Privacy Policy
What personal data Thelemail processes, why, and what rights you have. Written to be read, not skimmed.
Effective date: 11 June 2026
This policy explains what personal data Thelemail processes, why, and what rights you have. It is written to be read, not skimmed, and to match exactly what the service actually does. The technical companion to this policy is our threat model.
Data controller: Vladislav Gorokhov, Empresário em Nome Individual, NIF 315434546, Praça de Bocage 67, 2900-277 Setúbal, Portugal Contact: privacy@thel.email
1. The short version
- Your stored mail is encrypted with keys derived from your password. We cannot read your stored mail. We do not scan it, sell it, use it for advertising, or train AI on it.
- What we necessarily can see is the metadata email requires to function: sender and recipient addresses, timestamps, message sizes, and the content of messages in transit where encryption to the recipient is not possible (standard SMTP to external providers).
- We collect the minimum account and billing data needed to run a paid service, host everything in the EU (Hetzner, Germany and Finland), and use a small number of processors (Stripe, Hetzner) under data processing agreements.
2. What we process, why, and on what legal basis
2.1 Account data
Email address (your Thelemail address and any recovery/contact address you provide), display name (optional), hashed authentication material (SRP verifier; we never receive your password itself), encrypted private key material (which we cannot decrypt), 2FA credentials (TOTP secrets, WebAuthn public keys, hashed backup codes), session and device records (client type, creation time, IP address at login). Purpose: providing and securing your account. Legal basis: performance of contract (GDPR Art. 6(1)(b)); security logging under legitimate interest (Art. 6(1)(f)).
2.2 Mail content
Stored mail (messages, attachments) is encrypted to your key at rest; we hold only ciphertext we cannot decrypt.
Mail in transit is different, because email is an open federated system:
- Messages between Thelemail accounts are end-to-end encrypted; we never process their readable content.
- Inbound external messages arrive as plaintext over SMTP; our receiving server processes them in memory only for as long as needed to perform delivery functions (authentication checks, encrypting the message to your key), then stores only the encrypted form. Plaintext is not written to disk or logs.
- Outbound messages to external recipients without a compatible encryption key are transmitted as standard email (TLS in transit where the receiving server supports it). They necessarily exist in readable form during transmission.
Purpose: delivering your mail (the service itself). Legal basis: performance of contract (Art. 6(1)(b)).
2.3 Metadata
Like every email provider, we process message envelope metadata: sender and recipient addresses, timestamps, message sizes, authentication results (SPF/DKIM/DMARC), and delivery status. Some of this is retained in logs for deliverability, abuse prevention and troubleshooting. Purpose: routing mail, preventing abuse, maintaining sending reputation. Legal basis: performance of contract and legitimate interest (Arts. 6(1)(b), 6(1)(f)). Retention: operational mail logs are retained for 30 days and then deleted or anonymised.
2.4 Billing data
Plan, billing history, VAT country, and payment status. Card payments are processed by Stripe; we receive payment confirmations and limited payment metadata, never full card numbers. Purpose: charging for the service, accounting, tax compliance. Legal basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)). Invoicing records are retained for the period required by Portuguese tax law (currently 10 years).
2.5 Support and contact
If you email us or use the contact form, we process what you send us to respond. Legal basis: legitimate interest / pre-contractual steps (Arts. 6(1)(f), 6(1)(b)). Retained as long as needed to handle the matter and a reasonable period after.
2.6 Website analytics
Our public website uses privacy-respecting, self-hosted analytics without cross-site tracking, advertising identifiers, or sale of data. The application itself contains no third-party trackers.
3. What we do NOT do
- We do not read, scan, or analyse the content of your stored mail (we cannot).
- We do not sell or rent personal data to anyone.
- We do not use your mail or data for advertising or to train AI models.
- We do not embed advertising or third-party tracking in the product.
4. Processors and recipients
We share data only with processors necessary to run the service, under GDPR Art. 28 data processing agreements:
| Processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting (servers, storage) | Germany / Finland (EU) |
| Stripe | Card payment processing | EU entity; some processing may involve transfers safeguarded under Standard Contractual Clauses |
Beyond processors: we disclose data only where legally compelled by a valid order binding on us under Portuguese/EU law. Because stored mail is zero-access encrypted, the data we are technically capable of producing under compulsion is limited to the categories described in this policy (account data, metadata, billing), not the decrypted contents of your mailbox. We will publish transparency information about requests we receive where law permits.
5. International transfers
The service is hosted in the EU. Where a processor involves transfers outside the EEA (e.g. elements of payment processing), those transfers are safeguarded by adequacy decisions or Standard Contractual Clauses.
6. Retention
- Mail: retained in encrypted form until you delete it or your account is closed. Deleted messages are removed from active storage promptly and from backups on the backup rotation cycle of 30 days.
- Account data: retained while your account exists; deleted or anonymised within 30 days of account closure, except data we must keep (e.g. invoices) under legal obligations.
- Operational logs: see 2.3.
- Backups: encrypted, EU-hosted, rotated on a fixed cycle.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interest, and to withdraw consent where processing is based on consent. You can exercise most of these directly: your mail is exportable in standard formats from your account at any time, and account deletion can be requested at privacy@thel.email (processed within 30 days).
A note on erasure and zero-access: deleting your account removes your encrypted mail and account data. We cannot selectively decrypt or extract readable mail contents on your behalf without your credentials. Export before deletion.
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Portuguese CNPD (Comissão Nacional de Proteção de Dados); you may also complain to the authority of your own EU country.
8. Security
Security measures include: zero-access encryption of stored mail, SRP authentication (your password never reaches us), client-side key generation, two-factor authentication (TOTP, WebAuthn), encrypted backups, EU-only hosting, TLS in transit, internal access controls, and the plaintext-handling disciplines described in our threat model. No system is perfectly secure; our threat model describes honestly what is and is not protected.
9. Children
The service is not directed at children under 16, and we do not knowingly process their data. Family plan administrators are responsible for the mailboxes they create.
10. Changes to this policy
We will notify you of material changes by email or in-product notice before they take effect. The current version is always at thelemail.com/privacy.
11. Contact
Questions or rights requests: privacy@thel.email
Vladislav Gorokhov, Empresário em Nome Individual, Praça de Bocage 67, 2900-277 Setúbal, Portugal.
Last updated: 11 June 2026.