Privacy Policy
Last updated 26 September 2026Effective 26 September 2026
In short: we collect what we need to run your mailbox and keep it secure. We don't show ads, sell your data or use third-party analytics. You can delete your account at any time.
Who we are
Viremail is provided by Svayam Incarnation Limited, United Kingdom (company number [Company number (to be added)], registered office [Registered office address (to be added)]). For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the controller of the personal data described in this policy.
ICO registration number: [ICO registration number (to be added)]. Data protection contact: [Data protection contact (to be confirmed)], or contact us via the contact details on our website.
If an organisation (such as your employer) provides your Viremail account, that organisation may be the controller of your mailbox data and we act as its processor. See our Data Processing Addendum.
The data we collect
Information you give us
- Account data: your name, email address and password. Your password is stored only as a one-way hash by our mail server.
- Recovery email (optional): stored on our mail server and used only to help you recover your account and send security notices.
- Profile (optional): profile photo, bio, job title, company, location and website.
- Your content: email messages and attachments, contacts, calendars, tasks and notes, and chat messages you send to other Viremail users.
- Support messages: anything you tell us when you contact us.
Information created when you use the service
- Session data: while you are signed in, your mailbox password is held in your server-side session, encrypted with AES-GCM, so we can open your mailbox for you. It is deleted when you sign out or the session expires.
- Security logs: the time of each sign-in attempt, IP address, device and browser type, and whether it succeeded.
- Country: we may derive your approximate country from your IP address (via a header added by our network provider, Cloudflare). We use this for security and for aggregate statistics on our own internal dashboard (for example, number of people online, countries and device types). We do not use third-party analytics.
- Sign-in security: if you turn them on: your two-step verification secret (stored encrypted), one-way hashes of your backup codes, the public keys of your passkeys, and tokens for devices you choose to trust.
- Encryption keys: if you turn on end-to-end encryption, your OpenPGP public key and your private key, which is encrypted in your browser with your password before it reaches us. We cannot read it.
- Message metadata: sender, recipients, subject line, dates and sizes, which mail servers need to deliver and store mail. This is visible to us even for end-to-end encrypted messages.
- Call data: when you make audio or video calls, connection details (such as IP addresses) needed to set up the call. Calls are not recorded.
How we use your data and our lawful bases
We only use personal data where we have a lawful basis under UK GDPR.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and run your account; store, send and receive your mail, calendar, contacts, notes, tasks and chats | Account data, your content, session data | Contract (Art. 6(1)(b)) |
| Set up audio and video calls between users | Account data, call connection data | Contract |
| Keep accounts secure: sign-in protection, two-step verification, passkeys, detecting suspicious sign-ins, showing you your sign-in history | Security logs, sign-in security data, country | Legitimate interests (Art. 6(1)(f)) in protecting you and the service; contract |
| Filter spam, phishing and malware | Your content, message metadata | Legitimate interests; contract |
| Account recovery and security notices | Recovery email, account data | Contract; legitimate interests |
| Check new passwords against known breaches | Partial hash of new password | Legitimate interests in preventing account takeover |
| Aggregate usage statistics on our internal dashboard | Country, device type, session counts | Legitimate interests in running and planning the service |
| Respond to support requests | Support messages, account data | Contract; legitimate interests |
| Enforce our terms and prevent abuse | Account data, security logs, message metadata | Legitimate interests |
| Comply with the law and valid legal requests | Any data we hold, as required | Legal obligation (Art. 6(1)(c)) |
| Optional profile features | Profile photo and fields | Consent (Art. 6(1)(a)). You can remove them at any time |
Where we rely on legitimate interests, we have balanced them against your rights. You can object: see Your rights.
What we don't do
- We do not show ads, and we do not sell or rent your personal data.
- We do not use Google Analytics, advertising networks or third-party tracking.
- We do not scan your mail to build advertising profiles.
- External images in emails are blocked by default, to stop senders tracking when you open messages.
- We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
Who we share data with
Your mail and account data are stored on our own mail servers. We share limited data only with:
| Recipient | What is shared | Why |
|---|---|---|
| People you communicate with | Messages, chats, calls and your name/profile as you choose | To deliver the service |
| Other mail providers | Messages you send, and their metadata | Email delivery to recipients outside our service |
| Cloudflare (network and security provider) | Connection data such as IP address, passing through its network | Protecting and delivering the website |
| Have I Been Pwned | The first 5 characters of a SHA-1 hash of a new password (k-anonymity) | Warning you about breached passwords |
| TURN relay server | Encrypted call media, when a direct connection is not possible | Connecting calls |
| Courts, police and regulators | Only what is legally required | See our law enforcement policy |
| A buyer or successor | Data needed to continue the service | If our business is sold or reorganised; we will tell you first |
We may use a search-engine verification meta tag (for example, Google Search Console). This is a line of text in our web page and does not track you.
International transfers
Your data is hosted on our own servers. Where the third parties listed above process data outside the UK, transfers rely on appropriate safeguards, such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. Contact us for more details. Server location: [Hosting location (to be confirmed)].
How long we keep data
| Data | Kept for |
|---|---|
| Mail, contacts, calendars, tasks, notes | Until you delete them or delete your account |
| Chat messages | Until deleted, or your account is deleted |
| Session (including encrypted password) | Until you sign out, or the session expires (up to 30 days of inactivity if you choose to stay signed in) |
| Sign-in security logs | 90 days |
| Password reset codes | 15 minutes |
| Two-step verification data, passkeys, trusted devices | Until you remove them or delete your account |
| Aggregate statistics | Kept only in aggregated form that does not identify you |
| Backups | [Backup retention period (to be added)] |
See the full Data Retention Policy.
Your rights
Under UK data protection law you have the right to:
- Access a copy of your personal data.
- Rectify inaccurate data. You can edit most of it in Settings.
- Erase your data. Delete your account in Settings → Account.
- Restrict or object to our processing, including processing based on legitimate interests.
- Data portability: download your mail with any IMAP client or via "Show original", or ask us for an export.
- Withdraw consent at any time, where we rely on consent.
To make a request, contact us via the contact details on our website. We will respond within one month, and may need to confirm your identity first. There is normally no charge.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to deal with your concerns first.
Security
We use encryption in transit (TLS), encrypted storage of sensitive secrets, two-step verification, passkeys and optional end-to-end encryption. No system is perfectly secure; see our Security Overview.
Children
Viremail is not intended for children under 13 and we do not knowingly allow them to create accounts. See our Children's Privacy policy.
Changes to this policy
We may update this policy. If changes are significant, we will tell you by email or in the app before they take effect.
Contact us
For any privacy question, contact us via the contact details on our website.