Last updated · September 8, 2026

Privacy Policy

Overview

SendReplay emails the recording of your Zoom webinars to the people who registered for them. This policy explains what data we handle, what we store, and how it is used.

What we access

With your authorization, we read your Zoom webinars, their registrant lists (names and email addresses), attendance reports, and cloud recording metadata including the share link and passcode. Access is granted through OAuth and can be revoked by you at any time. We never modify anything in your Zoom account.

If you enable a storage copy, we also write recording files into the Google Drive or Dropbox folder you connect.

What we store

We store your account details (name, email, password hash), encrypted OAuth tokens for the services you connect, your email templates and sending settings, and for each webinar a send log: the registrants' names and email addresses, whether they attended, and the delivery status of each email. This log exists so you can see who received the replay and so that unsubscribes and bounces are honoured on future sends.

Recording content is never stored on our servers. When a storage copy is enabled the file is streamed from Zoom to your own storage in small chunks.

Registrant data and email

Registrant email addresses are used only to send the replay email you configured, on your behalf. Every email carries an unsubscribe link; an address that unsubscribes, bounces, or reports the email as spam is added to your account's suppression list and is not emailed again from your account. We do not use registrant data for any other purpose and never share it with third parties beyond the email delivery provider below.

Third-party services

We communicate with the Zoom API to read the data described above, with Postmark (our email delivery provider, acting as a sub-processor) to send emails and receive delivery events, with Stripe for billing, and with the Google Drive and Dropbox APIs when you enable a storage copy. Your use of those services is governed by their own terms and privacy policies.

Retention and deletion

Disconnecting a service immediately revokes and deletes its stored tokens. Deleting your account removes your account details, connections, templates, send logs, and registrant records. Suppression entries are deleted with the account. To request deletion, email us from your account address.

Cookies

We use only essential cookies: a session cookie to keep you signed in and a CSRF token to protect forms. We do not use advertising or cross-site tracking cookies.

Contact

Questions about this policy or your data: hi@staticmaker.com.