Home/Privacy Policy

Privacy policy

What we hold, and what we could not hand over if asked.

A privacy policy is only worth reading if it says what a system is incapable of doing, not just what a company promises not to do. Both are below.

Last updated: [COMPLETE: date] · Operator: [COMPLETE: legal entity name & address]

1. What we do not collect, at all

None of the following is requested, stored, or verified at any point:

  • Your legal name.
  • A phone number. There is no SMS verification anywhere in the flow.
  • Government identification, passport scans, selfies or any KYC document.
  • A billing address. Payment is cryptocurrency, which carries none.
  • Card numbers or bank details — we have no mechanism to accept them.
  • Date of birth, gender, occupation, or any demographic profile.

This is not restraint. There is nothing in the product that needs any of it, so none of it is asked for. Data you never hold cannot be leaked, subpoenaed or sold.

2. What we necessarily do hold

a. One contact address

A single email address of your choosing, so we can send credentials, invoices and service notices. It may be any mailbox you control — including a throwaway one. It is used for that purpose only and is never sold, rented or shared with a third party for marketing.

b. Ciphertext

Your messages, attachments and files, encrypted before they leave your browser. We hold the sealed bytes and the wrapped data keys. We do not hold anything capable of unwrapping them. See the security page for the mechanism.

c. Authentication verifiers

A value derived from your passphrase that proves you know it without revealing it. Your passphrase itself is never transmitted and never stored, in any form, reversible or otherwise.

d. Mail metadata

Envelope data — sender, recipient, timestamp, message size — because that is how email routing physically works. Content is sealed; the fact that a message was delivered is not, and no provider can change that.

e. Billing records

Invoice reference, plan, amount, currency and transaction identifier, held at portal.owrbit.com for accounting purposes. A blockchain transaction is public by nature; how identifiable that makes it depends on the coin you chose and how you acquired it, which is outside our control.

3. Logging

Web and proxy access logs are dropped rather than written to disk. Mail queue state exists transiently while a message is in flight, because delivery cannot happen otherwise, and is discarded once the message is handed off.

Said plainly: "no logs" is a posture, not a switch

Any service claiming absolute zero retention is overstating its position. Transient state exists during processing, and a legal order in the operating jurisdiction can compel prospective logging that did not exist before. What we can say honestly is that we do not retain access logs by default, and that the content itself is encrypted such that logging it would produce ciphertext.

4. Retention

  • Mailbox content — kept while your account is active. Deleted objects are crypto-shredded immediately.
  • Suspended annual accounts — data held for 30 days from expiry, then crypto-shredded and the address released.
  • Terminated accounts — crypto-shredded on termination.
  • Billing records — retained for the period required by applicable accounting law: [COMPLETE: retention period].
  • Abuse reports — retained while the matter is open plus a reasonable period afterwards, to detect repeat patterns.

5. Third parties

We use as few as the service allows. Those we do use:

  • Billing portal (portal.owrbit.com) — invoicing, payment processing and support tickets.
  • Cryptocurrency payment processing — to generate invoices and confirm settlement on-chain.
  • Infrastructure providers — hosting for servers and encrypted object storage, which hold ciphertext only.
  • Blocklist and reputation services — queried during spam scoring at the gateway.

We do not run third-party analytics, advertising pixels, session recorders or social trackers on this website. There is no cookie consent banner because there is nothing to consent to.

6. Legal disclosure

If served with a valid legal order in the operating jurisdiction, we comply with it — as every operator must. What compliance would actually produce is:

  • Ciphertext, which is unreadable without your passphrase.
  • Wrapped key material that cannot be unwrapped without your passphrase.
  • Your contact address, invoice records and mail metadata.
  • Not your passphrase, your master key, or any readable message content — because we do not have them and cannot obtain them.

Where we are legally permitted to notify you of a request, we will. Where a gag provision prevents it, we cannot. Treating the architecture as the protection — rather than a promise about our future conduct — is the point of the design.

7. Your rights

  • Access — everything we hold about you is either in your account or is ciphertext you already possess the key to.
  • Deletion — delete objects yourself, or request termination for a full crypto-shred. Deletion does not entitle you to a refund; see the refund policy.
  • Correction — change your contact address at any time in the portal.
  • Portability — export over standard IMAP to any client or provider. No lock-in, no proprietary format.

Where GDPR, CCPA or an equivalent regime applies to you, those statutory rights apply in addition to the above. Direct requests through the portal.

8. Children

The service is not directed at anyone under 16 and is not intentionally sold to them.

9. Changes

Material changes are announced to your contact address before they take effect, and this page's date is updated. We do not make privacy terms retroactively worse without telling you first.

10. Contact

Privacy questions: [email protected]. Security disclosures: [email protected]. Everything else: the contact page.

The best privacy policy is a short list of things you hold.

Ours is short because the architecture keeps it that way.