Privacy Policy
Last updated 3 August 2026
YeyMail exists to keep your real email address private. This policy explains, in plain language, exactly what we do and don't do with your data. The short version: we relay your mail and immediately discard the content. We never store message bodies, we never sell your data, and we never build advertising profiles.
One thing has changed, and we would rather you read it here than find it in your browser's network tab: this public website now uses an analytics tool, and only if you accept it on the banner. It never runs once you are signed in. Cookies and analytics sets out what it collects, what it is never given, and how to change your mind.
What we store
To run the service we keep the minimum necessary:
- Your account email and a securely hashed password (argon2 — we can never read it).
- The aliases you create, your destination inboxes, and your custom domains.
- Forwarding metadata only: delivery logs and timestamps (e.g. “forwarded”, “bounced”, “blocked”), including which alias received a message, when, and the sending and receiving servers involved. Per-message delivery logs are kept for up to 30 days; your account activity history for up to 90 days. Both are pruned automatically after that.
- Billing records via our payment processor (we never see full card numbers).
- Ordinary web server logs for our own site: the page requested, the response, the time, and a truncated network address — the last part is removed before anything is written, so a single visitor cannot be identified from it. We keep these for up to 30 days to spot faults and automated attacks against the site. Session cookies and authorisation headers are never written to them at all.
- The IP address you signed up from, and — if we ever suspend an account — a short note of why. We keep these to stop one person creating accounts in bulk to farm free trials, which is the abuse that makes every other limit meaningless. Our lawful basis is legitimate interest in preventing fraud and protecting the service; the address is never used for advertising, profiling, or location tracking. It is erased with your account, with one exception: where we have already opened an abuse record, that record and the address in it are kept and detached from your account, because an erasure request would otherwise be a way to clear the history and start again.
- If you subscribe to the blog newsletter: your email address, when you confirmed, and the IP address you subscribed from. We keep these on the basis of your consent, and as the record that consent was given — including after you unsubscribe, so we can prove we were entitled to write to you. Ask us at privacy@yeymail.com and we will delete the row outright.
What we never store
We do not store the content, subject lines, or bodies of your emails. Messages pass through our servers over encrypted connections and are discarded after delivery. There is no message archive to breach, subpoena, or leak — because no content is kept.
Encryption & security
Mail is carried over TLS wherever the server at the other end supports it. For destinations that publish an enforcing MTA-STS policy and present a certificate chain we can verify, we require that verified certificate and will not fall back to plaintext; where a provider publishes no policy, publishes one only in testing mode, or serves a chain we cannot verify, delivery stays opportunistic, encrypted whenever the far end offers it but not enforced. We publish SPF, DKIM, and DMARC records and sign outbound mail, and we publish our own MTA-STS and TLS-RPT records so that senders can verify our mail servers. Optional PGP encryption lets you have incoming mail encrypted to your public key before it is forwarded.
No ads, no advertising profiles
We do not run ads. We never sell, rent, or share your data with ad networks or data brokers, and we do not build advertising profiles of you. There are no third-party trackers of any kind inside the signed-in app at /app: nothing measures what you do with your own aliases, domains, or mail. You are the customer, not the product.
We do run product analytics on this public marketing site, so we can tell which pages people arrive on and where they give up before signing up. We pay for advertising, and without that we are guessing. It is off until you accept it, it never follows you into your account, and it is described in full under Cookies and analytics.
Cookies and analytics
There are two groups here, and they are treated very differently on purpose.
1. Strictly necessary. No consent needed, because each one only does the thing you asked for.
- A session cookie that keeps you signed in. It holds a random session identifier, no personal data, and is
HttpOnly, signed, and markedSecure. - A short-lived sign-in security cookie used only while you're completing “Continue with Google”. It exists to stop a third party forging that sign-in, lasts ten minutes, and is deleted the moment you land back here.
- Your answer to the cookie banner, kept on your own device. We store it so we do not have to ask again on every page, and so that a no stays a no. Recording a refusal is the only way to honour one. Clearing this site's browser storage erases it, and the banner will ask again.
None of those three require your consent, and none of them can be switched off while you use the service. They carry no analytics or advertising purpose whatsoever.
2. Analytics. Nothing happens unless you say yes.
We use PostHog to understand how this public website is used: which page someone landed on, what they did next, and where they gave up.
Until you choose Accept, the PostHog script is never downloaded and never runs, and no analytics cookie or browser storage is created. Choosing Reject means it is never loaded at all. The two choices are the same size, side by side, in the same weight, with nothing pre-selected, and refusing costs you nothing here: the whole site works identically either way.
If you accept, PostHog receives:
- the pages you visit on this site, and the order you visit them in;
- how you arrived, meaning the referring website or the ad or search that sent you;
- clicks and form interactions on those pages, such as which button you pressed;
- where on the page those clicks landed, including clicks that hit nothing. That is what a heatmap is, and it is how we find a button people keep pressing that does not work;
- your device type, browser, operating system, screen size, and language;
- how long pages took to load;
- your IP address, which PostHog uses to work out an approximate country, region, and city. We do not use it to identify you, and we never combine it with your account;
- a random identifier stored in your browser, so that a second visit from the same browser is counted as one returning visitor rather than two new ones.
Even after you accept, PostHog is never given and never switched on for:
- anything inside your account. Analytics stops at the sign-in page. It does not run on any page under
/app, and your aliases, destinations, domains, activity, and mail are never sent to it. We are not willing to watch paying customers use a privacy product. - who you are. We do not send PostHog your email address, your account identifier, or any sign-in, password-reset, or invitation link. What it holds is a browser, not a person we can name.
- session replay or screen recording. We do not record your screen and we cannot play your visit back. We never capture what you type: the text you enter into any form here, including the address you put into the breach checker, is stripped before anything is sent. Click positions, described above, are coordinates and button labels, not a recording of you.
- advertising. Nothing collected here is sold, shared with an ad network, or used to build an advertising profile or retarget you.
Changing your mind is one click, in either direction. Use the Cookie settings link in the footer of any page on this site. It is there whether you accepted or refused, it takes exactly the same effort as accepting did, and withdrawing stops the collection immediately and deletes what PostHog stored in your browser. You do not have to email us, and you do not have to give a reason.
PostHog Inc. is a United States company and stores this data in the United States, which is a transfer outside the UK and EEA. It is covered by our data processing agreement with them, which relies on the EU-US Data Privacy Framework and the Standard Contractual Clauses. If you would rather that transfer did not happen, choose Reject and nothing is ever sent.
When you pay, checkout and the billing portal are hosted by Stripe on their own domains and set their own cookies there under Stripe's privacy notice: we never see your card details. The breach checker on our home page still sets nothing and sends nothing to us, and the address you type into it goes only to the breach database, never to PostHog.
Your rights (GDPR)
You can export your account data or delete your account at any time from Settings. Deleting your account immediately disables all aliases, cancels any active subscription, and purges your personal data — your account, aliases, destination inboxes, domains and mail history — from our database. We retain two narrow records: that a given @yeymail.com address was previously in use, so it can never be reassigned to someone else and start receiving what was your mail; and, where we had already opened an abuse record against the account, that record and the IP address in it, detached from your identity.
For the full list of your rights under the GDPR — access, rectification, erasure, portability, restriction, objection, and how to exercise each — see our GDPR & data rights page, or contact privacy@yeymail.com.
Sub-processors
- Stripe for billing.
- Cloudflare for the anti-bot check on the sign-up and password-reset forms. It receives your IP address and nothing else.
- Google, only if you choose “Continue with Google”.
- PostHog for website analytics, and only for visitors who accepted them on the cookie banner. Your data is stored in the United States, on PostHog Cloud US. If you did not accept, PostHog is not a processor of your data at all, because it was never sent any. That transfer out of the UK and EEA relies on the EU-US Data Privacy Framework and the Standard Contractual Clauses in our agreement with them.
- Standard infrastructure providers for hosting.
These providers process data only as needed to deliver the service and under their own compliance commitments.
The breach checker
The “breach check” tool on our home page runs entirely in your browser: the address you type is sent directly from your device to the XposedOrNot community breach database and never reaches our servers. We do not receive, log, or store what you check.
Changes
We'll post any material changes here and update the date above.