Privacy Policy

What we keep, what we do not keep, and for how long. The second one matters most.

Last changed: 4 September 2026

What we do NOT keep

The content of YOUR mail — what arrives at your domain — never enters our management systems at all. Those messages live only on the receiving machine, in your mailbox, and are removed by the automatic cleanup.

The event log holds no sender or recipient addresses, no subjects and no bodies of customer mail. It holds counters, times and reasons — enough to investigate an incident and not enough to read anyone's mail. That limit is enforced by a test, not by a promise.

Stated separately and plainly: OUR own messages to you — address confirmation, password recovery, the bot linking code — pass through a send queue in our database and, while they wait, hold the recipient address, subject and text including the one-time link. The record is erased as soon as the message is sent. The same applies to a message you send us through the contact form or the bot: that is your enquiry, and we keep it in order to answer.

What we keep

  • The account email address and a hash of the password. We do not know the password itself.
  • The domains you connected, their state and ownership history.
  • The money ledger: top-ups, charges, adjustments.
  • A security event log: sign-ins, password changes, domains created and released — with time and network address.
  • Numeric mailbox summaries: how many messages arrived, when mail was last collected.
  • Your Telegram id, if you linked the bot.
  • An access key to your DNS zone, if you chose the automatic path. It is stored encrypted and deleted when the domain is released.

Retention

  • Your messages — anything older than 72 hours is removed by an hourly cleanup.
  • One-time links and codes from emails are valid for 15 minutes; the send-queue record is erased once the message has gone out.
  • Panel sessions — 7 days; expired ones are removed.
  • The money ledger — for as long as the account exists: it is financial history and may not be erased.
  • Event log and summaries — for as long as the account exists.

Who else sees the data

  • Cloudflare — hosting for the site and panel, the database, and forwarding for our support address.
  • The hosting providers of the receiving machines (currently OVH and Hetzner) — the mailboxes and messages physically sit on their servers.
  • The payment service — the invoice: its amount and number. Your payment credentials never reach us at all.
  • Telegram — if you use the bot; the conversation goes through their servers.
  • GitHub — hosting for the Russian version of this site; opening it shows them the usual request details.
  • Law enforcement — on a lawful request.
  • Nobody else. We do not sell data and do not share it with advertising networks.

Your rights

You may ask what we hold about you and ask for the account to be closed. Closing removes domains, mailboxes and access keys; financial history is kept for as long as the law requires.

Send the request through the form on this site or through the bot, from the account email address.

The data controller is 301ST Ltd, 124 City Road, London, EC1V 2NX, United Kingdom.

Cookies and trackers

There are no advertising or analytics trackers on this site. The only cookie is the panel session after sign-in; without it the panel does not work.

Your chosen colour theme is stored in your browser and never reaches us.