smallemail coming soon

Privacy Policy

How small.email collects, protects, and stores your data under strict European Union privacy jurisdiction. Ad-free, transparent, and built from first principles.

GDPR Compliant Effective Date: October 9, 2026 • Version 1.0 • Data Jurisdiction: EU (Frankfurt & Helsinki)

Our Foundational Privacy Guarantee

small.email operates on a direct, paid subscription model. We never sell your personal information, we never scan your inbox for advertisements or behavioral profiling, and all persistent data storage resides strictly inside the European Union under GDPR law.

1. Overview

This Privacy Policy outlines how small.email ("we", "us", or "our") manages personal data when you visit our website (https://small.email), connect custom domains, and use our email infrastructure services.

We believe personal communications belong exclusively to their sender and recipient. Our technical architecture is designed to minimize data exposure at every layer, from inbound SMTP ingress to edge webmail delivery.

2. Information We Collect

We collect only the minimum data strictly required to deliver, secure, and route your emails:

Account Credentials

Your primary account email address, cryptographically hashed credentials, and multi-factor authentication tokens.

Domain & Routing Keys

Domain names you verify, DNS verification tokens, selector DKIM public keys, and SPF/DMARC routing parameters.

Mailbox Content

Inbound and outbound email messages, headers, attachments, and folder trees stored encrypted in object storage.

Billing Metadata

Subscription tier, renewal date, and invoice identifiers. Handled by Merchant of Record partners; we never see raw card numbers.

Operational Telemetry: Connection logs (IP addresses, timestamps, and SMTP response codes) are retained for up to 30 days solely for defensive rate limiting, spam prevention, and delivery diagnostics, after which they are permanently purged.

3. Mailbox Privacy & Zero Ad-Scanning

Traditional "free" email providers subsidize their infrastructure by reading your correspondence to train behavioral advertising models. small.email does not:

  • No Content Inspection: We do not scan the text or attachments of your emails for marketing, commercial analytics, or profiling.
  • No Ad Trackers: Our webmail interface is completely free of third-party advertising SDKs, tracking pixels, and analytics beacons.
  • Workspace Boundary Isolation: Workspace owners can manage provisioning and quotas, but cannot access or decrypt mailbox contents of individual team members without direct credentials.

4. EU Data Sovereignty & Storage

All core infrastructure, primary databases, and message storage are hosted exclusively within the European Union:

  • Inbound SMTP Gateways: Dedicated Haraka and Rspamd clusters situated in Frankfurt, Germany and Helsinki, Finland (Hetzner Online GmbH).
  • Edge Metadata & Object Storage: Message indexes and encrypted MIME bodies stored via Cloudflare D1 and Cloudflare R2 restricted to the EU jurisdiction.
  • Transactional Outbound: Amazon Web Services (AWS SES v2) provisioned strictly in EU regions (Frankfurt / Ireland) for verified paying customers.

5. AI & Machine Learning Processing Policy

If you choose to enable optional AI-assisted features (such as on-demand email thread summarization or draft assistance in the webmail client):

Zero Data Retention (ZDR) Commitment

Any prompt sent to foundational AI APIs (such as the Anthropic Claude API) is covered under strict enterprise Zero Data Retention agreements. Your data is processed in-memory, never stored on third-party servers, and never used to train foundational AI models.

All AI capabilities remain opt-in and under user control at all times.

6. Sub-processors & Service Partners

We work with vetted infrastructure providers bound by contractual Data Processing Agreements (DPAs):

Partner Service Provided Jurisdiction Data Scope
Cloudflare, Inc. Edge CDN, Pages, Workers, D1 & R2 Storage European Union Encrypted mail storage & web traffic
Hetzner Online GmbH Dedicated Inbound SMTP Gateways Germany / Finland Inbound SMTP filtering & delivery
Amazon Web Services EMEA SES v2 Transactional Outbound EU (Frankfurt / Ireland) Outbound authenticated mail
Polar Software Inc. Merchant of Record (Global USD Billing) USA / EU Compliant Customer email & billing receipts
PT Mayar Pintar Teknologi Indonesian Payment Gateway (IDR) Indonesia Local payment verification (QRIS/VA)

7. Your Rights Under GDPR

As a European Union or global data subject, you hold comprehensive rights over your personal data:

Right of Access (Art. 15)

Obtain confirmation of what personal data is processed and receive a full copy.

Right to Erasure (Art. 17)

Request the complete, permanent deletion of your account and all associated mailboxes.

Right to Rectification (Art. 16)

Update or correct any inaccurate account details and routing records.

Data Portability (Art. 20)

Export your full mailbox and message history in standard, interoperable formats.

Restriction of Processing (Art. 18)

Restrict processing while a contest or verification is in progress.

Right to Object (Art. 21)

Object to specific data processing operations at any time.

To exercise any of these statutory rights, please email us directly at [email protected].

8. Data Retention & Permanent Deletion

We retain active mailbox messages until you delete them or close your account. When you delete a message or remove a custom domain:

  • The record is immediately inaccessible from all user interfaces.
  • Underlying encrypted object blocks in Cloudflare R2 are permanently purged through automated garbage collection within 30 days.
  • System connection logs are routinely truncated and never retained beyond 30 days.

9. Contact & Data Protection

If you have any questions regarding this Privacy Policy, your rights under GDPR, or wish to exercise data portability, please reach out to our team:

small.email Data Protection
Inquiries: [email protected]
General Support: [email protected]
Contact Privacy Team