Privacy policy

Last updated August 3, 2026

Mandoline (mandoline.tools) turns newsletter images into clickable, email-safe HTML. This page explains what data the service touches and what happens to it. The short version: your images stay in your browser, and we store as little as we can get away with.

Your newsletter images

Slicing runs entirely in your browser. Signed out, your image is never uploaded to our servers.When you sign in, your project and its image are saved to your account (stored with our database provider, Supabase) so you can reopen them later; deleting a project deletes the stored image with it. Publishing hosts the finished slices on Mandoline's CDN, or uploads them directly into your own Mailchimp, Klaviyo, or HubSpot account if you connect one.

To count free projects, we store an anonymous SHA-256 fingerprint of the image along with its file name. The image cannot be reconstructed from this fingerprint.

So you can resume a project later, your browser keeps a copy of the current image in its own local storage on your device. Clearing your browser's site data removes it, and it is replaced whenever you start a new project.

Your account

Signing in uses a magic link. We store your email address and sign-in timestamps, plus your plan status (free or paid). Authentication and our database run on Supabase; sign-in emails are delivered via Resend.

Your email platform connection

Connecting Mailchimp, Klaviyo, or HubSpot uses OAuth: you approve access on the platform's own site and we never see your password there. The resulting access token is stored in an encrypted cookie in your browser only; it is not saved in any database. We use the connection solely to upload slices and create the draft campaigns you ask for. Disconnect any time by signing out of the connection or clearing cookies.

Payments

Paid subscriptions are processed by Paddle, our merchant of record. Your card details go to Paddle, not to us; we receive only your subscription status and a customer reference so we can unlock your account.

Cookies

Mandoline uses functional cookies: your sign-in session, the encrypted email-platform session, and a short-lived token that protects the OAuth flow. Google Analytics loads only if you accept it in the analytics banner, and then sets two cookies telling us which pages are useful. Decline and it is never loaded, so nothing about your visit reaches Google. We also count page visits and product milestones (an image was opened, a link was finished, the code was copied or sent to Mailchimp) with Umami, a privacy-focused analytics tool that sets no cookies, stores nothing on your device, and keeps no identifier that could follow you between days. Those records carry the page address and the page you came from, your browser, language, screen size, a country derived from your IP address, how you started the project, how many links it had, and whether the account is free or paid. They never include your images, link addresses, alt text, project names, or anything else you typed, and sign-in codes are stripped out before either tool sees them. We call this pseudonymous rather than anonymous: nothing is linked to your account, but it is not a blank slate either. Google Analytics runs on your consent, which you can withdraw at any time; our basis for the cookieless counts is our legitimate interest in knowing which parts of the service work. There are no advertising trackers, and we never sell data. You can at any time.

Where data lives

The app is hosted on Render and the database on Supabase, both in the United States. Slices you host with Mandoline are served from Cloudflare's CDN. Emails are sent via Resend. Payments are handled by Paddle. Usage counts are processed by Umami Cloud, and by Google Analytics only for visitors who accept it, both in the United States. Your email platform is involved only if you connect it.

Deleting your data

Delete individual projects (and their stored images) from your projects page, or delete your whole account (profile, projects, images, and slices hosted with us) from your account settings. Email works too. Slices already uploaded to your email platform's account are yours and stay under your control there.

Changes and contact

If this policy changes materially, we'll note it here with a new date. Questions or deletion requests: support@mandoline.tools.

Back to Mandoline · Privacy · Terms · Refunds