Privacy policy

Last updated July 22, 2026

Mandoline (mandoline.tools) turns newsletter images into clickable, email-safe HTML. This page explains what data the service touches and what happens to it. The short version: your images stay in your browser, and we store as little as we can get away with.

Your newsletter images

Slicing runs entirely in your browser, and the zip download is generated locally on your machine. Signed out, your image is never uploaded to our servers. When you sign in, your project and its image are saved to your account (stored with our database provider, Supabase) so you can reopen them later; deleting a project deletes the stored image with it. Publishing to Mailchimp uploads the slices directly to your own Mailchimp File Manager, under your Mailchimp account.

To count free projects, we store an anonymous SHA-256 fingerprint of the image along with its file name. The image cannot be reconstructed from this fingerprint.

So you can resume a project later, your browser keeps a copy of the current image in its own local storage on your device. Clearing your browser's site data removes it, and it is replaced whenever you start a new project.

Your account

Signing in uses a magic link. We store your email address and sign-in timestamps, plus your plan status (free or paid). Authentication and our database run on Supabase; sign-in emails are delivered via Resend.

Your Mailchimp connection

Connecting Mailchimp uses OAuth: you approve access on Mailchimp's site and we never see your Mailchimp password. The resulting access token is stored in an encrypted cookie in your browser only; it is not saved in any database. We use the connection solely to upload slices and create the draft campaigns you ask for. Disconnect any time by signing out of the connection or clearing cookies.

Payments

Paid subscriptions are processed by Paddle, our merchant of record. Your card details go to Paddle, not to us; we receive only your subscription status and a customer reference so we can unlock your account.

Cookies

Mandoline uses functional cookies: your sign-in session, the encrypted Mailchimp session, and a short-lived token that protects the OAuth flow. One optional Google Analytics cookie is set only if you accept it in the analytics banner; it tells us which pages are useful. Decline and everything works the same. There are no advertising trackers, and we never sell data. You can at any time.

Where data lives

The app is hosted on Render and the database on Supabase, both in the United States. Emails are sent via Resend. Payments are handled by Paddle. Mailchimp is involved only if you connect it.

Deleting your data

Delete individual projects (and their stored images) from your projects page, or delete your whole account (profile, projects, and images) from your account settings. Email works too. Slices already uploaded to your Mailchimp account are yours and stay under your control there.

Changes and contact

If this policy changes materially, we'll note it here with a new date. Questions or deletion requests: support@mandoline.tools.

Back to Mandoline · Privacy · Terms · Refunds