Privacy Policy
Last updated August 17, 2026
This Privacy Policy explains what snailworkmail ("we") collects, why, and how it is used. It covers snailworkmail.com and its subdomains, including the webmail console.
Running an email service means holding correspondence, which is among the most sensitive data a person keeps. The short version: we store your mail so we can deliver it to you, we do not read it, and we do not monetise it.
1. What we collect
- Account data — the email address you signed up with, a hashed password (or, if you use Google Sign-In, the immutable Google account identifier), your name, and your interface language.
- Domain and mailbox configuration — the domains you connect, the addresses and aliases you create, and the results of the DNS checks we run against them.
- Mail content — the messages sent to and from your addresses, including headers, bodies, and attachments. Original messages are stored as received so we can always re-read them accurately.
- Delivery metadata — sending counts, bounce and complaint events reported by our upstream provider, spam scores, and SPF/DKIM/DMARC results. Used to enforce limits and protect deliverability.
- Server logs — standard web and mail server logs kept for security and debugging, rotated on a short schedule. SMTP logs include the connecting IP address of the sending server.
2. What we do not do
We do not read your mail. We do not scan it to build advertising profiles, we do not sell or share it, and we do not use it as training data. Automated processing is limited to operating the Service: spam and authentication checks at delivery time, conversation threading, search indexing within your own account, and storage accounting.
3. Cookies and third-party services
- Session cookie — an essential, httpOnly cookie that keeps you signed in. No advertising or tracking cookies are set in the webmail console.
- Google Analytics — usage analytics on the snailworkmail.com marketing site.
- Google Sign-In — optional. We request only your basic profile and email address; we never gain access to your Google mail or files.
- Paddle — our payment provider and merchant of record. When you upgrade, Paddle collects your payment and billing details under its own privacy policy; we never see your card number.
- Amazon Web Services — our infrastructure provider. Mail and attachments are stored in the AWS Seoul (ap-northeast-2) region.
- Amazon SES — used to send outbound mail and verification emails.
Remote images in messages you receive are blocked by default, so opening an email does not silently report back to its sender.
4. How we use data
To operate the Service (authentication, mail delivery, search), to prevent abuse (sending limits, spam filtering, suspension of accounts with high bounce or complaint rates), to process payments, and to provide support when you ask for it. Support staff access account configuration, not message contents, unless you explicitly ask us to look at a specific message to diagnose a problem.
5. Retention
Account and configuration data is kept while your account exists. On the free plan, messages older than 90 days may be deleted; on the paid plan there is no retention limit. Deleting a mailbox or a domain deletes its mail from our storage. Server logs are rotated on a short schedule. Delivery-event records are kept as long as needed to enforce limits and investigate abuse.
6. Your rights
You can read, export, and delete your mail from the console at any time. To delete your account and all associated data, or to exercise any data-protection right available under your local law, contact us and we will act within a reasonable period.
7. Changes and contact
We may update this policy; the date above reflects the latest revision. Contact: support@snailworkmail.com.