Sovereign Mail
PricingSupportOpen app

PRIVACY

Your mail stays in infrastructure you control.

This notice explains the separate data boundaries for the public website, a customer-owned Sovereign Mail deployment, and optional paid services.

Effective August 18, 2026
Last updated August 18, 2026

Customer-owned application data

Sovereign Mail is deployed to Cloudflare resources controlled by the workspace owner. Mail copies, attachments, account records, provider connection records, and Cloudflare credentials stay in that customer deployment. The public website does not receive them. Provider passwords are encrypted in the customer deployment and mail content is not written to application logs.

Existing mail providers

When a workspace connects an IMAP and SMTP account, that provider continues to receive and send the original mail. Its own privacy terms still apply. Sovereign Mail stores the synchronized copy in the customer-owned Cloudflare account.

Website, billing, and support data

The public website host may process ordinary request information such as IP address, browser, requested page, timestamp, and security events. If you buy managed service, Stripe processes payment and billing details under its own privacy terms. Sovereign Mail keeps the Stripe customer, subscription, product, price, status, and event identifiers needed to provide the service; it does not store full card details.

If you contact support, provide only the minimum information needed. Do not send passwords, Cloudflare tokens, private keys, raw mail, or message bodies. Support records may include contact details, diagnostics you deliberately provide, and the response history.

Use, retention, and disclosure

Information is used to operate the site, prevent abuse, fulfill paid service, answer support requests, and meet legal obligations. Billing and support records are kept only as long as needed for those purposes, accounting, disputes, and security. Information is disclosed to infrastructure and payment providers only as needed, or when legally required. Sovereign Mail does not sell personal information.

Your choices

Members can delete their personal account from Settings → Account. Owners must transfer ownership or remove the customer deployment. See Account deletion for the exact scope. For a privacy request, open a private support request through Support.

The public AGPL source is available without an account or subscription. Review it at GitHub.
© Sovereign Mail
TermsRefundsSupportSource