1. Two different roles
Mailcycle handles personal data in two capacities.
- As a controller for your account data: the information you give us when you create an account, pay us and contact support (see section 2). This policy describes that processing.
- As a processor for the mail your email addresses receive. That content belongs to you; we handle it on your instructions. If you are subject to the GDPR or UK GDPR, our Data Processing Agreement governs that relationship and takes precedence over this policy for it.
The controller for account data is Northlab Studios Ltd, registered in England and Wales, 167-169 Great Portland Street, London W1W 5PF, United Kingdom.
2. What we collect
Your account
There is no sign-up form. Creating a Mailcycle account generates a twelve-word recovery phrase on your device and derives an opaque identifier from it. The complete account record we hold is:
- An account id:
acct_followed by 32 hexadecimal characters, derived from your recovery phrase. It is not linked to any identity. - A public key used to check that you hold the phrase when you sign in, and, for accounts created before that key existed, a hash that served the same purpose. Neither can be reversed into the phrase or into your encryption key.
- A plan identifier and a creation date.
Using the account adds records linked to that id: your sessions (a hash of each token, when it was created and when it expires), a push token for each phone that allows notifications, your notification settings and muted addresses, and an activity log of events such as a device pairing or a message sent, holding a kind, the ids involved and a time.
We do not hold your name, your email address, a password, a security question, a phone number, a recovery contact or a signup source.
Information you give us
- Billing: if you buy a paid plan, we record the plan, amount, currency, payment provider, payment status, dates and the provider's own reference for the payment, plus a ledger of charges, refunds, chargebacks, credits and plan changes. You enter payment details on the provider's own checkout or in the App Store or Google Play, and we never receive them. The provider is given our payment reference and the plan, not your account id. Polar, which takes card payments, asks for an email address at checkout for receipts and its customer portal. That address stays with Polar; we do not receive it. Paying by card, or through the App Store or Google Play, ties a real identity at that provider to a payment we can link to your account id. Paying in cryptocurrency usually does not.
- Support: whatever you include when you write to us. If you email us, we have your email address for that conversation; we do not attach it to your account.
- Domains you bring: on plans that include custom domains, the domain name, its verification token and its DNS and routing status. The domain is added to our Cloudflare account so it can receive mail.
- Pairing a device: the device sends its platform and a device name so you can recognise it when you confirm the pairing. No shared key exists at that point, so this name is held in plain text on the pairing record until the pairing is confirmed, then cleared. The name you give the device is encrypted.
Information we collect automatically
- Device metadata: platform and status for each paired device, plus a last-active timestamp rounded down to the hour. The names, tags and notes you give your devices are encrypted before they reach us.
- Connection data: IP addresses are visible to Cloudflare, our hosting provider, while a connection is open, and are used for rate limiting and abuse prevention. We do not store them in our database as account history or join them to an account id.
- Rate limit counters: counts of recent requests, keyed by a SHA-256 hash of the IP address (for IPv6, of its /64 prefix) or of the account id. One row per limit per time window, not one row per request.
- Service logs: errors and a sample of one request in ten, kept by our hosting provider. They can include request details such as the IP address. We do not log message content.
- Product analytics: none in the app. We run no analytics, no advertising and no cross-site tracking on app.mailcycle.email, whose addresses carry the identifiers of your email addresses and devices.
- Visit counting on the website, and only if you allow it. Cloudflare Web Analytics then records the page you opened, the page that linked you to it, your browser, device type and country, and how long the page took to load. It sets no cookie, stores nothing on your device and cannot recognise you on a later visit. It is off until you allow it. See the Cookie Policy.
Information received on your behalf
Mail sent to your email addresses. Its sender addresses, subjects, bodies, headers and attachments are encrypted before storage to a key derived from your recovery phrase, which we never hold. What remains readable to us is the routing metadata: the recipient email address, the arrival time, the size, the number and size of attachments and whether it has been read. This is Customer Data and is covered by section 4.
Information from other people
Anyone can report a Mailcycle address or account for abuse, without an account. A report holds its source type, the address or account id it names, the reason given, and how it was resolved. It holds nothing about the reporter unless they write it into the reason. If you report by email, we also have your email address for that conversation.
Administrative records
Mailcycle has a single administrator. For each account they can record a suspension and its reason, notes, a rate limit tier, a retention cap, extra address allowance, a custom price, credits, refunds and past-due status. Every administrative action is written to an audit log holding the action, the target id, the reason and some detail, which for a suspended address includes the address. The administrator has no access to message content.
We do not buy personal data, and we do not sell it.
3. Why, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the Service | Account id, routing metadata, device platform and status | Performance of a contract |
| Billing and tax records | Payment records and the billing ledger | Contract; legal obligation |
| Support | Support correspondence | Contract; legitimate interests |
| Security and abuse prevention | Hashed rate limit counters, sampled service logs, abuse reports, administrative records and the audit log | Legitimate interests; legal obligation |
| Service notices | Posted on this website, and by push notification where turned on | Contract |
| Marketing email | Not applicable. We hold no address to send one to | N/A |
Where we rely on legitimate interests, we have considered your rights and interests and concluded they are not overridden. You can ask us for that assessment.
4. Mail content
Mail received at your email addresses is yours, and it is encrypted.
- Inbound mail arrives at our servers in the clear, as SMTP requires. It is parsed in memory, and before anything is written to storage the whole message is sealed to a public key belonging to that address. The matching private key is derived from your recovery phrase on your device.
- What we store is ciphertext. We hold no copy of the private key and no means of deriving one.
- Mail you send through the API is the exception. It has to leave as plain text to reach an ordinary mail server, so it passes through our code and Cloudflare Email Sending in the clear. We do not write it to storage or log it. Your own copy is encrypted on your device.
- We cannot use it to train machine learning models.
- We cannot scan it for advertising.
- We cannot disclose its content to anyone, including under a legal order, because we cannot read it.
No one at Mailcycle can access message content. There is no internal viewer and no escrowed key; production access shows only ciphertext. What we can access, and can therefore be compelled to produce, is set out in section 2: your email addresses, arrival times, sizes, plan and payment records. The encryption protects stored mail. Mail arriving or being sent is in the clear in our code for the length of that request.
Opening mail discloses nothing to the sender. The app blocks remote content when it shows a message, so tracking pixels do not fire. Senders cannot learn that you opened their mail, when, from where, or on how many devices.
People who send mail to your email addresses are not our customers and have no direct relationship with us. You are responsible for having a lawful basis for the personal data that arrives at your addresses.
5. Who we share it with
- Subprocessors: infrastructure, push notification and payment vendors that process data on our behalf under contract. The current list is at mailcycle.email/legal/subprocessors.
- Professional advisers: auditors and lawyers, under confidentiality.
- Authorities: where we are legally required. We review every request and reject overbroad ones. Two practical limits apply: we can only produce what section 2 says we hold, which does not include message content or your identity, though for a paid account it does include the payment provider's reference; and because we hold no email address for you, “notifying you” means a push notification, if you have turned them on, which we will send unless we are legally prohibited from doing so.
- A successor: if Mailcycle is acquired or merged, subject to this policy continuing to apply. We will notify you before your data becomes subject to a different policy.
6. International transfers
Mailcycle's database and storage run in Western Europe. Push notifications go through Expo in the United States, and card payments through Polar in the United States. Some vendors on the subprocessor list are located elsewhere, including the United States. Where personal data leaves the UK or EEA, we rely on adequacy decisions where they exist and otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus additional technical measures such as encryption in transit and at rest.
Copies of the relevant transfer mechanisms are available on request.
7. How long we keep it
You can shorten most of the windows below.
| Data | Retained |
|---|---|
| Account record | For the life of the account. Deleting the account removes it from the live database immediately, with no grace period. See Backups below. |
| Message content and metadata | The retention window you set per email address: 24 hours, 7, 30 or 90 days, defaulting to 7. Anything past it stops being readable at once, and a server-side sweep that runs every hour deletes it. Shortening a window deletes mail already past the new limit straight away. 90 days is the maximum we offer. |
| Device records | Until the device is removed, then removed from the live database immediately |
| Pairing records | A code that is never claimed is deleted when the device cancels it, or 14 days after it was created. When a code is claimed, the device name is cleared from it. The rest of the record is kept while the device exists and deleted when the device or the account is removed. |
| Sessions | 30 days from sign-in, or until you sign out or end the session. An hourly sweep deletes expired sessions. |
| Push tokens | Until the session they belong to ends, or until Expo reports that the app was uninstalled |
| Notification settings | For the life of the account |
| Account activity log | For the life of the account |
| Rate limit counters | Hashed, and deleted within an hour of their window closing. The longest window is 30 days. |
| Service logs | Kept by our hosting provider for its log retention period, then deleted |
| Administrative records | Suspension status, administrator notes, rate limit tier, retention cap and billing state last for the life of the account and are erased with it. |
| Audit log | Permanent. Entries are hash-chained and never edited or deleted, including after the account they refer to is deleted. |
| Abuse reports | Deleted with the account they refer to. Otherwise open reports are kept until resolved, and resolved reports are deleted 12 months after resolution. |
| Retired addresses | Permanent, as a hash of the address only, so the address is never issued again |
| Support correspondence | Up to 12 months |
| Payment records and billing ledger | Kept after the account is deleted, for as long as tax and accounting law requires, typically 6 to 7 years. They contain no mail and no keys. |
| Backups | Our database provider keeps point-in-time restore history for 30 days, so a deleted database record, including sealed content and metadata, can be restored during that window and is gone from the restore history within 30 days. Message bodies and attachments stored in object storage are deleted at once and are not backed up. |
8. How we protect it
Message content is sealed to a key derived from your recovery phrase, which we never hold, as soon as it reaches us. Underneath that: TLS in transit, encryption at rest, device credentials in the platform keystore, and an audit log of every administrative action. There are no passwords in the system to protect. The full picture, including what we can still see, is in our security overview.
If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected customers without undue delay.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing, to receive your data in a portable format, and to withdraw consent where we rely on it.
You can exercise most of these directly in the app:
- Access and portability. Settings → Export data downloads your addresses and messages, decrypted on your device.
- Deletion. Settings → Danger zone → Delete account removes the record, every email address, every message and every device from the live database immediately. You do not need to ask us, and we cannot delay it. What remains is listed in section 7: payment records and the billing ledger, audit log entries, hashes of retired addresses, and the restore window.
- Restriction. Lowering an address's retention window deletes anything already past the new limit straight away.
For anything else, email hello@mailcycle.email. We respond within one month and will not charge you or degrade your service for asking.
Verification. Because accounts are anonymous, we generally cannot verify that a person asking about an account is its holder, and we will not act on an unverified request. Anyone holding the recovery phrase can exercise every right above directly in the app. If you have lost the phrase, we cannot identify your account in order to help.
If your request concerns mail received at a customer's email address rather than your own account, we will forward it to the relevant customer, who is the controller for that data.
You may complain to a supervisory authority: in the UK the Information Commissioner's Office, or in the EEA your local authority. We would appreciate the chance to resolve it first.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. The rights above cover the CCPA rights to know, delete, correct and opt out, and we will not discriminate against you for exercising them.
10. Children
Mailcycle is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, write to us and we will delete it.
11. Changes
We will update this policy as the service changes. Material changes are announced on this website at least 30 days before they take effect. The effective date at the top always reflects the current version.
12. Contact
hello@mailcycle.email
Northlab Studios Ltd, 167-169 Great Portland Street, London W1W 5PF, United Kingdom
Data protection officer or representative: [DPO or representative name and contact, or “not appointed”].