Privacy policy

Last updated 13 September 2026.

Registration details outstanding
Everything below describes what this software actually does. The items shown in square brackets are company registration details that have not been filled in yet; they are marked rather than guessed.

Who is responsible for what

5dayemail.com is operated by [to be supplied: registered legal entity name], registered in the Netherlands under [to be supplied: Dutch Chamber of Commerce (KvK) number], at [to be supplied: registered business address].

There are two different relationships here and they are not interchangeable. For a course list, the creator is the data controller and we are their processor. They decided to collect the address, they wrote what is sent to it, and a request about that data is theirs to answer. We store and deliver it on their instructions and never use it for anything else. For a creator account, we are the controller — the account, the courses written in it and the billing relationship, if one ever exists, are ours.

If you are subscribed to a course

We store, for as long as you are on that list:

  • Your email address, because there is no way to send you an email without it, and a one-way hash of it so that an address that has unsubscribed can be recognised and refused without keeping the address itself.
  • Your time zone, taken from your browser when you signed up, so that each day of the course arrives in the morning where you are rather than in the middle of your night.
  • Which day of the course you are on, when you confirmed, when the last email went out, and whether you have paused or finished.
  • Which days you have opened on the web. Each email links to a page where you can read that day in a browser, and opening it records that day as read, against your subscription and with the time. Pressing "mark complete" on that page records the same thing. It is how the progress shown on those pages is counted. Nothing records it if you only ever read the email itself.
  • The record of your consent: the date, the IP address and the browser you used to sign up, and a SHA-256 hash of the exact sentence you agreed to. The hash rather than the sentence, because the point is to prove which wording you saw. This record is append-only and is never edited.

Your first name is not stored. It is used to address the confirmation email and then discarded — there is no column for it anywhere in the database. We do not track opens and we do not embed tracking pixels — nothing in an email reports back that you looked at it. The one thing we do record is described above: following an email's link to read a day on the web marks that day read. That is a page you chose to open, not a pixel that fired without you.

The lawful basis is your consent, which you gave by clicking the confirmation link, and which you can withdraw at any time using the unsubscribe link in any email. The consent record itself is kept under our legitimate interest in being able to demonstrate that consent was given, which is what Article 7(1) of the GDPR requires of us.

If you write courses here

Signing in is Google only; there is no password to store. From your Google account we receive and keep your email address and display name. You additionally supply a sender name, a reply-to address, a time zone, and a postal address.

Your postal address is published. It appears in the footer of every course email you send, because a bulk commercial email without a real postal address is one mailbox providers are entitled to treat as spam. Do not use a home address you are not willing to have read by strangers; a registered business address or a PO box is the right thing here.

We also store the courses you write, every saved version of every email in them, and any images you upload. Uploaded images are stored in a bucket that is readable by anyone holding the URL, because they have to be fetchable by a mail client with no session. An image is not deleted when you remove it from an email or archive the course — there is no cleanup pass yet, so treat anything you upload as published from the moment it is uploaded.

The lawful basis is the contract between us: we cannot run the account without this.

Cookies and analytics

Signing in sets a session cookie. It is strictly necessary — it is what keeps you signed in — and it is not used to measure anything.

No analytics cookies are set, anywhere on this site. Ten pages — the home page, this one, the terms, the guides index and the six guides — load Google Analytics 4, and they load it with every consent signal set to denied. In that state it writes nothing to your browser and gives you no identifier: what leaves the page is an anonymous count that a page was viewed, which cannot be joined up across visits, across devices or to you.

Every other page loads no analytics at all. That includes the opt-in page for a course, the page a confirmation link lands on, the unsubscribe page, and the signed-in creator area. If you got here by clicking a link in an email you asked for, you are not being measured — and measuring someone on the page where they are trying to leave would be the worst version of this.

There is no cookie banner because there is nothing to ask you for. A banner exists to get permission to store something on your device; nothing here stores anything on your device for measurement, so the question does not arise. Nothing on the site depends on the measurement working, and a content blocker will stop it with no effect on anything.

Who else touches the data

These are the only processors involved:

  • Supabase — the Postgres database that holds everything described above, plus authentication and file storage. Hosted in the United States (region us-east-1, Northern Virginia).
  • Resend — the email provider that delivers every message. They necessarily see the recipient address and the content of the email, and they keep their own delivery, bounce and complaint logs under their own policy.
  • DigitalOcean — the servers that run the application and the send loop, in the United States (New York region), beside the database.
  • Google — sign-in for creators (Google account holders only) and the analytics described above.

Two of these place personal data outside the European Economic Area. The database that holds your subscriber record and the consent ledger is hosted in the United States, and mail delivery runs through Resend, which is established there. Both transfers rely on the standard contractual clauses in those providers' data processing agreements. The application servers sit beside the database in the United States, and Google sign-in applies only to creators, who choose it.

How long it is kept

  • Subscriber records and the consent ledger: for as long as the list exists. Neither is on any automatic deletion schedule, because the consent ledger is the evidence that the mail was wanted. Both are removed by an erasure request.
  • Delivery and bounce records: 180 days, then deleted nightly.
  • Operational health and dispatch logs: 30 days, then deleted nightly. These hold no addresses.
  • The suppression list: forever, and this is deliberate. It holds a SHA-256 hash of an address that has unsubscribed, bounced, complained or been erased, and nothing else. It is never pruned and no cascade can remove it, because the whole point of it is that an address which has said stop can never be added back to any list here by anyone, including by the person who erased it.

Your rights, and how to use them

Under the GDPR you can ask for a copy of your data, ask for it to be corrected or erased, ask us to restrict or stop processing it, ask for it in a portable form, and withdraw consent at any time.

If you are on a course list, the fastest route is the unsubscribe link in any email you have received: one click stops every remaining email immediately, with no confirmation page and nothing to fill in. It stops mail from the whole platform, permanently, including courses by other creators, and it cannot be undone by anyone — including by us. For anything more than stopping the mail, write to the creator whose course you joined — they are the controller, and every email from them carries their reply-to address. You can also write to us at [to be supplied: address for data protection requests] and we will act on it.

If you write courses here, write to [to be supplied: address for data protection requests]. Deleting a creator account deletes the courses, the subscribers, the send history and the delivery records that belong to it.

You have the right to complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens.

What erasure actually does

Erasing a subscriber is one transaction and it removes the subscriber record, the consent ledger entries, every queued and sent message, every link token, every progress record and every delivery event attached to that address. Not marked deleted — deleted.

One thing survives, and you should know about it before you ask. A SHA-256 hash of the address is written to the suppression list first, and that row is never removed. The hash cannot be turned back into the address, and it is not used to contact anyone — it exists so that the address can never be re-added to a list here, by import or by anybody typing it in. It is the only way to make "erase me and never mail me again" mean both halves of the sentence at once.

Security

Application data lives in a database schema that is not exposed to the public API at all, so it can only be read by the server. Confirmation and unsubscribe links are opaque random tokens and only a keyed hash of each one is stored, so a copy of the database does not yield a working link. There are no creator passwords to leak.

Changes

If this policy changes in a way that affects what is collected or who it is shared with, the date at the top of this page changes with it. The wording a subscriber agreed to at sign-up is stored as it was and is not rewritten by a later version of this page.