Privacy Policy

Effective October 4, 2026

This Privacy Policy explains how Camora ("we", "us") collects, uses and shares personal information in connection with Camora, the email marketing and automation platform at camora.ai (the "Service"), and the choices you have.

There are two kinds of people this policy covers:

  • Customers and visitors: people who visit our website, request access, or use the Service through an account. For this information we are the controller.
  • Our customers' contacts: the people our customers email or message using the Service. Our customers decide what data they collect and how they use it; we process it on their behalf as a processor (or "service provider"). If you received an email sent through Camora, the sender's privacy policy applies, and you should contact the sender first. You can always unsubscribe with the link in the email.

1. Information we collect

Information you give us

  • Access requests: your name, work email, company, website, expected sending volume and anything you tell us about what you plan to send.
  • Account information: name, email address, password (stored only as a secure hash), workspace name and team roles.
  • Customer configuration: sending-provider credentials (stored encrypted), sending and tracking domains, postal address, routes, offers and settings.
  • Content and Customer Data: contact lists and fields, templates, campaigns, workflows, uploaded files, and the prompts and messages you send to the in-app AI assistant.
  • Communications: messages you send us for support or otherwise.

Information collected automatically

  • Usage and log data: IP address, browser and device type, pages and features used, timestamps and error logs, used to operate and secure the Service.
  • Cookies: we use only the cookies the Service needs to work: a session cookie that keeps you signed in, and a preference cookie that remembers light or dark mode. We do not use advertising or third-party analytics cookies on camora.ai.

Information about our customers' contacts (processed for customers)

Email address, name and any custom fields the customer imports or collects; list and tag membership; sending history; and engagement events such as deliveries, bounces, complaints, opens (via a tracking pixel), clicks (via redirect links), unsubscribes and conversions reported by the customer's partners. Open and click tracking records the IP address and user agent of the request.

2. How we use information

  • To provide, maintain and secure the Service, including sending messages on our customers' instructions and processing unsubscribes and suppressions.
  • To review access requests and contact you about your request or account.
  • To provide AI features you ask for, such as drafting campaigns, building workflows and answering questions about your data.
  • To protect deliverability and prevent abuse, for example by monitoring bounce and complaint rates and pausing risky sends.
  • To troubleshoot, improve and develop the Service.
  • To comply with law and enforce our Terms of Service.

We do not sell personal information, and we do not use our customers' contact data for our own marketing or to train AI models.

3. How we share information

We share information only as needed to run the Service, with:

  • Service providers (sub-processors) that host and power the Service under contracts that protect the data:
    • Railway (application hosting and database)
    • Cloudflare (DNS, network and security)
    • Anthropic (AI features; content you send to the assistant or agents is processed to generate responses and is not used to train its models)
    • Sending providers that customers connect, such as Amazon Web Services (Amazon SES) and FeedBlitz, which deliver the customer's messages
    • Slack (internal notifications to our team about new access requests)
  • Integrations our customers configure, such as webhooks, affiliate postbacks and data feeds. These send data where the customer directs.
  • For legal reasons, when we believe disclosure is required by law, subpoena or court order, or necessary to protect the rights, safety or property of Camora, our customers or others.
  • In a business transfer, such as a merger, acquisition or sale of assets, subject to this policy.

4. Retention

  • Account information is kept while your account is active and deleted within 30 days after it closes, unless we must keep it longer by law.
  • Customer Data is kept until the customer deletes it or closes their account, then deleted within 30 days. Backups roll off on their normal schedule.
  • To honor unsubscribes and complaints, we may keep the minimum information needed to make sure an address is not mailed again.

5. Security

We use administrative, technical and physical safeguards designed to protect personal information, including encrypted connections (HTTPS), encryption of stored provider credentials, hashed passwords and session tokens, role-based access within workspaces, and limited internal access. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you as required by law.

6. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have the right to know, delete and correct, and to not be discriminated against for exercising these rights; we do not sell or share personal information for cross-context behavioral advertising.

  • Customers and visitors: email legal@camora.ai. We will verify your request and respond within the time the law requires.
  • Contacts of our customers: contact the sender of the email. If you contact us, we will forward your request to the relevant customer. To stop emails, use the unsubscribe link in any message.

If you are in the EU, UK or Switzerland, you may also complain to your local data protection authority.

7. International transfers

We and our service providers are based in, and process information in, the United States. Where the law requires, we rely on appropriate safeguards such as Standard Contractual Clauses for transfers of personal information from the EU, UK and Switzerland.

8. Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

9. Changes to this policy

We may update this policy from time to time. If changes are material, we will notify customers by email or in the Service before they take effect, and we will update the effective date above.

10. Contact

Camora. Privacy questions or requests: legal@camora.ai.