Legal
Privacy Policy
Nisdos Mail is built on a simple idea: your mail should live in storage you control, not ours. This policy explains what we collect, why, how we protect it, and — just as importantly — the data we deliberately never hold.
1. Who we are
Nisdos Mail (“Nisdos”, “we”, “us”) provides an email service that routes, verifies and encrypts mail for your own domain and writes it into object storage you nominate (for example Amazon S3, Cloudflare R2, a WebDAV server, or a Git repository). For any question about this policy or your data, contact us at the-mail@nisdos.com.
2. Data you entrust to us
- Account data — the email address you sign up with, a password hash, and basic billing details where a paid plan applies.
- Domain & DNS configuration — the domains you connect and the MX, SPF, DKIM and DMARC records we manage and verify on your behalf.
- Storage credentials — the access keys for the storage you nominate. These are encrypted before they are stored so they can be used to operate your mailbox and for no other purpose. This applies when we hold keys on your behalf; if you enrol in device custody encryption and supply your own keys, we do not retain working keys able to read your stored mail.
- Message content & metadata — the mail we route for you. Message bodies and attachments are compressed and encrypted, then written to your storage. Routing metadata (sender, recipient, timestamps, delivery status) is processed transiently to deliver mail and maintain your domain's reputation.
3. Data we deliberately do not hold
Your mail at rest lives in storage you control, not on our disks. Message bodies and attachments are encrypted with a per-mailbox key before they leave our edge, so your storage provider only ever sees ciphertext.
If you enable device custody encryption, the mailbox key is generated in your browser and never sent to us. Enrolling erases our copy of that key — from that moment we cannot read your stored mail, and neither can anyone we could be compelled to hand it to.
4. How we use your data
- To route, verify, encrypt and deliver mail for your domains.
- To operate, secure and maintain your account and mailboxes.
- To monitor deliverability and protect your domain's sending reputation.
- To detect and prevent abuse, fraud and security incidents.
- To comply with our legal obligations.
We do not sell your data, and we do not scan your mail to build advertising or marketing profiles.
5. Legal bases (GDPR)
Where the GDPR applies, we process your data to perform our contract with you (providing the service), to pursue legitimate interests (security, abuse prevention, deliverability), to comply with legal obligations, and — where required — on the basis of your consent, which you may withdraw at any time.
6. Storage, location & sovereignty
Because your mail is written into storage you nominate, you choose where the bytes physically sit and whose jurisdiction governs them. Our own operational systems (routing, account data, encrypted credentials) are hosted with reputable providers under appropriate safeguards. Where data is transferred internationally, we rely on lawful transfer mechanisms such as Standard Contractual Clauses.
7. Retention
Your mail is retained in your storage for as long as you keep it there — deletion is under your control. Account and billing records are kept for as long as your account is active and thereafter only as required to meet legal, tax and accounting obligations. Transient routing logs are kept for a limited period for security and troubleshooting, then deleted.
8. Sub-processors
We rely on a small set of service providers to run the service — for example infrastructure hosting and payment processing. Each is bound by contractual confidentiality and data-protection obligations. We will provide a current list of sub-processors on request.
9. Security
Mail is encrypted at rest with per-mailbox keys, storage credentials are encrypted, and traffic is protected in transit with TLS. Our receiving edge is stateless and confirms delivery only after your mailbox holds the message, so mail is not silently dropped. No system is perfectly secure, but we design to minimise what an attacker — or we — could ever access.
10. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise any of these, email the-mail@nisdos.com. Much of your mail data is already directly accessible to you in the storage you control.
11. Cookies & analytics
Our marketing site uses privacy-respecting analytics to understand aggregate traffic. The webmail application uses only the cookies strictly necessary to keep you signed in and to operate the service.
12. Children
Nisdos Mail is not directed at children and is not intended for use by anyone under the age of 16.
13. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected in the “last updated” date above and, where appropriate, communicated to you directly.
14. Contact
Questions about privacy or your data? Write to the-mail@nisdos.com and we'll respond.