Last updated 27 August 2026

Privacy policy

This describes what we hold about your business and your mail, where it physically sits, who can reach it, and when it goes away. It is deliberately specific. A privacy policy you cannot check is not worth reading.

What this covers

This policy covers the email service operated by [REGISTERED ENTITY NAME], [REGISTERED OFFICE ADDRESS]. For the mail your staff send and receive, your business is the data fiduciary and we are the data processor acting on your instructions. For your billing and account records, we are the data fiduciary.

What we hold

  • Account details: the name, work email address and password hash of each person who signs in, the organisation name, and the role each person holds.
  • Domain and DNS details: the domains you add, the records we ask you to publish, and the results of our checks on them.
  • Mailbox contents: the messages, attachments, folders, drafts and contacts in each mailbox. This is your data. We hold it so we can deliver it.
  • Delivery records: for each message, the sender, the recipients, the size, the time and the result. We do not store the subject or the body in these records.
  • Billing records: the billing address and state, GSTIN if you give one, invoices, payments, refunds and credits. Card details are handled by our payment provider and never reach our servers.
  • Security records: sign-in attempts with the IP address, sessions, and an audit log of every administrative action, which stores identifiers and counts but never message content.
  • Support correspondence you send us.

We do not build advertising profiles, we do not scan mail for marketing, and we do not sell or share data with anyone for their own purposes.

Where it is held

  • The application, the mail servers and the database run on servers in the Asia Pacific (Mumbai) region, inside India.
  • Large attachments and exported archives are stored in Cloudflare R2 object storage. The buckets are private, have no public domain, and are reachable only through short-lived signed links our servers issue after checking who is asking.
  • Backups are encrypted with a separate key and held in the same region.
  • Payments are processed by Razorpay in India. Card details go to them directly from your browser.
  • Mail you send necessarily leaves our servers to reach the receiving provider your recipient uses, wherever that is. That is what sending email means.

Who can see it

No member of our staff has permission to read the contents of a customer mailbox. There is no administrative screen, report or command in the product that would show it, so this is not a promise about behaviour, it is a property of the system.

Support staff can see account, domain, mailbox and billing records in order to do their work, and every one of those actions is written to an audit log. When staff need to see your admin screens to reproduce a problem, they use an impersonation session that is limited, expires in 30 minutes, cannot take a payment or change a password, and notifies the organisation owner.

We will disclose data to a government authority only where we are legally required to, and we will tell you unless the law forbids it.

Companies that process data for us

  • Amazon Web Services, for the servers and the database, in the Mumbai region.
  • Cloudflare, for object storage of attachments and exports.
  • Razorpay, for taking payments and issuing refunds.
  • An email delivery provider for our own notification emails, such as invoices and password resets.

Each of these is bound by a contract that limits them to processing the data for us. The current list is kept here and updated when it changes.

How long we keep it

DataKept forThen
Mail in an active mailboxFor as long as the mailbox existsYou delete it, or the mailbox is deleted
Mail in a deleted mailbox30 daysPermanently deleted
Mail in a suspended account30 days, then 60 days archivedPermanently deleted
Delivery and connection logs30 daysDeleted
Sign-in attempts90 daysDeleted
Administrative audit log24 monthsDeleted
File download records12 monthsReduced to counts, then deleted
Invoices, payments, refunds7 yearsKept, because tax law requires it
Storage measurements used for billing7 yearsKept, for billing disputes
Temporary upload objects24 hoursDeleted automatically

Nothing is destroyed on the day a subscription lapses. Every stage of winding an account down is emailed to the owner first, and an export is available throughout.

Deleting your data

You can delete a message, a mailbox, a domain or the whole organisation from the admin screens. Deleting a mailbox removes it from service at once and permanently destroys its mail 30 days later, which is the window that lets us undo an accidental deletion. Deletion at the end of that window is real removal from the database and from object storage, including from backups as they age out of their own cycle.

Billing records are the one thing we cannot delete on request. Indian tax law requires us to keep invoices, payments and refunds for seven years.

Cookies and browser storage

We set one cookie, the session cookie that keeps you signed in. It holds a random token, is marked HttpOnly, Secure and SameSite=Lax, and expires after eight hours of inactivity or thirty days, whichever comes first. Your light or dark theme choice is kept in your browser and never sent to us. There are no advertising cookies, no third-party analytics and no tracking pixels on our own pages.

Remote images in the mail you receive are blocked until you ask for them, because loading one tells the sender you opened the message. When you do ask, we fetch it through our servers so your IP address is not handed to the sender.

Your rights

Under the Digital Personal Data Protection Act, 2023 you can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it where we are not required to keep it, and complain about how we have handled it. Write to [PRIVACY EMAIL] and we will reply within 30 days.

If you are an employee of a customer, your mail belongs to your employer's account. Ask your organisation administrator first, because we can only act on their instructions for it.

Our grievance officer is [GRIEVANCE OFFICER NAME], [GRIEVANCE EMAIL], [PHONE]. If we have not resolved a complaint, you can escalate it to the Data Protection Board of India.

Security

The specific controls, including how tenants are kept apart, how secrets are encrypted and how to report a vulnerability, are on the security page. If a breach affects your data we will tell you and the Board as the law requires, with what we know, what we have done and what you should do.

Changes to this policy

We will email account owners before a change that materially affects what we hold or how long we hold it. Smaller corrections are published here with a new date at the top.