processes recipient addresses and email content solely to deliver the message.
Twilio — SMS notifications, the support-text proxy, and signup-time phone-carrier checks (Twilio Lookup v2) are processed via Twilio.
The Platform uses two and only two analytics providers, both for our own first-party measurement of how the website and product are used. We do not allow either provider to use your data for their own advertising, model training, or third-party sharing.
Vercel — Our website and API are hosted on Vercel's infrastructure. Vercel may process request logs (IP, user agent, request path) in the course of serving the application.
Cloudflare Turnstile — We use Cloudflare Turnstile to protect signup, contact, and waitlist forms from automated abuse. Turnstile may collect device and browser signals to distinguish humans from bots, processed by Cloudflare under its privacy policy.
All third-party service providers are bound by contractual obligations (or, where applicable, by their published Data Processing Addenda) to: process your data only for the purposes we specify; maintain appropriate security measures; not sell, share, or use your data for their own advertising, marketing, or model training; notify us promptly of any security incidents; and delete your data upon termination of our agreement or upon our instruction.
In response to valid legal process, we may disclose:
We may voluntarily report to law enforcement any activity that we suspect involves fraud, money laundering, terrorism financing, Prohibited Items, or other criminal conduct, without prior notice to you. This is consistent with our commitment to operating a safe, lawful platform.
We honor lawful preservation requests from law enforcement and will preserve relevant records for the period specified, or 180 days if no period is specified.
We implement strong encryption to protect your data:
We maintain strict access controls to protect your data:
Our physical Facilities where packages are received and stored employ security measures including restricted access, security monitoring, and inventory tracking. Only authorized personnel are permitted to handle packages.
While we implement commercially reasonable security measures, no system is 100% secure. We cannot guarantee the absolute security of your data. In the event of a security breach that affects your personal information, we will notify you in accordance with applicable law.
We retain your information for the following periods:
We may retain information beyond the standard retention periods if required by law, regulation, or legal process; subject to a pending or anticipated legal hold or litigation; necessary for the investigation of fraud or security incidents; or subject to a law enforcement preservation request.
When data reaches the end of its retention period and no exception applies, it is permanently deleted or irreversibly anonymized. Deletion is performed through secure deletion procedures that render the data unrecoverable.
We use the following categories of cookies:
When you first visit our website, we present a cookie consent banner. You may accept or decline non-essential cookies. Your preference is stored and respected across sessions. You can change your cookie preferences at any time by clearing your browser cookies and revisiting the site.
We respect Do Not Track (DNT) browser signals. When we detect a DNT signal, we disable non-essential analytics tracking for that session.
We do not engage in cross-site tracking. We do not use advertising cookies, retargeting pixels, or any technology that tracks your activity across other websites. We do not participate in ad networks or behavioral advertising programs.
You have the right to request access to the personal information we hold about you. We will provide a copy of your data in a structured, machine-readable format within thirty (30) days of a verified request.
You have the right to request correction of inaccurate or incomplete personal information. You can update most account information directly through the Operator Dashboard or by contacting us.
You have the right to request deletion of your personal information, subject to the following exceptions:
To request deletion, email with the subject "Data Deletion Request." We will process your request within thirty (30) days and confirm deletion in writing.
You have the right to receive your personal data in a portable, machine-readable format (JSON or CSV). This includes your account information, Agent configurations, package records, and API logs.
You have the right to request that we restrict the processing of your personal information in certain circumstances, such as when you contest the accuracy of your data or when processing is no longer necessary but you need the data for legal claims.
You have the right to object to our processing of your personal information for analytics and improvement purposes. To exercise this right, email .
Where our processing of your information is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.
We will not discriminate against you for exercising any of your privacy rights. You will not receive a different level of service or pricing for making a privacy request.
To exercise any of these rights, contact us at . We will verify your identity before processing any request to protect against unauthorized access. We will respond to all verified requests within thirty (30) days.
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information. In the preceding twelve (12) months, we have collected the following categories of personal information:
As a California resident, you have the right to:
California residents may designate an authorized agent to submit privacy requests on their behalf. Authorized agents must provide written authorization from the consumer and verify their own identity. We may deny requests from agents who cannot provide adequate proof of authorization.
Pursuant to California Civil Code §1789.3, California residents may contact the Complaint Assistance Unit of the Division of Consumer Services at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.
Under California Civil Code §1798.83, California residents may request information regarding the disclosure of personal information to third parties for direct marketing purposes. As stated in this Policy, we do not disclose personal information to third parties for their direct marketing purposes.
The Platform is operated from the United States. If you access the Platform from outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Platform, you consent to this transfer.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will promptly delete that information. If you believe a child under 18 has provided us with personal information, please contact us at .
In the event of a data breach that compromises your personal information, we will:
We maintain a documented incident response plan that includes procedures for identifying, containing, investigating, and remediating security incidents. Our response team is trained and prepared to act swiftly in the event of a breach.
We may create aggregated, anonymized, or de-identified data from your personal information. This data cannot reasonably be used to identify you. We may use aggregated data for:
You may opt out of having your data included in aggregated datasets by emailing with the subject "Opt-Out: Aggregated Data." We will honor your request within thirty (30) days.
The Platform exposes its outbound mail capabilities to AI agents and developers via REST API, MCP (Model Context Protocol), A2A (Agent-to-Agent), and OpenClaw. This section describes the data we collect and retain in connection with those programmatic interfaces.
Agent profiles hosted at [agent-slug].mailbox.bot may be publicly accessible. Information you include in an Agent's profile (name, description, capabilities, protocol endpoints) is visible to anyone who accesses the profile URL. Do not include sensitive personal information in Agent profiles.
Data transmitted through the REST API, MCP server, A2A endpoint, or OpenClaw integration (including outbound mail submissions, recipient addresses, document files, agent metadata, and webhook payloads) is encrypted in transit (TLS 1.2+) and at rest (AES-256). We log request/response metadata (endpoint, status code, latency, IP, user agent, agent identifier, idempotency key) to operate, secure, and bill the Platform. API access logs are retained for twelve (12) months. We do not read or analyze the body of your document submissions beyond what is necessary to print, address, weigh, postage, and dispatch the piece.
API keys (member, agent, and facility scopes) and webhook signing keys are issued by the Platform and shown only once at creation. We store a salted hash of the secret portion server-side; we cannot recover the original secret. You are responsible for protecting these credentials. See the Terms of Service for the full credential-security obligations and the Company's position on liability for credential compromise.
For accounts with agents configured, decision logs — which rule triggered, what action was taken, the MAILBOX.md version in effect at the time, and the corresponding API/MCP context — are available to the Account Holder via the dashboard and API. Decision logs are retained for the duration of your account plus five (5) years.
Webhook payloads are signed with your webhook signing key (HMAC-SHA256, format whsk_prefix:t=ts,v1=hmac) so that you can verify their authenticity. We recommend always verifying webhook signatures and rotating signing keys periodically. Webhook delivery logs (event metadata, delivery attempts, response status) are retained for twelve (12) months and are also surfaced to you via the dashboard's API Logs / Webhook Sandbox view.
When you submit a document for outbound mailing, the PDF (or other supported format) is uploaded to our private object storage, encrypted at rest, and transmitted to the assigned facility's production system for printing. The document is accessible only to (a) you and any agent credentials you have authorized, (b) authorized Company personnel and the facility's production staff with a legitimate operational need to print, envelope, weigh, and dispatch the piece, and (c) law enforcement pursuant to valid legal process. We do not read, parse, train models on, or sell the contents of your documents.
For each outbound mail piece, the facility may capture photo evidence of one or more steps in the production lifecycle (printed pages, sealed envelope, postage label, carrier drop-off). These photos are stored with the same encryption and access controls as your document and are surfaced to you via the dashboard, REST API, MCP, and webhooks. Photo proof documents the drop-off event and does not constitute proof of delivery.
Recipient addresses you submit are used solely to address and dispatch the corresponding mail piece, to compute postage, and to satisfy carrier tendering requirements. We do not enrich, sell, share, or repurpose recipient address data for marketing, advertising, list-building, or any other purpose.
Outbound document files are retained for the duration of your account (so that you and your agent can audit historical sends) plus up to seven (7) years for tax, billing-dispute, and audit purposes, after which they are deleted or irreversibly anonymized. You may request earlier deletion of specific document files by emailing , subject to legal-hold and active-litigation exceptions described in Section 8.
Inbound virtual mailbox service and physical-package receiving are in restricted private beta and are not generally available. Privacy practices specific to those services (intake exterior photography, content scanning, package storage, forwarding, and CMRA-related handling) will be described in detail when those services are released to general availability. Members participating in private beta receive a separate beta addendum that supplements this Privacy Policy.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of the Platform after the effective date of an updated Privacy Policy constitutes your acceptance of the updated terms. If you disagree with any changes, you may terminate your account before the effective date.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Golden Ratio, LLC dba Mailbox.bot
Privacy Inquiries
3556 S 5600 W, Suite #1-1038
Salt Lake City, UT 84120
Email:
General Support:
We will acknowledge receipt of all privacy-related inquiries within two (2) business days and provide a substantive response within thirty (30) days.
By creating an account on Mailbox.bot, joining the waitlist, or using our services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.