

Mailtrap
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •Regarding AI: it does not mention the use of artificial intelligence, which raises uncertainties about data processing.
- •Regarding Basic Privacy: it documents the purposes of data processing, ensuring clarity on the use of collected information.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (3)
AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.
- •Mailtrap
- •Does not document the use of artificial intelligence, which can generate uncertainties about data processing.
- •Omission of ethical AI principles may compromise fairness in data processing.
- •Requires specific clauses in contracts to address AI use and anti-bias measures.
Use of artificial intelligence is not disclosed in policies
The policy does not mention the use of artificial intelligence, which can generate uncertainties about how email interaction data is processed.
Ethical AI principles and anti-bias measures not documented
The policy does not mention ethical AI principles, which can raise concerns about the fair processing of email interaction data.
AI decision contestation mechanism not available
The policy does not specifically mention human review or contesting automated decisions, limiting customer rights.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Mailtrap
- •Clearly identifies the data controller, facilitating communication about privacy.
- •Provides a Data Processing Agreement (DPA) for business customers, ensuring commitment to data protection.
- •These practices strengthen due diligence and trust in data management.
AI data retention policy clearly documented
The policy clearly details the retention of interaction data, including specific periods and the user's ability to manage their data.
Policy on data use for AI training clearly stated
The policy mentions the use of collected data to improve the service, but does not clearly specify AI model training.
AI training opt-out control available
Although the policy offers general data protection rights, there is no specific and explicit opt-out for AI training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller and processor roles clearly defined
The policy clearly identifies the responsible company and defines the scope of services covered, ensuring transparency.
Data controller identity and contact clearly disclosed
The policy provides clear information about the controller's identity and contact, facilitating privacy communication.
Privacy contact channel available
The privacy policy provides a specific contact channel for privacy issues, ensuring customer support.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: Importante para garantir que os dados sejam tratados de forma ética e responsável..
- •Mecanismo de contestação de decisões de IA não disponível: Crucial para garantir que os clientes possam contestar decisões que impactam suas interações.
Conformance analysis (20)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Contact channel for privacy issues available
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Mailtrap Email Marketing: Strengths, Weaknesses, and Practical Guidance for Privacy and Security
Transparency in Data Control
Mailtrap excels in providing clear information about the data controller, which is crucial for users concerned about their privacy rights. With an AITS Privacy Score of 89%, users can feel confident knowing who is responsible for their data. This transparency allows users to understand whom to contact regarding data inquiries, ensuring compliance with regulations like GDPR and LGPD. By clearly listing the identity and contact information of the data controller, Mailtrap empowers users to exercise their rights effectively, such as requesting data access or deletion.
Clear Purpose of Data Processing
Another strength of Mailtrap is its documentation of data processing purposes. The platform categorically lists the reasons for data collection, which enhances user trust and aligns with privacy regulations. This clarity helps users understand how their information is utilized, whether for analytics, service improvement, or marketing. By knowing the specific purposes, users can make informed decisions about their data sharing, ensuring that they are comfortable with how their information is being used.
Lack of AI Transparency
Despite its strengths, Mailtrap has notable weaknesses, particularly regarding its handling of artificial intelligence. The AITS AI Score of 29% indicates significant gaps in transparency about AI usage. Users should be aware that Mailtrap does not disclose whether it employs AI in its operations, which raises concerns about data processing practices. Without this information, users may find it challenging to assess how their data is being managed, especially in terms of automated decision-making processes.
Absence of Ethical AI Principles
Additionally, Mailtrap does not document ethical AI principles or anti-bias measures. This lack of information can be alarming for users who prioritize fairness and accountability in AI systems. Without clear guidelines or policies, users may be exposed to risks associated with biased algorithms or unfair treatment based on automated decisions. To mitigate this risk, users should consider reaching out to Mailtrap for clarification on their AI practices and demand transparency regarding any AI-related functionalities.
Practical Settings to Enhance Privacy
To maximize privacy while using Mailtrap, users should regularly review their account settings. Ensure that data sharing preferences are set to the minimum required for functionality. Users should also enable any available privacy features, such as two-factor authentication, to enhance account security. Furthermore, regularly auditing the data collected by Mailtrap can help users stay informed about what information is being processed and for what purposes.
Alternatives and Precautions
For users concerned about the weaknesses identified, it may be prudent to explore alternative email marketing platforms that provide more robust AI governance and transparency. Look for platforms that explicitly outline their AI usage and ethical guidelines. Additionally, consider implementing a data minimization strategy by only providing essential information when using Mailtrap. This approach not only protects user privacy but also aligns with principles outlined in ISO 27701, ensuring compliance with international data protection standards.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Mailtrap:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents