Home / Documentation / Security and GDPR

Security and GDPR

Where your data lives and who can reach it matters as much as the encryption on top of it. This page covers how we store mail, how passwords and signing work, and what actually happens when you delete an account.

1. The storage vault

Mail bodies, attachments and database records all live on a dedicated machine in Warsaw, separate from the public gateway.

  • Encryption at rest. The NVMe arrays use hardware-accelerated AES-256-XTS at the block level.
  • No public IP. The vault has no address reachable from the open internet.
  • Encrypted internal link. Traffic between the gateway and the vault runs over an authenticated, encrypted tunnel.

2. Passwords and signing

No MD5, no SHA-1, no unsalted hashes anywhere in the system.

  • Argon2id. Mailbox and account passwords are hashed with Argon2id, the Password Hashing Competition winner, which resists GPU and ASIC cracking far better than older algorithms.
  • TLS 1.3. Ingress connections require TLS 1.3 with forward-secret cipher suites such as ECDHE-ECDSA-AES256-GCM-SHA384 and ChaCha20-Poly1305.
  • DKIM signing. Outbound mail is signed with ed25519 keys held inside the vault.

3. Jurisdiction and the US CLOUD Act

Under the US CLOUD Act, a US cloud company such as Google, Microsoft or Amazon can be compelled by US law enforcement to hand over customer data stored on European servers, sometimes without notifying the customer at all.

Why that doesn't apply to us

  1. A Polish company. Owned and run by a Polish legal entity, with no US parent or subsidiary.
  2. Servers only in Warsaw. All hardware is in our own datacenter space in Warsaw. Nothing is relayed through another country.
  3. GDPR by default. We operate under Regulation (EU) 2016/679, and we provide a Data Processing Agreement for business accounts.

4. Deleting an account under Article 17

When you request deletion, here's what actually happens:

  • 30-day grace period. The account is suspended immediately but not purged, in case the deletion was a mistake.
  • Atomic purge. After the grace period, the database row and the Maildir on disk are removed together in a single transaction.
  • Fails closed. If the disk wipe doesn't complete, the whole transaction rolls back rather than leaving a half-deleted account.
  • Audit record. We keep a record that the deletion happened, for our own compliance purposes, without keeping the mail itself.