viremail

Privacy Policy

Last updated 26 September 2026Effective 26 September 2026

In short: we collect what we need to run your mailbox and keep it secure. We don't show ads, sell your data or use third-party analytics. You can delete your account at any time.

On this page
  1. Who we are
  2. The data we collect
  3. How we use your data and our lawful bases
  4. Who we share data with
  5. International transfers
  6. How long we keep data
  7. Your rights
  8. Security
  9. Children
  10. Changes to this policy
  11. Contact us

Who we are

Viremail is provided by Svayam Incarnation Limited, United Kingdom (company number [Company number (to be added)], registered office [Registered office address (to be added)]). For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the controller of the personal data described in this policy.

ICO registration number: [ICO registration number (to be added)]. Data protection contact: [Data protection contact (to be confirmed)], or contact us via the contact details on our website.

If an organisation (such as your employer) provides your Viremail account, that organisation may be the controller of your mailbox data and we act as its processor. See our Data Processing Addendum.

The data we collect

Information you give us

  • Account data: your name, email address and password. Your password is stored only as a one-way hash by our mail server.
  • Recovery email (optional): stored on our mail server and used only to help you recover your account and send security notices.
  • Profile (optional): profile photo, bio, job title, company, location and website.
  • Your content: email messages and attachments, contacts, calendars, tasks and notes, and chat messages you send to other Viremail users.
  • Support messages: anything you tell us when you contact us.

Information created when you use the service

  • Session data: while you are signed in, your mailbox password is held in your server-side session, encrypted with AES-GCM, so we can open your mailbox for you. It is deleted when you sign out or the session expires.
  • Security logs: the time of each sign-in attempt, IP address, device and browser type, and whether it succeeded.
  • Country: we may derive your approximate country from your IP address (via a header added by our network provider, Cloudflare). We use this for security and for aggregate statistics on our own internal dashboard (for example, number of people online, countries and device types). We do not use third-party analytics.
  • Sign-in security: if you turn them on: your two-step verification secret (stored encrypted), one-way hashes of your backup codes, the public keys of your passkeys, and tokens for devices you choose to trust.
  • Encryption keys: if you turn on end-to-end encryption, your OpenPGP public key and your private key, which is encrypted in your browser with your password before it reaches us. We cannot read it.
  • Message metadata: sender, recipients, subject line, dates and sizes, which mail servers need to deliver and store mail. This is visible to us even for end-to-end encrypted messages.
  • Call data: when you make audio or video calls, connection details (such as IP addresses) needed to set up the call. Calls are not recorded.

How we use your data and our lawful bases

We only use personal data where we have a lawful basis under UK GDPR.

PurposeData usedLawful basis
Create and run your account; store, send and receive your mail, calendar, contacts, notes, tasks and chatsAccount data, your content, session dataContract (Art. 6(1)(b))
Set up audio and video calls between usersAccount data, call connection dataContract
Keep accounts secure: sign-in protection, two-step verification, passkeys, detecting suspicious sign-ins, showing you your sign-in historySecurity logs, sign-in security data, countryLegitimate interests (Art. 6(1)(f)) in protecting you and the service; contract
Filter spam, phishing and malwareYour content, message metadataLegitimate interests; contract
Account recovery and security noticesRecovery email, account dataContract; legitimate interests
Check new passwords against known breachesPartial hash of new passwordLegitimate interests in preventing account takeover
Aggregate usage statistics on our internal dashboardCountry, device type, session countsLegitimate interests in running and planning the service
Respond to support requestsSupport messages, account dataContract; legitimate interests
Enforce our terms and prevent abuseAccount data, security logs, message metadataLegitimate interests
Comply with the law and valid legal requestsAny data we hold, as requiredLegal obligation (Art. 6(1)(c))
Optional profile featuresProfile photo and fieldsConsent (Art. 6(1)(a)). You can remove them at any time

Where we rely on legitimate interests, we have balanced them against your rights. You can object: see Your rights.

What we don't do

  • We do not show ads, and we do not sell or rent your personal data.
  • We do not use Google Analytics, advertising networks or third-party tracking.
  • We do not scan your mail to build advertising profiles.
  • External images in emails are blocked by default, to stop senders tracking when you open messages.
  • We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Who we share data with

Your mail and account data are stored on our own mail servers. We share limited data only with:

RecipientWhat is sharedWhy
People you communicate withMessages, chats, calls and your name/profile as you chooseTo deliver the service
Other mail providersMessages you send, and their metadataEmail delivery to recipients outside our service
Cloudflare (network and security provider)Connection data such as IP address, passing through its networkProtecting and delivering the website
Have I Been PwnedThe first 5 characters of a SHA-1 hash of a new password (k-anonymity)Warning you about breached passwords
TURN relay serverEncrypted call media, when a direct connection is not possibleConnecting calls
Courts, police and regulatorsOnly what is legally requiredSee our law enforcement policy
A buyer or successorData needed to continue the serviceIf our business is sold or reorganised; we will tell you first

We may use a search-engine verification meta tag (for example, Google Search Console). This is a line of text in our web page and does not track you.

International transfers

Your data is hosted on our own servers. Where the third parties listed above process data outside the UK, transfers rely on appropriate safeguards, such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. Contact us for more details. Server location: [Hosting location (to be confirmed)].

How long we keep data

DataKept for
Mail, contacts, calendars, tasks, notesUntil you delete them or delete your account
Chat messagesUntil deleted, or your account is deleted
Session (including encrypted password)Until you sign out, or the session expires (up to 30 days of inactivity if you choose to stay signed in)
Sign-in security logs90 days
Password reset codes15 minutes
Two-step verification data, passkeys, trusted devicesUntil you remove them or delete your account
Aggregate statisticsKept only in aggregated form that does not identify you
Backups[Backup retention period (to be added)]

See the full Data Retention Policy.

Your rights

Under UK data protection law you have the right to:

  • Access a copy of your personal data.
  • Rectify inaccurate data. You can edit most of it in Settings.
  • Erase your data. Delete your account in Settings → Account.
  • Restrict or object to our processing, including processing based on legitimate interests.
  • Data portability: download your mail with any IMAP client or via "Show original", or ask us for an export.
  • Withdraw consent at any time, where we rely on consent.

To make a request, contact us via the contact details on our website. We will respond within one month, and may need to confirm your identity first. There is normally no charge.

You also have the right to complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to deal with your concerns first.

Security

We use encryption in transit (TLS), encrypted storage of sensitive secrets, two-step verification, passkeys and optional end-to-end encryption. No system is perfectly secure; see our Security Overview.

Children

Viremail is not intended for children under 13 and we do not knowingly allow them to create accounts. See our Children's Privacy policy.

Changes to this policy

We may update this policy. If changes are significant, we will tell you by email or in the app before they take effect.

Contact us

For any privacy question, contact us via the contact details on our website.


All policiesTerms of ServicePrivacy PolicyCookie & Storage PolicyAcceptable Use PolicyAnti-Spam PolicySecurity & Responsible DisclosureEnd-to-End EncryptionData Retention PolicyLaw Enforcement RequestsChildren's PrivacyAccessibility StatementData Processing AddendumOpen Source Credits

Viremail is a service of Svayam Incarnation Limited, a company registered in England and Wales (company number [Company number (to be added)]), registered office [Registered office address (to be added)], United Kingdom. Contact us via the contact details on our website.