Updated August 31, 2026
Privacy policy
cleanify.email is operated by XBesh Labs FZE LLC and is a private tool by design. This page lists exactly what we store, why we store it, and what we never do with it.
1. What we store
- Account data: your email address and a scrypt hash of your password. We never store the password itself.
- Sessions: a hashed session token in an HttpOnly cookie, expiring after 7 days.
- Uploads and results: the CSV rows you upload (including their non-email columns, so exports can preserve them), each address's verdict, reason, and any suggested correction.
- Single-check history: the addresses you check individually and their full verification evidence.
- Operational logs: technical logs for reliability. They exclude passwords, session tokens, and provider secrets.
2. How verification works
When an address is checked, our server-side verification engine performs DNS and MX lookups and a live SMTP conversation with the address's mail server. Only the address being verified is shared with that mail server — that is how SMTP verification inherently works. The engine credential exists only in our server environment and never reaches your browser.
3. What we never do
- We do not sell your data or your lists — to anyone, ever.
- We do not use your lists to build shared databases, train models, or enrich other customers' results.
- We do not send email to the addresses you verify.
- We do not run third-party advertising or cross-site tracking. The only cookie is your session; your theme preference lives in your browser's local storage.
4. Why we are allowed to hold it
We process account data to perform our contract with you, verification data to provide the service you asked for, and a minimum of operational logs for our legitimate interest in keeping the service secure and working. Where you are in the UK or EEA, those are our lawful bases under UK/EU GDPR. We do not rely on consent for any of it, because we do not run advertising or tracking.
For the addresses inside the lists you upload, you are the controller and we are your processor — you decide whose addresses are verified, and we act on your instructions.
5. Who else touches it
We keep the list short, and none of them are advertising companies:
- Fly.io — application and worker hosting.
- Managed PostgreSQL — the database holding your account, jobs and results.
- Stripe — payments. Stripe receives your billing details directly; we never see or store card data.
- Our own verification engine — run by us, not a third party. It contacts the mail servers of the addresses you verify.
Verification inherently means contacting the recipient's mail provider with the address being checked — that is how SMTP verification works, and it is the only circumstance in which an address leaves our systems.
6. Where data lives and transfers
Our application and database are hosted in Singapore, and we are established in the United Arab Emirates. If you are in the UK or EEA, this means your data is transferred outside that area; where required we rely on Standard Contractual Clauses with our providers as the transfer mechanism. Access is scoped per account: your checks, jobs and results are visible only to you.
7. How long we keep it
- Uploads, results and check history: until you delete them or close your account.
- Sessions: 7 days, then they expire and are removed.
- Billing records: retained as long as tax and accounting rules require, even after an account closes.
- Operational logs: short-lived, and they never contain passwords, tokens or secrets.
Deleting your account deletes your checks, jobs, rows and sessions with it — they cascade at the database level rather than being flagged as hidden.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict or object to how we use it, and you can ask for it in a portable form. Much of this you can do yourself: export from Results, change your password in Profile, and delete your account to remove everything.
Write to support@foxora.ai and we will respond within 30 days. If you are in the UK or EEA and think we have got it wrong, you have the right to complain to your data protection authority.
9. Security
Passwords are scrypt-hashed and session tokens are stored only as hashes. The verification credential exists solely in our server environment and never reaches browser code. Traffic runs over TLS. No system is perfectly secure, but we do not hold card data, and we do not hold your password in a form we could read.
10. Children
cleanify is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Cookies
We use one essential cookie for your session and no tracking or advertising cookies at all. The detail is in our cookie policy.
12. Who controls your data
The data controller is XBesh Labs FZE LLC, a Free Zone Entity registered with Ajman NuVentures Centre Free Zone, United Arab Emirates, under licence and registration number 262102428888, registered office 26th Floor, Amber Gem Tower, Sheikh Khalifa Street, Ajman, United Arab Emirates.
13. Changes and contact
If this policy changes materially, we'll announce it in the product before it takes effect. Questions or deletion requests: support@foxora.ai