Privacy

What we store, how long we keep it, and who else can touch it. Written to be read rather than to be survived.

Last updated 12 September 2026

This is a draft, not a legal document.

It describes what the product actually does, which is the part we can state accurately. It has not been reviewed by a lawyer and is not yet binding on anyone. If you need a commitment in writing before trusting us with mail, write to legal@pidgeon.email and we will tell you honestly where this stands.

The short version

We host your email so that you can read it. We do not read it, train on it, sell it, or scan it to sell advertising. There is no version of this product where your correspondence is the thing being monetised.

What we store

The mail sent to and from your addresses, including attachments, because that is the service. Your account address, the domains you add, the addresses you create, and the keys and endpoints you configure. Operational records: which API calls were made, which webhooks were delivered, and which messages our spam classifier acted on.

How long we keep it

Messages and attachments stay until you delete them. Everything else expires on a schedule:

  • Raw copies of received mail — 30 days, or 1 year where our parser could not read the message cleanly and we keep it to fix that.
  • The event log — 90 days.
  • Notifications from our mail provider — 30 days.
  • Product analytics — 30 days.

Backups outlive those windows. Deleting a message removes it from the product immediately; a copy can persist in an encrypted backup for a further period until that backup rotates. Anyone who tells you otherwise about any hosted service is describing an architecture that does not exist.

Encryption, and what we cannot promise

Mail is encrypted in transit and at rest. It is not end-to-end encrypted, and this is a design decision rather than an omission: an API that hands your mail to your own code as plaintext, a spam classifier, and a server-side search index all require that we can read the message. You should assume we technically can, and hold us to not doing so.

Who else touches it

Our infrastructure providers, each for one job: hosting and delivery of mail, database and authentication, application hosting, error reporting, and product analytics. Data is held in the EU. A current list with each provider’s role belongs in this document and will be here before it stops being a draft.

Analytics, with the recording turned off

We measure whether the product works — did sign-up complete, did the domain verify — not what you do inside it. Session recording and autocapture are off, and the mail client is excluded from analytics entirely.

What you can ask for

A copy of your data, correction of it, or its deletion. IMAP and SMTP are available on every plan including the free one, so an export does not depend on us building a button: your own mail client can take everything with it. Write to privacy@pidgeon.email.