Blog →

Missive security and privacy FAQ

Table of content

by

Eva Tang

December 10, 2020

· Updated on

April 24, 2026

Missive was built with privacy as a core principle, not an afterthought. We’re SOC 2 Type II compliant, GDPR compliant, encrypt data at rest and in transit, don’t sell user data, and block read trackers in emails by default. This FAQ answers the questions we hear most often about reliability, privacy, and security.

The short version:

  • Missive does not sell user data to third parties, ever.
  • All data in our database and cloud storage is encrypted at rest.
  • SOC 2 Type II compliant, audited by an independent CPA.
  • Fully GDPR compliant, with a published Data Processing Agreement.
  • We pass Google’s yearly OAuth API security assessment (required for any service that connects to Gmail or Google Workspace).
  • When viewing emails in Missive, read trackers and 1x1 tracking pixels are blocked by default.

Full details live in our privacy policy and security page. Everything below is the plain-language FAQ.

Can Missive access my emails?

Technically yes, the same way Gmail can read your Gmail and Outlook can read your Outlook. Missive imports email via IMAP or OAuth and stores it in our database. That’s the technical foundation of a collaborative inbox: your team can only work on a message together if the message is available to the app.

That said:

  • Only a small number of our engineers have database access.
  • Our internal tools surface system health signals (volume, performance, errors), not email content.
  • We don’t scan, share, or sell user data.
  • We only look at a specific user’s content when that user has explicitly asked us to, usually while investigating a bug they reported.

Why is Missive more secure than a shared Gmail or Outlook account?

Most teams that end up on Missive start by sharing passwords to a Gmail or Outlook account, or by setting up a distribution list that forwards to everyone. Both approaches break down on the security side:

  • Shared passwords can’t be revoked cleanly. When someone leaves the team, you’re either rotating the password (and re-distributing it to everyone) or accepting that an ex-employee still has access. With Missive, access is per-user. Removing someone instantly cuts their access to every shared inbox they were part of.
  • No audit trail. If three people share one Gmail login, you can’t tell who replied to which message, who deleted what, or who opened which attachment. Missive logs every action per user, with timestamps.

The short version: Missive doesn’t replace Gmail or Outlook as your mail server, your email still lives there. Missive adds an access layer designed for teams on top, which is more auditable and more revocable than sharing credentials.

Does Missive use my email content to train AI?

No. Missive does not train models on your data.

If you turn on Missive’s AI assistant or AI rules, the relevant content is sent to the AI provider you picked (OpenAI, Anthropic, or Google). Each provider has its own policy, but the pattern is consistent:

  • OpenAI: does not train on API inputs unless you explicitly opt in. Prompts and responses retained for up to 30 days for abuse monitoring, then deleted.
  • Anthropic: does not train on API inputs or outputs by default. Same 30-day safety retention.
  • Google Gemini: same default for the paid API tier.

This is true whether you pay Missive for AI credits or bring your own API key (BYOK). BYOK also unlocks provider-side controls like OpenAI’s EU data residency for teams that need it. More detail in our AI overview docs.

Can senders see when I open their emails?

No. Missive blocks read trackers and 1x1 tracking pixels by default, so senders can’t tell whether you opened their message. You can even build rules on the “contains read trackers” condition, handy for auto-routing marketing email.

Where does Missive store my data?

Missive runs on Amazon Web Services (US East 1 region, Northern Virginia) for application hosting, with Crunchy Bridge for managed Postgres databases. Both are compliant with major security certifications and publish their security practices publicly.

If you need to allowlist our IP ranges on your mail server, AWS publishes the current list at https://ip-ranges.amazonaws.com/ip-ranges.json.

Is Missive SOC 2 compliant?

Yes. Missive has SOC 2 Type II compliance, audited by an independent third-party CPA based in California. Type II (as opposed to Type I) confirms that our security controls are both well-designed and consistently effective over time, not just a point-in-time snapshot.

The SOC 2 report is available on request. Email security@missiveapp.com to get a copy.

Is Missive GDPR compliant?

Yes. Missive is fully compliant with the EU’s General Data Protection Regulation. You can request a Data Processing Agreement and see the full list of subprocessors on our GDPR page.

Is Missive HIPAA compliant?

No. Missive is not HIPAA compliant and we don’t sign Business Associate Agreements (BAAs). If you work with Protected Health Information (PHI) and need a HIPAA-compliant email tool, Missive isn’t the right fit.

Is Missive PCI DSS compliant?

Missive itself doesn’t store or process payment card data. All payment processing for Missive subscriptions is handled by Stripe, which is certified as a PCI DSS Level 1 Service Provider. We don’t store or even relay card numbers through our infrastructure, so PCI scope sits with Stripe.

Does Missive support SSO and two-factor authentication?

Yes, both.

  • Two-factor authentication (2FA) is available on every plan, Free included. Set it up in Settings > Login & Security using any TOTP app (Authy, Google Authenticator, 1Password, etc.).
  • SAML SSO is available on the Business plan and works with any SAML 2.0 identity provider (Okta, Azure AD, Google Workspace, OneLogin, and so on).
  • SSO enforcement lets admins require every user in the org to authenticate through your IdP, which is how most compliance programs expect centralized access to work.

Will Missive still be around in a few years?

Almost certainly yes. Missive has been running since 2015, is fully bootstrapped (no VC funding), profitable, and independently owned by the original founding team. Over 5,000 teams use Missive daily, across logistics, legal, real estate, professional services, and more.

No investor whims, no forced-sale pressure. We move at the pace that makes the product better.

Do you sell or share user data?

We do not sell user data, to anyone, ever. That’s the hard line. We do share a limited set of operational data with a small number of subprocessors (things like our email delivery provider, payment processor, and error reporting service), and those are all listed publicly on the GDPR page.

Can I export my data?

Yes. Go to Settings > Login & Security and request an export. You get:

  • Conversations: every message (email, SMS, etc.), comment, assignment, and timestamp, in .json per organization.
  • Comments: every internal chat comment you have access to, in .csv per organization.
  • Contacts: every contact from every contact book you can access, in .csv per book.
  • Email addresses and phone numbers: every From/To/Cc field across messages you can access, in .csv.
  • Canned responses: in .html with attachments.
  • Rules: in .csv per organization.

Missive delivers the export as a conversation in your inbox when it’s ready.

How do I delete my account and all my data?

Heads up: this can’t be undone. The full steps are documented here, and the short version is:

  1. Go to Settings > Accounts, delete each connected account (email, SMS, etc.) via Delete account.
  2. Go to Settings > Calendars, delete each connected calendar.
  3. Go to Settings > Integrations, delete each integration (Asana, Todoist, etc.).
  4. Go to Settings > Organizations. If you own one, delete it. If you’re a member, an admin needs to remove you.
  5. Go to Settings > Login & Security (you may need to re-enter your password or confirm with Google or Apple).
  6. Scroll to Delete account and click Delete.
  7. Confirm in the popup.

You’ll be logged out immediately. Within 30 days, every trace of your Missive data and activity is permanently deleted from our database, cloud storage, backups, and logs. This process satisfies Article 17 of GDPR (the right to erasure).

If you just want to stop paying but keep access, go to Settings > Billing and switch to the Free plan instead.

Who do I contact with more questions?

Missive is the collaborative email client for teams that treat inbox hygiene as a team sport. Start a free account at missiveapp.com.

Related articles

Explore more
Tips & Templates

December 22, 2023

5 examples of bad customer service (and how to fix them)

Bad customer service costs companies customers and trust. Here are 5 clear examples of poor customer service, why they happen, and how to turn them around.

Read more
Productivity

March 17, 2025

What is the best email client for Outlook? Our top 6 picks

Looking for the best email client for Outlook? We compare the top 6 Outlook alternatives based on collaboration, AI features, security, and pricing. Find the best option for teams and individuals.

Read more
Tips & Templates

June 12, 2020

How to reduce your response time?

When dealing with customers, doing it fast is almost always better. People expect to receive a diligent and...

Read more
Tips & Templates

July 27, 2020

How to set up Facebook Messenger for Business?

For most companies, being able to connect with leads, customers or followers on social media is crucial,...

Read more
Productivity

March 6, 2020

How to receive emails in batches

Email batching saves focus time by scheduling when you check your inbox instead of reacting to every notification. Here’s how to set it up with alarms, add-ons, or rules.

Read more
Tips & Templates

December 5, 2023

Customer service values: what they are, why they matter, and how to build yours

Customer service values give your team a shared playbook for handling the situations that weren’t in the training manual. Here’s what good customer service values look like, how to build them, and real examples from brands that get it right.

Read more
Productivity

December 7, 2022

Inbox zero method: how to actually master it (without losing your mind)

Inbox zero is supposed to make you more productive, not a slave to your inbox. Here’s how the method actually works, why strict interpretations of it can backfire, and the practical techniques that hold up in 2026.

Read more
Shared Inbox

November 3, 2022

The 10 best shared inbox software for team collaboration

A shared inbox lets multiple coworkers handle emails at support@ or sales@ without stepping on each other. Here are the 10 best shared inbox tools in 2026, what each is best for, and how to run one well.

Read more
Productivity

July 24, 2025

7 Fyxer AI alternatives: from email clients to add-on tools

Compare 7 Fyxer AI alternatives for 2026, from Gmail-native add-ons like Gmelius and Hiver to team inboxes like Missive. Pricing verified April 2026.

Read more

We live in our inboxes.
Let’s make email enjoyable.

Try us out for free, invite a few people to get a feel, and upgrade when you’re ready.

4.8 → Over 1000 reviews
4.8
→ 1000+ reviews