Privacy Policy
Last updated 26 July 2026
YeyMail exists to keep your real email address private. This policy explains, in plain language, exactly what we do and don't do with your data. The short version: we relay your mail and immediately discard the content — we never store message bodies, and we never sell or profile your data.
What we store
To run the service we keep the minimum necessary:
- Your account email and a securely hashed password (argon2 — we can never read it).
- The aliases you create, your destination inboxes, and your custom domains.
- Forwarding metadata only: delivery logs and timestamps (e.g. “forwarded”, “bounced”, “blocked”), including which alias received a message, when, and the sending and receiving servers involved. Per-message delivery logs are kept for up to 30 days; your account activity history for up to 90 days. Both are pruned automatically after that.
- Billing records via our payment processor (we never see full card numbers).
What we never store
We do not store the content, subject lines, or bodies of your emails. Messages pass through our servers over encrypted connections and are discarded after delivery. There is no message archive to breach, subpoena, or leak — because no content is kept.
Encryption & security
Every hop we control is TLS-encrypted. We publish SPF, DKIM, and DMARC records and sign outbound mail. Optional PGP encryption lets you have incoming mail encrypted to your public key before it is forwarded.
No tracking, no ads
We do not run ads, embed third-party trackers in the app, or build advertising profiles. You are the customer, not the product.
Cookies
We use exactly two cookies, and both are strictly necessary for something you asked us to do:
- A session cookie that keeps you signed in. It holds a random session identifier — no personal data — and is
HttpOnly, signed, and markedSecure. - A short-lived sign-in security cookie used only while you're completing “Continue with Google”. It exists to stop a third party forging that sign-in, lasts ten minutes, and is deleted the moment you land back here.
That's the whole list. We set no analytics, advertising or tracking cookies, which is why you have not been shown a cookie banner: consent is required for tracking cookies, and we don't use any. If that ever changes, we'll ask you first rather than assume.
When you pay, checkout and the billing portal are hosted by Stripe on their own domains and set their own cookies there under Stripe's privacy notice — we never see your card details. The breach checker on our home page sets nothing and sends nothing to us.
Your rights (GDPR)
You can export your account data or delete your account at any time from Settings. Deleting your account immediately disables all aliases, cancels any active subscription, and purges your personal data — your account, aliases, destination inboxes, domains and mail history — from our database. We retain one narrow, non-content record: that a given @yeymail.com address was previously in use, so it can never be reassigned to someone else and start receiving what was your mail. That protection is for you.
For the full list of your rights under the GDPR — access, rectification, erasure, portability, restriction, objection, and how to exercise each — see our GDPR & data rights page, or contact privacy@yeymail.com.
Sub-processors
We use a payment processor (Stripe) for billing and standard infrastructure providers for hosting. These providers process data only as needed to deliver the service and under their own compliance commitments.
The breach checker
The “breach check” tool on our home page runs entirely in your browser: the address you type is sent directly from your device to the XposedOrNot community breach database and never reaches our servers. We do not receive, log, or store what you check.
Changes
We'll post any material changes here and update the date above.