GDPR & Data Rights
Last updated 3 August 2026
YeyMail is built to hold as little of your data as possible — we never store the content of your mail, and we never sell your data or build advertising profiles. This public website does use analytics, and only if you accept them on the cookie banner; see Cookies and analytics. This page sets out your rights under the EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR, and how to exercise each. It complements our Privacy Policy, which describes what we store and why.
Who is the data controller
YeyMail is the data controller for the personal data described in our Privacy Policy. For any data-protection question or request, contact privacy@yeymail.com. We aim to respond to rights requests within 30 days.
What data we process, and our legal basis
- Your account (email, hashed password) and the aliases, destination inboxes and domains you create — processed to perform our contract with you, i.e. to run the service you signed up for.
- Forwarding metadata (which alias received mail, when, delivered/bounced/blocked — never content) — processed under our legitimate interest in operating a reliable, abuse-resistant service and giving you delivery logs. Kept for up to 30 days (delivery logs) or 90 days (activity history).
- Billing records — processed to perform our contract and to meet our legal obligations (tax and accounting). Card details are handled by our payment processor; we never see full card numbers.
- If you subscribe to the blog newsletter: your email address, when you confirmed, and the IP address you subscribed from. We keep these on the basis of your consent, and as the record that consent was given — including after you unsubscribe, so we can prove we were entitled to write to you. Ask us at privacy@yeymail.com and we will delete the row outright.
- Website analytics on our public marketing pages (pages viewed, referrer, device, approximate location from your IP address) — processed only on the basis of your consent, given on the cookie banner. No consent means no collection at all, not merely collection we ignore. This never applies to pages inside your account.
We do not process the content, subject lines or bodies of your email. Mail is relayed over encrypted connections and discarded after delivery.
Cookies: three are strictly necessary and need no consent. They are the session cookie that keeps you signed in, a ten-minute security cookie used only while completing “Continue with Google”, and the record of your answer to the cookie banner. Analytics cookies are separate: they are set only if you accept them, they are never set inside your account, and you can withdraw at any time from the Cookie settings link in the site footer. See Cookies and analytics in the Privacy Policy for exactly what is collected.
Your rights
- Access — get a copy of the personal data we hold about you. Use Export my data in Settings for an immediate machine-readable download, or ask us.
- Rectification — correct anything inaccurate. Most fields are editable directly in your dashboard.
- Erasure (“right to be forgotten”) — delete your account from Settings. This immediately disables all aliases, cancels any active subscription, and purges your personal data and mail history. We retain two narrow records: a marker that a shared
@yeymail.comaddress was previously in use, so it can never be reassigned to a stranger who would then receive your mail; and, where we had already opened an abuse record against the account, that record and the IP address it concerns, detached from your identity. - Data portability — receive your data in a structured, common format (JSON) via Export my data, and move it elsewhere.
- Restriction & objection — ask us to pause processing, or object to processing based on legitimate interest. Contact us and we'll act on it.
- Withdraw consent — where we rely on consent, you can withdraw it any time without affecting the service. Optional product emails and the newsletter are in Settings. Website analytics are under Cookie settings in the site footer, which takes exactly as few clicks as accepting did and deletes what was stored in your browser.
How to exercise a right
Most rights are self-service in Settings (export, deletion, editing your data, notification preferences). For anything else — or if you'd prefer we handle it — email privacy@yeymail.com from your account address. We may ask you to confirm your identity before acting on a request. Exercising your rights is free.
International transfers
Our infrastructure and sub-processors may process data outside your country. Where data leaves the EEA/UK, it is covered by appropriate safeguards such as the EU Standard Contractual Clauses.
Sub-processors
We use Stripe for billing, Cloudflare for the anti-bot check on the sign-up and password-reset forms (it receives your IP address and nothing else), Google if you choose “Continue with Google”, PostHog for website analytics if (and only if) you accepted them on the cookie banner, and standard infrastructure providers for hosting. These providers process data only as needed to deliver the service and under their own compliance commitments. PostHog stores its data in the United States; that transfer relies on the EU-US Data Privacy Framework and the Standard Contractual Clauses, and it does not happen at all if you declined. The optional home-page breach checker runs in your browser and sends nothing to us. See the note in our Privacy Policy.
Complaints
If you believe we've mishandled your data, please tell us first at privacy@yeymail.com — we'd like the chance to put it right. You also have the right to lodge a complaint with your local data-protection authority.