Emvali
Privacy Policy
Last updated: 6 October 2026
Emvali is an email validation API operated by Ryno Brits, based in South Africa. This policy says what personal information the service processes, why, and how to ask for access or deletion. Questions go to support@emvali.com .
Account data we store
When you create an account, the database on Railway stores:
- Your account email address.
- Your password as a scrypt hash. The password itself is not stored.
- API keys as SHA-256 hashes. A short prefix and a label are stored so a key can be told apart from another. The full key is shown once and is not stored.
- The account plan, and when the account and keys were created or revoked.
- A monthly count of validations for that account.
Addresses submitted for validation
When you send an address to the API, Emvali processes it to run the checks: syntax, MX and DNS, disposable, role, and free-provider signals, and a risk score. The result is returned on that request. The address is not written to the account database and is not kept as a list of addresses you have checked. What is stored for the account is the usage count for the month.
A mail-server (MX) lookup for a domain may be cached for a few minutes. That cache holds the domain’s mail servers, not the full address you submitted.
Rate limits and abuse prevention
Signup and login are rate limited using the IP address of the request. Login is also rate limited with a short hash of the email, not the email itself. Validation calls are rate limited per API key. These are counters. They expire with the limit window, which is seconds, a minute, or an hour. The counters live in memory on the API, or in Redis when that cache is configured. They are not an account profile, and they are not a stored history of the addresses you validated.
Logs and hosting
The website and the API are hosted on Railway. Request logs may include an IP address and the request path. Application logs redact passwords and API key credentials. Emvali does not add a separate archive of validation addresses.
Payments
Paddle.com is the Merchant of Record for orders. Paddle handles checkout, billing, invoicing, and sales tax or VAT. Emvali does not store card numbers or card details. Paddle’s privacy notice describes how Paddle handles payment data: paddle.com/legal/privacy.
Cookies
These website pages do not set advertising or analytics cookies. The account form sends your email and password to the API over HTTPS to create an account or to log in. It does not set a tracking cookie.
Why we process this information
We process it to create and secure your account, to run validation requests, to count monthly usage against the plan, and to limit abuse of signup, login, and the API.
Your rights
You can ask for a copy of the account data we hold, ask us to correct it, or ask us to delete it. Email support@emvali.com . Deletion removes the account email, the password hash, the API key hashes, and the usage counts held for that account in the Emvali database.
This policy is written so those requests can be handled in line with the Protection of Personal Information Act (POPIA) in South Africa, and with the GDPR where the GDPR applies to you. Where you have the right, you can also complain to the Information Regulator in South Africa, or to a data protection authority in your country.
Where data is handled
Ryno Brits is based in South Africa. The service is hosted on Railway, which may process data outside South Africa. Payment data is handled by Paddle.
Changes
If this policy changes, the date at the top of this page will change.