Last updated 27 August 2026
Privacy policy
This describes what we hold about your business and your mail, where it physically sits, who can reach it, and when it goes away. It is deliberately specific. A privacy policy you cannot check is not worth reading.
What this covers
This policy covers the email service operated by [REGISTERED ENTITY NAME], [REGISTERED OFFICE ADDRESS]. For the mail your staff send and receive, your business is the data fiduciary and we are the data processor acting on your instructions. For your billing and account records, we are the data fiduciary.
What we hold
- Account details: the name, work email address and password hash of each person who signs in, the organisation name, and the role each person holds.
- Domain and DNS details: the domains you add, the records we ask you to publish, and the results of our checks on them.
- Mailbox contents: the messages, attachments, folders, drafts and contacts in each mailbox. This is your data. We hold it so we can deliver it.
- Delivery records: for each message, the sender, the recipients, the size, the time and the result. We do not store the subject or the body in these records.
- Billing records: the billing address and state, GSTIN if you give one, invoices, payments, refunds and credits. Card details are handled by our payment provider and never reach our servers.
- Security records: sign-in attempts with the IP address, sessions, and an audit log of every administrative action, which stores identifiers and counts but never message content.
- Support correspondence you send us.
We do not build advertising profiles, we do not scan mail for marketing, and we do not sell or share data with anyone for their own purposes.
Where it is held
- The application, the mail servers and the database run on servers in the Asia Pacific (Mumbai) region, inside India.
- Large attachments and exported archives are stored in Cloudflare R2 object storage. The buckets are private, have no public domain, and are reachable only through short-lived signed links our servers issue after checking who is asking.
- Backups are encrypted with a separate key and held in the same region.
- Payments are processed by Razorpay in India. Card details go to them directly from your browser.
- Mail you send necessarily leaves our servers to reach the receiving provider your recipient uses, wherever that is. That is what sending email means.
Who can see it
No member of our staff has permission to read the contents of a customer mailbox. There is no administrative screen, report or command in the product that would show it, so this is not a promise about behaviour, it is a property of the system.
Support staff can see account, domain, mailbox and billing records in order to do their work, and every one of those actions is written to an audit log. When staff need to see your admin screens to reproduce a problem, they use an impersonation session that is limited, expires in 30 minutes, cannot take a payment or change a password, and notifies the organisation owner.
We will disclose data to a government authority only where we are legally required to, and we will tell you unless the law forbids it.
Companies that process data for us
- Amazon Web Services, for the servers and the database, in the Mumbai region.
- Cloudflare, for object storage of attachments and exports.
- Razorpay, for taking payments and issuing refunds.
- An email delivery provider for our own notification emails, such as invoices and password resets.
Each of these is bound by a contract that limits them to processing the data for us. The current list is kept here and updated when it changes.
How long we keep it
| Data | Kept for | Then |
|---|---|---|
| Mail in an active mailbox | For as long as the mailbox exists | You delete it, or the mailbox is deleted |
| Mail in a deleted mailbox | 30 days | Permanently deleted |
| Mail in a suspended account | 30 days, then 60 days archived | Permanently deleted |
| Delivery and connection logs | 30 days | Deleted |
| Sign-in attempts | 90 days | Deleted |
| Administrative audit log | 24 months | Deleted |
| File download records | 12 months | Reduced to counts, then deleted |
| Invoices, payments, refunds | 7 years | Kept, because tax law requires it |
| Storage measurements used for billing | 7 years | Kept, for billing disputes |
| Temporary upload objects | 24 hours | Deleted automatically |
Nothing is destroyed on the day a subscription lapses. Every stage of winding an account down is emailed to the owner first, and an export is available throughout.
Deleting your data
You can delete a message, a mailbox, a domain or the whole organisation from the admin screens. Deleting a mailbox removes it from service at once and permanently destroys its mail 30 days later, which is the window that lets us undo an accidental deletion. Deletion at the end of that window is real removal from the database and from object storage, including from backups as they age out of their own cycle.
Billing records are the one thing we cannot delete on request. Indian tax law requires us to keep invoices, payments and refunds for seven years.
Cookies and browser storage
We set one cookie, the session cookie that keeps you signed in. It holds a random token, is marked HttpOnly, Secure and SameSite=Lax, and expires after eight hours of inactivity or thirty days, whichever comes first. Your light or dark theme choice is kept in your browser and never sent to us. There are no advertising cookies, no third-party analytics and no tracking pixels on our own pages.
Remote images in the mail you receive are blocked until you ask for them, because loading one tells the sender you opened the message. When you do ask, we fetch it through our servers so your IP address is not handed to the sender.
Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it where we are not required to keep it, and complain about how we have handled it. Write to [PRIVACY EMAIL] and we will reply within 30 days.
If you are an employee of a customer, your mail belongs to your employer's account. Ask your organisation administrator first, because we can only act on their instructions for it.
Our grievance officer is [GRIEVANCE OFFICER NAME], [GRIEVANCE EMAIL], [PHONE]. If we have not resolved a complaint, you can escalate it to the Data Protection Board of India.
Security
The specific controls, including how tenants are kept apart, how secrets are encrypted and how to report a vulnerability, are on the security page. If a breach affects your data we will tell you and the Board as the law requires, with what we know, what we have done and what you should do.
Changes to this policy
We will email account owners before a change that materially affects what we hold or how long we hold it. Smaller corrections are published here with a new date at the top.