Privacy Policy
Last updated: July 2026. GoyMail is a privacy-focused email service for adults 18 and older. This policy explains what we collect, what we avoid collecting, and how we use the information needed to operate the service. For terms of use, see Terms of Service.
1. Privacy approach
GoyMail is designed to require less identity data than a typical webmail service. Registration does not require KYC, identity documents, legal names, phone numbers, address verification, or an existing email address. Login uses an access token instead of an email address as the login secret. The web app does not run third-party advertising trackers, does not load third-party assets, and renders mail bodies as plaintext rather than remote HTML.
Email is not end-to-end encrypted by default. Messages and metadata must pass through our systems so we can provide mailboxes and IMAP/SMTP access. That mailbox and delivery state is user data, not an access log.
2. What we collect
Account data: the handle and domain needed to create your email address, password hashes or token hashes, optional security settings, plan information, and preferences needed to operate your mailbox.
Mail data: messages, attachments, headers, folders, delivery metadata, and related mailbox state stored or processed as part of sending, receiving, and displaying email.
No-logs policy: we do not retain connection logs, web access logs, or IP histories. We do not sell traffic data, use it for advertising, or build account profiles from it. We do not keep connection metadata to investigate abuse after the fact.
Ephemeral processing (not retained as logs): a live TCP peer address may exist briefly for the connection. In-memory rate-limit counters (and nginx shared-memory limits) may key briefly on IP for anonymous public endpoints, or on account identity for authenticated outbound mail. Those counters are not written as access logs and are not kept as IP history. Routine web-app request lines use route patterns (not full paths) and are not intended to include access tokens, passwords, cookies, request bodies, message bodies, client IPs, or account identifiers.
3. How we use information
- To provide mailboxes, account access, support, and optional paid features.
- To apply ephemeral and account-keyed rate limits, keep outbound SMTP gated until unlock, and protect shared-IP deliverability.
- To debug outages and reliability using non-identifying operational signals where practical.
- To meet legal obligations where applicable, after reviewing whether a request is valid, narrow, compulsory, and limited to data we actually retain.
4. Cookies and local storage
The web app uses first-party cookies and local storage for sessions, CSRF protection, and UI preferences such as theme. Clearing browser storage may sign you out or reset preferences.
5. Third parties
We do not run third-party advertising trackers on the core GoyMail web app. External links, wallet providers, mail clients, DNS providers, Telegram, or other sites you choose to use are governed by their own policies once you leave GoyMail.
6. Retention and deletion
We retain account and mail data while your account exists. We do not retain connection, access, or IP logs. Backup remnants of account or mailbox data may persist for a limited time after deletion as part of ordinary operations. Authenticated outbound rate limits are keyed to the account (not stored as IP access history).
Public IRC and Telegram: GoyMail's IRC is privacy-focused on our side: Ergo history, The Lounge transcripts, Matterbridge message-body logs, and connect-IP logging are disabled. Messages are still visible live, recipients may log or copy them, and messages bridged from #lobby are stored by Telegram under Telegram's cloud retention rules. Editing or deleting a message on one side is not guaranteed to edit or delete every bridged copy.
Public XMPP: Prosody stores registered accounts and rosters, but this deployment disables server-side MAM, offline-message archives, and HTTP file upload. Prosody does not keep message transcripts or access logs (errors only in ephemeral container console). Federation with other XMPP servers is enabled, so messages you send to remote JIDs may be retained by those servers under their policies. Converse uses browser session storage; native clients may retain messages locally.
7. Legal requests
We do not treat informal law-enforcement messages as permission to hand over user data. We only accept valid, binding, and specific legal process that applies to our jurisdiction. We review requests for jurisdiction, scope, authenticity, and necessity before responding.
We may reject, narrow, challenge, or ask for clarification on requests that are vague, overbroad, unsupported, outside our jurisdiction, or not directed through an official channel. Where lawful and practical, we may notify affected users. We cannot provide data we do not retain.
8. Security
We use reasonable technical measures including token hashing, password hashing, session protection, CSRF protection, rate limits, strict security headers, and plaintext mail rendering in the web app. No service is perfectly secure; protect your token, passwords, devices, and mail clients.
9. Adults only
GoyMail is for adults 18 and older. Do not register, use the service, or create an account for someone else unless the user is at least 18 and allowed to use the service under applicable law.
10. Changes to this policy
We may update this page from time to time. The "Last updated" date at the top will change when we do.
11. Contact
Privacy-related questions: use Contact & FAQ.