Home / Privacy

Privacy Policy

What personal data Thelemail processes, why, and what rights you have. Written in plain language.

Effective date: 31 August 2026

This policy explains what personal data Thelemail processes, why, and what rights you have. It uses plain language and matches what the service actually does. The technical companion to this policy is our threat model.

Data controller: Thelemail, Praça de Bocage 67, 2900-277 Setúbal, Portugal Contact: [email protected]

1. The short version

  • Your stored mail is encrypted to account keys that your device unlocks through OPAQUE. We cannot read your stored mail. We do not scan it, sell it, use it for advertising, or train AI on it.
  • What we necessarily can see is the metadata email requires to function: sender and recipient addresses, timestamps, message sizes, external-message subject lines, and the content of messages in transit where end-to-end encryption to the recipient is not possible (standard SMTP to external providers).
  • We collect the minimum account and billing data needed to run a paid service. Core mail processing and encrypted mailbox storage run on Hetzner infrastructure in the EU. Cloudflare delivers the public website, Stripe processes web payments, Google provides Android push delivery and Google Play billing, and Apple provides iOS push delivery and App Store billing. These providers do not receive readable stored-mail content.

2. What we process, why, and on what legal basis

2.1 Account data

Email address (your Thelemail address and any recovery/contact address you provide), display name (optional), password-authentication material (an OPAQUE registration record; we never receive or store your password itself), encrypted private key material (which we cannot decrypt), 2FA credentials (TOTP secrets, WebAuthn public keys, hashed backup codes), session and device records (client type, creation time, IP address at login), and mobile push-registration tokens. Purpose: providing and securing your account. Legal basis: performance of contract (GDPR Art. 6(1)(b)); security logging under legitimate interest (Art. 6(1)(f)).

2.2 Mail content

Stored mail (messages, attachments) is encrypted to your key at rest; we hold only ciphertext we cannot decrypt.

Mail in transit is different, because email is an open federated system:

  • Messages between Thelemail accounts are end-to-end encrypted; we never process their readable content.
  • Inbound external messages that are already OpenPGP-encrypted to the recipient remain ciphertext through delivery. Other external messages arrive in readable form over SMTP; our receiving server processes them in memory only for as long as needed to perform authentication checks, spam classification and encryption to the recipient, then stores only the encrypted form. Readable message content is not written to disk or logs.
  • Outbound messages to external recipients are end-to-end encrypted when a compatible OpenPGP key is available through WKD. Otherwise they are transmitted as standard email (TLS in transit where the receiving server supports it) and necessarily exist in readable form during transmission.

Purpose: delivering your mail (the service itself). Legal basis: performance of contract (Art. 6(1)(b)).

2.3 Metadata

Like every email provider, we process message envelope metadata: sender and recipient addresses, timestamps, message sizes, authentication results (SPF/DKIM/DMARC), and delivery status. Subject lines of external messages are also visible to the service and treated as metadata. Some of this is retained in logs for deliverability, abuse prevention and troubleshooting. Purpose: routing mail, preventing abuse, maintaining sending reputation. Legal basis: performance of contract and legitimate interest (Arts. 6(1)(b), 6(1)(f)). Retention: operational mail logs are retained for 30 days and then deleted or anonymised.

2.4 Billing data

Plan, billing history, VAT country, and payment status. Web card payments are processed by Stripe; we receive payment confirmations and limited payment metadata, never full card numbers. Mobile subscriptions are processed by Google Play or the Apple App Store. Those stores process the payment method and purchase under their own privacy terms; we receive the purchase or subscription entitlement and limited transaction records needed to activate service, prevent fraud, and handle support. Purpose: charging for the service, accounting, tax compliance. Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). Invoicing records are retained for the period required by Portuguese tax law (currently 10 years).

2.5 Support and contact

If you email us, we process what you send us to respond. Legal basis: legitimate interest / pre-contractual steps (Arts. 6(1)(f), 6(1)(b)). Retained as long as needed to handle the matter and a reasonable period after.

2.6 Website analytics

Our public website uses privacy-respecting, self-hosted analytics without cross-site tracking, advertising identifiers, or sale of data. The application itself contains no third-party trackers.

2.7 Mobile push notifications

If you enable notifications, the mobile app obtains an app-specific routing token from Firebase Cloud Messaging (Google) on Android or Apple Push Notification service on iOS and registers it with Thelemail. Google or Apple receives that routing token and the notification payload needed to deliver the notification. Thelemail push payloads do not contain readable stored-mail content: message previews are encrypted to a device-held preview key, and other pushes contain only routing or event identifiers. Purpose: delivering requested account and mail notifications. Legal basis: performance of contract (Art. 6(1)(b)). You can disable notifications in the operating-system settings.

3. What we do NOT do

  • We do not read, scan, or analyse the content of your stored mail (we cannot).
  • We do not sell or rent personal data to anyone.
  • We do not use your mail or data for advertising or to train AI models.
  • We do not embed advertising or third-party tracking in the product.

4. Processors and recipients

We use the following service providers to operate Thelemail. Hosting and infrastructure providers act as processors under GDPR Art. 28 agreements. Apple and Google may act as independent controllers for their app-store transaction services under their own customer terms and privacy notices.

ProviderRoleLocation
Hetzner Online GmbHCore compute, encrypted object storage and backupsEuropean Union
CloudflarePublic website hosting and delivery, authoritative DNS, and proxy or security services where enabledGlobal network; transfers safeguarded under its DPA and Standard Contractual Clauses where applicable
StripeWeb card payment processingEU entity; some processing may involve transfers safeguarded under Standard Contractual Clauses
GoogleFirebase Cloud Messaging routing tokens and encrypted or content-free push delivery; Google Play subscription billing on AndroidGlobal service; transfers governed by Google’s applicable data-protection terms and safeguards
AppleApple Push Notification service routing tokens and encrypted or content-free push delivery; App Store subscription billing on iOSGlobal service; transfers governed by Apple’s applicable privacy terms and safeguards

Beyond processors: we disclose data only where legally compelled by a valid order binding on us under Portuguese/EU law. Because stored mail is zero-access encrypted, the data we are technically capable of producing under compulsion is limited to the categories described in this policy: account data, metadata, and billing data. Decrypted mailbox contents remain unavailable to us. We will publish transparency information about requests we receive where law permits.

5. International transfers

Core mail processing and encrypted mailbox storage are hosted in the EU. The public website is delivered through Cloudflare’s global network, and mobile push and app-store services use Google or Apple infrastructure. Where a service provider involves transfers outside the EEA, those transfers are handled under the provider’s applicable transfer safeguards, such as adequacy decisions or Standard Contractual Clauses.

6. Retention

  • Mail: retained in encrypted form until you delete it or your account is closed. Deleted messages are removed from active storage promptly and from backups on the backup rotation cycle of 30 days.
  • Account data: retained while your account exists; deleted or anonymised within 30 days of account closure, except data we must keep (e.g. invoices) under legal obligations.
  • Operational logs: see 2.3.
  • Backups: encrypted, EU-hosted, rotated on a fixed cycle.

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interest, and to withdraw consent where processing is based on consent. You can exercise most of these directly: your mail is exportable in standard formats at any time with our open-source export tool, and account deletion can be requested at [email protected] (processed within 30 days).

A note on erasure and zero-access: deleting your account removes your encrypted mail and account data. We cannot selectively decrypt or extract readable mail contents on your behalf without your credentials. Export before deletion, using the export tool.

You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Portuguese CNPD (Comissão Nacional de Proteção de Dados); you may also complain to the authority of your own EU country.

8. Security

Security measures include: zero-access encryption of stored mail, OPAQUE password-authenticated key exchange (your password never reaches us), client-side key generation, two-factor authentication (TOTP, WebAuthn), encrypted backups, EU-hosted core mail infrastructure and encrypted mailbox storage, TLS in transit, internal access controls, and the plaintext-handling disciplines described in our threat model. No system is perfectly secure; our threat model describes honestly what is and is not protected.

9. Children

The service is not directed at children under 16, and we do not knowingly process their data. Family plan administrators are responsible for the mailboxes they create.

10. Changes to this policy

We will notify you of material changes by email or in-product notice before they take effect. The current version is always at thelemail.com/privacy.

11. Contact

Questions or rights requests: [email protected]

Thelemail, Praça de Bocage 67, 2900-277 Setúbal, Portugal.


Last updated: 31 August 2026.