How MySecureSend protects your data, and where it lives.
Database & files metadata
Supabase, Sydney (AWS ap-southeast-2)
Application hosting
Vercel, Sydney (syd1)
Encryption service
Google Cloud Run, australia-southeast1 (Sydney)
Files are encrypted with AES-256 on our Sydney servers before the email is sent. PDF files are encrypted natively. Office documents use msoffcrypto. All other file types are encrypted into an AES-256 protected .zip via pyzipper.
OAuth2 tokens (used to send email on your behalf) are encrypted with AES-256 before storage. All database connections use TLS.
Files exist on our systems only for the seconds it takes to encrypt and send them. Once the email is sent, the file is discarded. We do not store file contents at any point, and cannot retrieve or reproduce a file after it has been sent.
| Data type | Retention |
|---|---|
| Account data | Duration of account + 90 days after deletion |
| Audit log (send_logs) | 7 years, to meet compliance obligations |
| OAuth2 tokens | Until you disconnect the account or delete it |
| Files | Not retained - discarded immediately after sending |
We connect to your Gmail or Outlook 365 account using send-only permissions:
Gmail: gmail.send - lets us send email as you. We cannot read your inbox, search your mail, or access anything beyond sending the message you initiate.
Outlook 365: Mail.Send - same principle. Send-only, no inbox read access.
We use the following service providers to deliver MySecureSend. Each is used strictly for the purpose below, and none receive your file contents.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | Sydney (ap-southeast-2) |
| Vercel | Application hosting | Sydney (syd1) |
| Google Cloud Run | File encryption processing | Sydney (australia-southeast1) |
| Twilio | SMS delivery (password notifications) | - |
| Resend | Transactional email delivery | - |
| OAuth2 - sending email on your behalf only | - | |
| Microsoft | OAuth2 - sending email on your behalf only | - |
This list is also referenced from our Privacy Policy and our Data Processing Agreement.
If your practice needs a signed Data Processing Agreement in place, email us at support@mysecuresend.com.au and we’ll send one across for you to countersign.
If you’ve found a security vulnerability, email us at support@mysecuresend.com.au. We’ll acknowledge your report and investigate promptly. Please don’t publicly disclose an issue before we’ve had a chance to address it.
For anything else, contact support@mysecuresend.com.au.