Privacy Policy
We do not sell personal data, and we do not log or store IP addresses.
01 Summary
Elektrine does not sell personal data.
We keep only data needed to run the account and stop abuse.
We do not keep content-level traffic logs of your browsing or mail bodies for marketing.
02 Registration
Normal signup uses a username and password. A real legal name is not required.
Optional recovery email is for account recovery only.
03 Data we store
Account
- Username, password hash, and security settings
- Optional recovery email if you set one
- Profile fields you publish, such as display name, avatar, and bio
- Preferences such as locale, theme, and notifications
- No IP address. Clearnet open signups store a sign-up source token: a keyed hash that cannot be turned back into an address and becomes meaningless within two weeks (not recorded for Tor or I2P, or for invite/payment access-gated signups)
- Login time and count
Your content
- Mail, posts, chats, files, and other content you create or receive
- Mailbox and message metadata needed for delivery and folders
Sessions and device records
Signed-in browser sessions store technical metadata so you can review and revoke them.
- Coarse browser/device labels and last-seen; raw browser user-agent strings are discarded
- No IP address is stored for any session or trusted device
- On Tor or I2P: no user agent is stored either
Security and abuse control
In-memory and short operational records stop attacks and spam.
- Failed login and rate-limit counters, kept only in memory and keyed by a hash of the source rather than the address
- Connection counters for mail protocols when needed to stop abuse
- Spam and malware signals on mail paths
Page and profile view counts
Elektrine counts page and profile views as daily totals. No record of an individual visit is kept.
- Stored per day: view counts per page, profile, and site, and the names of referring sites
- Not stored: IP addresses, user agents, cookies or visitor IDs, account IDs, or full referrer URLs
- Unique visitors are counted with a hash salted by a random value that exists for one day. The salt and the day's hashes are deleted when the day ends, so no count links back to a person
- No third-party analytics or advertising trackers
04 Log policy
What we do not keep
- We do not keep permanent content logs of web browsing through the product UI for profiling
- We do not sell logs or traffic data
- We do not build advertising profiles from private mail or private chats
IP addresses
Elektrine does not log or store IP addresses. Not in application logs, the database, audit records, sessions, API tokens, app passwords, passkeys, VPN records, or mail metadata.
Abuse limits that must recognise a repeat source use a keyed hash of it. In-memory limits use a key that never leaves memory. The one stored value, the sign-up source token, uses a key that is replaced every week and deleted after two, so older tokens cannot be linked to anything.
- Tor/onion and I2P: not even a source token is recorded, and no user-agent
- Invite- or payment-gated registration: no sign-up source token
- Account deletion immediately clears the sign-up source token, revokes sessions and API tokens, and deletes the view counts for that user's profile
Operational logs
Elektrine may also keep host or process logs outside the application database. Those follow Elektrine's infrastructure retention schedule.
- Mail delivery status needed to fix bounce and spam issues (not full SMTP session history by default)
- Error traces for server faults, without private message bodies when avoidable
VPN
VPN traffic contents are not logged.
Default: no durable connect or disconnect history and no client source IP on session rows.
WireGuard peers live in node memory. Aggregate bandwidth counters may remain for free-tier limits.
See the VPN Policy for full detail.
05 Mail and encryption
Mail uses open internet protocols. Delivery exposes envelope data to mail servers on the path.
Stored mail bodies use application encryption at rest by default.
Default: no second RFC822 copy and no connecting MTA IP on message metadata.
Admin tools do not decrypt mail or chat bodies.
Trash and spam are hard-deleted after a short retention window by default.
Private mailbox mode can lock more fields to a browser passphrase. Operational flags still stay on the server.
Use PGP or similar tools if you need end-to-end content protection outside Elektrine.
06 How we use data
- Run email, chat, social, DNS, VPN, and other enabled modules
- Authenticate accounts and stop abuse
- Fix faults and keep the service online
- Answer support requests you send
07 Sharing
We do not sell personal data.
- We share data when you send it, for example mail to another provider or a public post
- Infrastructure vendors process data only to host and deliver the service under our control
- Mail delivery uses the public SMTP ecosystem by design
- We disclose data when law requires a valid order
- We act to stop active abuse, fraud, or direct harm
08 Cookies
- Session cookies for login
- CSRF and security tokens
- Local preferences such as theme
- Private mailbox unlock state in the current browser when you unlock it
09 Retention and deletion
Account and content stay while the account is active.
IP addresses are never stored, as described under Log policy.
You may delete content and the account in settings where the product supports it.
Backups and infrastructure logs follow Elektrine's backup and log rotation schedule after deletion.
10 Your choices
- Export or delete account data where the product supports it
- Change privacy and notification settings
- Contact privacy support for requests the UI cannot complete
11 Children
The service is not for children under 13.
We do not knowingly collect personal data from children under 13.
12 Canary and transparency
Elektrine publishes a signed warrant canary at /canary.
A transparency report of legal requests is published at /transparency.
13 Changes
Elektrine may update this policy.
Material changes appear on this page. Important changes may also use in-app notice.
14 Contact
Privacy requests: privacy@elektrine.com