
Mailgun
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •In AI: it does not document ethical AI principles, which may generate distrust regarding data usage.
- •In Core Privacy: it details data processing purposes, ensuring transparency on how information is used.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •Mailgun
- •Does not document ethical AI principles, which may raise concerns about responsible data use.
- •There is no explanation of how automated decisions are made, limiting user trust.
- •Requires a clause addressing ethical AI principles and explanations of automated decisions.
Ethical AI principles and anti-bias measures not documented
There is no mention of ethical AI principles in the policy, which may raise concerns about the responsible use of email data.
Automated AI decisions have no explanation available
The lack of explanation on how automated decisions are made may generate distrust among email data users.
AI decision contestation mechanism not available
The policy does not mention the possibility of challenging automated decisions, limiting the rights of email data users.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Mailgun
- •The policy presents a detailed table connecting data categories with specific purposes.
- •The policy lists categories of recipients with specific purposes, ensuring clarity.
- •These practices offer security and transparency for your company's due diligence.
AI features clearly identified with their purposes
The policy describes specific functionalities that use AI, such as automated risk analysis, essential for security in email campaigns.
AI data retention policy clearly documented
The policy defines retention periods for email data and user interactions, although it does not specifically mention 'prompts'.
AI training opt-out control available
The policy offers opt-out mechanisms, but not a specific opt-out for email data used in AI training, which may limit user choice.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller and processor roles clearly defined
The policy clearly defines the roles of controller and processor, essential for ensuring compliance in managing email data and user interactions.
Data controller identity and contact clearly disclosed
The policy provides clear information about the controller's identity, facilitating contact for issues related to email data and user interactions.
Processing purposes clearly listed by data category
The policy presents a detailed table connecting email data and user interaction categories with specific purposes, ensuring transparency.
Source: vendor public documents
Critical Alerts
- •Decisões automatizadas por IA não têm explicação disponível: Importante para a transparência e confiança do usuário..
- •Mecanismo de contestação de decisões de IA não disponível: Crucial para a proteção dos direitos dos usuários.
Conformance analysis (20)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Processing purposes clearly listed by data category
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Mailgun Email Marketing: Privacy and AI Governance Audit Insights
Transparency in Data Processing Purposes
Mailgun excels in its transparency regarding data processing purposes. With an AITS Privacy Score of 89%, users can feel confident knowing that the platform clearly lists the purposes for which data is processed, categorized by data type. This clarity is crucial for users who want to ensure their data is handled responsibly and in compliance with regulations like GDPR and LGPD. By understanding how their data is utilized, users can make informed decisions about their email marketing strategies, aligning their practices with legal requirements and ethical standards.
Clear Identification of Data Recipients
Another strength of Mailgun is its clear identification of personal data recipients in its privacy policy. This transparency allows users to understand who has access to their data, which is essential for maintaining trust and compliance with privacy laws. Knowing the third parties involved in data processing helps users assess potential risks and take necessary precautions, such as limiting data sharing or opting for additional security measures. This proactive approach can enhance user confidence in Mailgun's email marketing services.
Lack of Ethical AI Principles
Despite its strengths in privacy, Mailgun has notable weaknesses in its AI governance. The platform does not document ethical AI principles or anti-bias measures, which raises concerns about the responsible use of artificial intelligence in its services. For users, this means that while Mailgun may leverage AI for automation and optimization, there is a lack of transparency regarding how these technologies are applied. Users should be cautious and consider the implications of using AI-driven features without a clear understanding of the underlying ethical framework.
Absence of Explanation for Automated Decisions
Another significant weakness is the absence of explanations for automated decisions made by AI. This lack of clarity can lead to distrust among users, especially when decisions impact their marketing campaigns or customer interactions. Users should be aware that without a mechanism to contest these automated decisions, they may have limited recourse if they feel that an AI-driven choice negatively affects their operations. To mitigate this risk, users should closely monitor the outcomes of AI-driven features and be prepared to adjust their strategies accordingly.
Practical Settings and Precautions
To enhance their experience with Mailgun while addressing potential weaknesses, users should take practical steps. First, review the platform's settings related to data sharing and AI features. Ensure that any AI-driven functionalities are aligned with your business's ethical standards and that you are comfortable with how data is processed. Additionally, consider implementing alternative solutions for critical tasks that require a higher level of transparency and accountability in AI decision-making.
Exploring Alternatives for Enhanced AI Governance
Given the concerns surrounding Mailgun's AI governance, users may want to explore alternative email marketing platforms that prioritize ethical AI practices and provide clear documentation on automated decision-making processes. Researching competitors with higher AITS AI Scores can help users find solutions that better align with their privacy and ethical standards. By weighing the strengths and weaknesses of Mailgun against other options, users can make informed choices that support their marketing goals while safeguarding their data privacy.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Mailgun:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents