Privacy Policy
DRAFT TEMPLATE — This policy must be reviewed by qualified legal counsel before production use. The operator’s legal name, jurisdiction, contact details, subprocessors, and applicable rights must be completed before launch.
We collect account names, contact email addresses, service addresses, password hashes, preferences, and support requests to provide the service. Mail storage includes sender and recipient metadata, message contents, and attachments. We do not store recoverable plaintext passwords.
We log security-relevant IP addresses, browser and device information, session activity, authentication attempts, and major security events. These records help us prevent unauthorized access, investigate abuse, and maintain reliability. The default security IP retention target is 90 days; operational retention settings and backup schedules must be verified by the operator.
Authorized gayest.email personnel may access mailbox contents when reasonably necessary to maintain the service, investigate spam, phishing, abuse or security incidents, respond to support requests, enforce policies, or comply with valid legal requirements. This service is not end-to-end encrypted. Staff message access requires an authorized role and a stated reason, and creates an append-only audit entry.
We use essential HttpOnly session cookies to sign you in. Theme preferences may be stored in your browser. Infrastructure providers process information necessary to operate hosting and mail delivery. The operator must publish a current list of subprocessors and transfer safeguards before launch.
You can export basic account data, manage addresses, revoke sessions, block senders, and request account deletion. Deletion immediately disables access and enters a 30-day review period. Legal holds, abuse evidence, audit records, and backups may require different retention periods. Contact support to cancel or ask about a deletion request.
Security includes password hashing, restricted administration, origin checks, and session expiration. Production operators must configure transport encryption, encrypted backups, access controls, retention jobs, and incident response. No system can promise absolute security.
We disclose information to service providers only as needed and may respond to valid legal process. Contact privacy@gayest.email for privacy questions once the operator activates that address. Applicable legal rights and complaint channels depend on jurisdiction and must be completed before launch.
Open your inbox