website data.
The public website serves documentation, migration pages, and package links. It may receive normal hosting logs from Vercel such as request URL, IP-derived region, user agent, timestamp, and response status. We do not need account credentials or subscriber files to browse the site.
// migration runsmigration data.
The CLI and MCP server are built for local execution. A dry run should inspect your source provider and produce a report before any destination write. Do not paste API keys, subscriber exports, or provider credentials into public issues or chats.
When you run mailexodus locally, provider data is processed in your environment unless you explicitly wire a hosted service or destination workflow. The project aims to keep subscriber records, consent state, tags, segments, templates, and flow reports under your control.
// providersprovider credentials.
Provider API keys are used only for the providers you connect. Permission scopes should be read-only for dry runs. Destination write scopes should be added only after reviewing the report and approving a commit run.
Sender reputation, historical analytics, live automation state, and provider-native private assets are not portable and should be reviewed inside the original provider.
// contactcontact.
For privacy questions, open an issue in the public repository or use the contact channel listed by the project maintainers.