Skip to content
mailivy
Features Security Pricing Help
Sign in Create account
Features Security Pricing Help
Sign in Create account
Terms of ServicePrivacy PolicyCookie PolicyAcceptable Use

Privacy Policy

Last updated 1 September 2026Applies to Mailivy AB and its apps
On this page
1Who we are2Information you give us3Information created when you use Mailivy4When you visit our website5What we never do6How we use your information7Who we share it with8Where your data is stored9How long we keep it10How we protect it11Your rights12California privacy rights13Children14Changes to this policy15Contact us

The short version

We collect as little as possible: enough to run your account and bill you.
Your stored mail is encrypted, and we can’t read it.
No ads, no tracking pixels, no selling data. Ever.
Your mail is stored in Sweden, under EU law.
You can see, export or delete your data at any time.
This summary isn’t legally binding. The full text below is.

1Who we are

In shortMailivy AB in Stockholm is responsible for your personal data, and this policy explains how we handle it.

This Privacy Policy explains how Mailivy AB (org. nr 559421-0187, Sveavägen 44, 111 34 Stockholm, Sweden) collects and uses personal data when you use Mailivy, our apps and the website at mailivy.com. Mailivy AB is the data controller for this processing.

Our Data Protection Officer can be reached at privacy@mailivy.com. If you use Mailivy through an organisation’s Business plan, that organisation controls the data in its accounts and we process it on its behalf, so please contact your administrator first.

2Information you give us

In shortYour name, your address, an optional recovery email and, on paid plans, billing details.
  • Account details: your first and last name, your Mailivy address, and any custom domains or aliases you create.
  • Recovery email: optional, and used only to help you back into your account and to send essential notices.
  • Sign-in credentials: we never store your password in readable form, only a salted one-way hash used to check it. Passkeys stay on your devices.
  • Billing details: for paid plans, your name, billing country, VAT number where relevant and payment method. Card details go straight to our payment processor; we only see the card type, last four digits and expiry date.
  • Support conversations: the messages you send us and any details you choose to include.
  • Imported mail: when you connect Gmail, Outlook or another IMAP account, we use the access you grant only to copy your messages, folders and contacts, and we delete that access when the import ends.

3Information created when you use Mailivy

In shortSome technical data is needed to deliver your mail. The contents of stored messages are encrypted and unreadable to us.

Message metadata: sender and recipient addresses, subject lines, timestamps, message size and delivery status. We need this to route and deliver mail, file it into Inbox, Updates, Receipts and Newsletters, and detect spam and abuse.

Message content: the bodies and attachments of stored messages are encrypted with keys derived from your password. We can’t read them, and we never scan them for advertising. Incoming mail is checked for malware and spam as it arrives, before it is encrypted and stored.

Device and log data: IP address, device type, operating system, app version and the time of sign-ins and key account events. We use this to keep your account secure, for example to show you recent sign-ins and alert you to unusual activity.

4When you visit our website

In shortOur website doesn’t use tracking cookies, third-party analytics or advertising networks.

When you visit mailivy.com, our hosting and security provider, Cloudflare, processes your IP address, browser type, the page you request and the time of the request. This is needed to deliver the page and protect the site from attacks, and these records are kept only for a short period.

The website sets no cookies of its own and loads no third-party analytics, advertising scripts, social media widgets or tracking pixels. Our fonts are served from our own domain, so your visit isn’t shared with font or advertising networks. Details are in our Cookie Policy.

5What we never do

In shortNo ads, no profiling and no selling your data.
  • We don’t show ads in Mailivy, and we don’t build advertising profiles.
  • We don’t sell, rent or trade personal data.
  • We don’t read your mail or use its contents for marketing of any kind.
  • We don’t put tracking pixels in our emails, and we strip spy pixels from incoming messages before they reach you.
  • We don’t use third-party analytics in the Mailivy apps.

6How we use your information

In shortTo run your account, keep it secure, help you when you ask and bill paid plans—and for nothing else.

We use personal data only for the purposes below, and only on the legal bases the GDPR allows:

PurposeData usedLegal basis
Creating and running your account, delivering and sorting mailAccount details, message metadata, encrypted contentPerformance of our contract with you
Keeping accounts and the Service secure, and preventing spam, fraud and abuseMessage metadata, device and log dataLegitimate interests (protecting users and the Service)
Taking payments and keeping accounting recordsBilling detailsContract; legal obligation under Swedish accounting law
Answering support requestsSupport conversations, account detailsContract; legitimate interests
Sending essential notices, such as security alerts and changes to our termsMailivy address, recovery emailContract; legal obligation
Sending optional product newsMailivy addressConsent, which you can withdraw at any time
Responding to legally valid requests from authoritiesOnly the data specifically requestedLegal obligation
Delivering and protecting the websiteIP address, browser dataLegitimate interests

Where we rely on legitimate interests, we have weighed them against your rights and freedoms. You can object at any time, as described in section 11.

7Who we share it with

In shortOnly with a few carefully chosen service providers, under strict contracts. Never with advertisers.

We share personal data only with the service providers we need to run Mailivy, and only under written agreements that meet the requirements of Article 28 of the GDPR:

  • Cloudflare, Inc. delivers the mailivy.com website, provides DNS and protects it from attacks.
  • Our payment processor takes payments for paid plans, handles card data and helps prevent payment fraud.

When you send a message, it is delivered to the recipient’s email provider, as email requires. A current list of our processors is available on request from privacy@mailivy.com.

Legal requests. We disclose data to authorities only when a request is legally valid under Swedish law, and we challenge requests that are not. Because stored mail is encrypted, we can’t hand over its content. Where the law allows, we notify the affected user, and we publish a transparency report every year.

Business transfers. If Mailivy AB is involved in a merger, acquisition or sale of assets, personal data may pass to the new owner, who will be bound by this policy. We’ll tell you before that happens.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

8Where your data is stored

In shortYour mail is stored in Sweden. When a provider handles data outside the EU, approved safeguards protect it.

All mail and account data is stored on our own infrastructure in data centres in Stockholm and Gothenburg, Sweden. Encrypted backups also stay within the EU.

Some of our providers, such as Cloudflare and our payment processor, may process limited data outside the European Economic Area, including in the United States. When they do, we rely on an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses with additional safeguards. You can ask us for a copy of these safeguards.

9How long we keep it

In shortOnly as long as we need it. Your mail stays until you delete it.
DataHow long we keep itWhy
Mail, contacts and filesUntil you delete them or close your accountTo provide the Service
Closed accountsErased within 30 days, and from backups within 90 daysTo allow recovery from accidental deletion
Unused free accountsClosed after 24 months without a sign-in, following two warning emailsTo limit the data we hold
Messages from blocked senders30 daysSo you can undo a block
Sign-in and security logs12 monthsAccount security and abuse prevention
Website request recordsA short period, normally no more than 30 daysDelivering and protecting the website
Support conversations2 years after the conversation endsTo help with follow-up questions
Billing records7 yearsRequired by Swedish accounting law

10How we protect it

In shortEncryption, strict access controls and independent audits every year.
  • Zero-access encryption: stored messages are encrypted with AES-256 using keys derived from your password.
  • Encryption in transit: TLS on our website, apps and mail servers.
  • Strong sign-in: passkeys, hardware security keys and authenticator apps on every plan, free.
  • Limited staff access: only the people who need it, protected by hardware keys, with every access logged.
  • Independent audits: third-party security reviews every year, with the reports published.

If a personal data breach is likely to put your rights at risk, we will notify IMY within 72 hours and tell affected users without undue delay.

11Your rights

In shortYou can see, correct, export or delete your data, and object to how we use it.

If you are in the EU, EEA or UK, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete your data (the “right to be forgotten”);
  • restrict how we process your data in certain cases;
  • export your data in a portable, machine-readable format;
  • object to processing based on our legitimate interests;
  • withdraw consent at any time, where we rely on consent.

Most of these can be done directly in Settings → Privacy. For anything else, write to privacy@mailivy.com. We’ll reply within one month and may ask you to confirm your identity first. Exercising your rights is free.

You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the data protection authority where you live or work.

12California privacy rights

In shortCalifornia residents have extra rights under the CCPA and CPRA. We don’t sell or share your personal information.

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to:

  • know what personal information we collect, use and disclose, and why;
  • delete personal information we hold about you;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information, although we don’t sell or share it;
  • limit the use of sensitive personal information, which we only use to provide the Service;
  • not be discriminated against for exercising any of these rights.

In the past 12 months we have collected the following categories of personal information:

CategoryExamplesCollectedSold or shared
IdentifiersName, Mailivy address, recovery email, IP addressYesNo
Customer recordsBilling name, billing country, card type and last four digitsPaid plans onlyNo
Commercial informationPlan and payment historyPaid plans onlyNo
Internet or network activitySign-in times, device type, app versionYesNo
Electronic communicationsMessage metadata; message content is encrypted and unreadable to usYesNo
Sensitive personal informationAccount sign-in credentials, stored only as a hashYesNo
Geolocation, biometric data or profiling inferences—NoNo

To make a request, email privacy@mailivy.com with the subject “California privacy request”. You may also use an authorised agent. We’ll verify your request and respond within 45 days.

13Children

In shortMailivy isn’t for children under 16.

Mailivy is not directed at children. You must be at least 16, or the age of digital consent in your country if that is higher, to create an account, and we don’t knowingly collect personal data from anyone younger. If you believe a child has created an account, write to privacy@mailivy.com and we’ll delete the account and its data.

14Changes to this policy

In shortIf something important changes, we’ll email you 30 days before it applies.

We may update this policy when the Service or the law changes. If a change is material, we’ll email you at least 30 days before it takes effect and show a notice in the apps. The “Last updated” date at the top shows when this policy last changed, and previous versions are available on request.

15Contact us

In shortQuestions about your privacy? Our Data Protection Officer will answer.

For any question about this policy or your personal data, contact our Data Protection Officer at privacy@mailivy.com, or write to Mailivy AB, Attn: Data Protection Officer, Sveavägen 44, 111 34 Stockholm, Sweden.

Questions about this document?
Write to legal@mailivy.com, or Mailivy AB, Sveavägen 44, 111 34 Stockholm, Sweden.
Email legal team
mailivy

Private email from Stockholm. Funded by subscribers, not advertisers.

Product
FeaturesSecurityPricingDownload
Support
Help centreImport mailService statusContact
Legal
Terms of ServicePrivacy PolicyCookie PolicyAcceptable Use
© 2026 Mailivy AB · Org. nr 559421-0187English (UK)