Privacy Policy

We do not sell personal data. Stored client IPs expire after 14 days by default.

01 Summary

Elektrine does not sell personal data.

We keep only data needed to run the account and stop abuse.

We do not keep content-level traffic logs of your browsing or mail bodies for marketing.

02 Registration

Normal signup uses a username and password. A real legal name is not required.

Optional recovery email is for account recovery only.

03 Data we store

Account

  • Username, password hash, and security settings
  • Optional recovery email if you set one
  • Profile fields you publish, such as display name, avatar, and bio
  • Preferences such as locale, theme, and notifications
  • Registration IP on clearnet open signups only (not stored for Tor, or for invite/payment access-gated signups); cleared after the IP retention window
  • Last login IP on clearnet only (never stored for Tor); replaced on each sign-in and cleared after the IP retention window

Your content

  • Mail, posts, chats, files, and other content you create or receive
  • Mailbox and message metadata needed for delivery and folders

Sessions and device records

Signed-in browser sessions store technical metadata so you can review and revoke them.

  • On clearnet: session IP, user agent, and last-seen for each session row
  • On Tor: no session IP or user agent is stored
  • Stored session IPs are cleared when last-seen is older than the IP retention window (default 14 days)

Security and abuse control

In-memory and short operational records stop attacks and spam.

  • Failed login and rate-limit counters (typically short-lived process or cache state)
  • Connection counters for mail protocols when needed to stop abuse
  • Spam and malware signals on mail paths

Optional product analytics

Some product features (for example public profile or site visit stats) may store visitor technical data when those modules are used.

  • Visitor rows (including IP) are pruned by the analytics retention schedule (separate from the 14-day IP window)

04 Log policy

What we do not keep

  • We do not keep permanent content logs of web browsing through the product UI for profiling
  • We do not sell logs or traffic data
  • We do not build advertising profiles from private mail or private chats

IP addresses

Default IP retention is 14 days (override with IP_RETENTION_DAYS).

A daily job nulls stored client IPs older than that window on account, session, audit, API token, app password, trusted device, and passkey records.

  • Tor/onion: client IP and user-agent are not written for registration, login, sessions, analytics, or trusted-device metadata
  • Invite- or payment-gated registration: no registration IP is stored
  • Clearnet registration/login/session IPs: cleared after the retention window (default 14 days)
  • Account deletion immediately wipes IPs, revokes sessions and API tokens, and deletes that user's analytics rows
  • Admin audit-log and API token last-used IPs: cleared after the retention window

Operational logs

Operators may also keep host or process logs outside the application database. Those follow the operator's infrastructure retention.

  • Mail delivery status needed to fix bounce and spam issues (not full SMTP session history by default)
  • Error traces for server faults, without private message bodies when avoidable

VPN

VPN traffic contents are not logged.

Default: no durable connect or disconnect history and no client source IP on session rows.

WireGuard peers live in node memory. Aggregate bandwidth counters may remain for free-tier limits.

See the VPN Policy for full detail.

05 Mail and encryption

Mail uses open internet protocols. Delivery exposes envelope data to mail servers on the path.

Stored mail bodies use application encryption at rest by default.

Default: no second RFC822 copy and no connecting MTA IP on message metadata.

Admin tools do not decrypt mail or chat bodies.

Trash and spam are hard-deleted after a short retention window by default.

Private mailbox mode can lock more fields to a browser passphrase. Operational flags still stay on the server.

Use PGP or similar tools if you need end-to-end content protection outside Elektrine.

06 How we use data

  • Run email, chat, social, DNS, VPN, and other enabled modules
  • Authenticate accounts and stop abuse
  • Fix faults and keep the service online
  • Answer support requests you send

07 Sharing

We do not sell personal data.

  • We share data when you send it, for example mail to another provider or a public post
  • Infrastructure vendors process data only to host and deliver the service under our control
  • Mail delivery uses the public SMTP ecosystem by design
  • We disclose data when law requires a valid order
  • We act to stop active abuse, fraud, or direct harm

08 Cookies

  • Session cookies for login
  • CSRF and security tokens
  • Local preferences such as theme
  • Private mailbox unlock state in the current browser when you unlock it

09 Retention and deletion

Account and content stay while the account is active.

Stored client IPs are cleared after the IP retention window (default 14 days) as described under Log policy.

You may delete content and the account in settings where the product supports it.

Backups and infrastructure logs follow the operator's backup and log rotation schedule after deletion.

10 Your choices

  • Export or delete account data where the product supports it
  • Change privacy and notification settings
  • Contact privacy support for requests the UI cannot complete

11 Children

The service is not for children under 13.

We do not knowingly collect personal data from children under 13.

12 Source code and canary

Elektrine source is public under AGPL-3.0-only.

A signed warrant canary is published at /canary when the operator maintains it.

13 Changes

Operators may update this policy.

Material changes appear on this page. Important changes may also use in-app notice.

14 Contact

Privacy requests: privacy@elektrine.com