Legal · last updated 2026-06-03

Privacy Policy

Effective June 3, 2026 (v1.0.1).

TL;DR

We collect the minimum data needed to give you an email account and the AI brain features. We do not sell your data, ever. Your email contents are end-to-end encrypted with libsodium. We do not use third-party advertising, analytics, or trackers. You can delete your account and all data at any time from Settings → Account → Delete Account.

What we collect

  • Account info — email address, password (argon2id-hashed), display name. You provide this at signup.
  • Sign in with Apple identity — if you sign in with Apple, we receive the stable Apple-side user identifier (the sub claim) and the email Apple shares with you (which may be a private-relay address). We use this only to recognize you on future logins.
  • Wallet address — if you sign in with a Web3 wallet, we store your public Ethereum address and the SIWE signature. We never have access to your wallet's private key. Wallet sign-in is identity-only — no transactions, no gas.
  • Email contents — messages you send and receive, including subject, body, attachments. Stored end-to-end encrypted with libsodium sealed boxes; even our infrastructure team cannot read message bodies for E2E-encrypted messages.
  • Notes & calendar events — what you write. Notes history (last 50 revisions per note) is retained so you can roll back.
  • Brain memory — knowledge-graph entities (people, organizations, places, dates, amounts) extracted from your email locally on our server using compromise.js NLP. Stored linked to your user account so the AI brain can search them.
  • AI conversation history — if you talk to the brain, we store the conversation transcript so it survives reloads. You can disable this in Settings → AI → Store conversation history.
  • Account preferences — settings, language, theme. Payment details themselves never reach our servers — Apple StoreKit and Stripe handle billing.
  • Postal mail — if you enable the Digital Postal Service, physical mail addressed to your CyberMail postal box is photographed by our postal partner (currently Stable.com) and the images plus OCR text are stored linked to your account.
  • Wallet-to-wallet messages (XMTP) — message metadata (sender/recipient wallet addresses, conversation IDs) plus encrypted ciphertext stored on the XMTP network. We do not store XMTP plaintext on our servers.
  • BYOK API keys (encrypted at rest) — if you provide your own LLM provider API key (OpenAI, Anthropic, etc.), we encrypt it with AES-256-GCM under a server-side envelope key before storing. We use it only to route your AI requests to that provider on your behalf.
  • Settings & preferences — quiet hours, blocklists, AI provider choice, etc.
  • Crash reports — if you opt in, anonymous stack traces sent to Sentry. Default: off.

What we don't collect

  • Location data
  • Contacts from your phone's address book (we never read it)
  • Photos / camera / microphone access (we don't ask for permission)
  • Browsing history (the AI's optional web-fetch tool only fetches URLs you explicitly ask about, not your browsing history)
  • Cross-site identifiers
  • Advertising IDs (IDFA)
  • Financial information — Apple StoreKit (iOS) and Stripe (web/Android) process all payments. We see the transaction receipt for entitlement, never the card number.
  • Your wallet's private key or seed phrase (never)

What we don't do

  • Sell or rent your data to any third party
  • Use your data to train machine learning models we don't own
  • Show advertising
  • Track you across other apps or websites
  • Send your email or message contents to third-party LLM providers, except: (a) you explicitly chose a provider in Settings → AI, OR (b) you ask the brain a question that requires generation. Even then, providers we route through (Groq, OpenRouter, Anthropic, OpenAI via your BYOK) commit by contract not to train on the inputs of our customer workspace. On iOS 26+ with Apple Intelligence, the AI runs entirely on-device — nothing leaves your phone.

AI provider routing

When you use the AI brain, your prompt is routed through one of these providers in priority order:

  1. Apple Foundation Models (iOS 26+, on-device) — nothing leaves your phone
  2. Your own Ollama URL (if you set one) — runs on your hardware
  3. Groq free tier — Llama 3.3, Mixtral. Groq's terms forbid training on API inputs.
  4. OpenRouter free tier — various open-source models
  5. Your BYOK provider — you set the API key; the request goes directly to OpenAI/Anthropic/Google on your behalf
  6. Anthropic Claude (only Pro+ tier, capped monthly) — used only when all of the above fail

Billing

All billing is handled by the platform you signed up on (Apple App Store, Google Play, or our web checkout). Manage your account through that platform's billing settings. We do not store payment card details.

Digital Postal Service

If you enable Digital Postal, we provision a real U.S. street address through our postal partner (Stable.com). Physical mail sent to that address is photographed, optionally OCR'd, and uploaded to your CyberMail inbox. USPS Form 1583 (Authorization to Receive Mail for Another) is required by federal law before we can receive mail on your behalf — you complete it during onboarding. We retain scans for 90 days unless you request earlier deletion.

Who has access

  • You — full access via the app, web client at cybrmail.net, and your linked accounts
  • Our infrastructure team — encrypted-at-rest storage means even we cannot read message bodies of E2E-encrypted messages without your decryption key. Operational access to non-content metadata is restricted to incident response and logged.
  • Apple — App Store review (dedicated demo account provisioned per submission)
  • Stable.com (postal partner) — only if you enable Digital Postal. They see scanned mail; we re-ingest into your CyberMail inbox.
  • Stripe (payments processor) — sees your billing email, card details, and country. We never see the card details.
  • Your chosen AI providers — see "AI provider routing" above
  • Law enforcement — only with a valid subpoena or court order. We will notify you unless legally prohibited.

Data location

Application servers run on Hetzner Cloud (Germany / Helsinki). File storage for CyberDrive (when it ships in v1.2) is on Cloudflare R2 (region: WNAM/ENAM by default). Payment data is handled by Apple (their global regions) and Stripe (US + EU). XMTP messages are stored on the XMTP decentralized network.

Your rights (GDPR + CCPA + Brazil LGPD)

  • Access — request a copy of all data we have about you (Settings → Account → Export Data)
  • Rectify — fix any inaccurate info
  • Delete — permanently remove your account and all data (Settings → Account → Delete Account). This is irreversible. For wallet-only accounts the same flow applies.
  • Portability — export email + calendar + notes in standard formats (mbox + iCal + markdown)
  • Object — opt out of crash reporting, AI conversation history, and proactive intelligence at any time
  • Cancel subscription — at any time, no questions, no cancellation fee

To exercise any of these rights, use the app's built-in controls or email jrennie99@gmail.com. We respond within 30 days.

Children

CyberMail is not directed at children under 13 (US) or under 16 (EU) and we do not knowingly collect data from them. If you believe a minor has signed up, email jrennie99@gmail.com and we will delete the account immediately.

Changes

If we materially change this policy, we'll notify you in-app at least 30 days before the change takes effect. The most current version always lives at cybrmail.net/privacy. The changelog of this policy is available on request.

Contact

CyberMail is operated by AR Dynamics Inc, a Florida corporation. EU data subject representative: please email jrennie99@gmail.com for the current designated representative.