The short version
1Who we are
This Privacy Policy explains how Mailivy AB (org. nr 559421-0187, Sveavägen 44, 111 34 Stockholm, Sweden) collects and uses personal data when you use Mailivy, our apps and the website at mailivy.com. Mailivy AB is the data controller for this processing.
Our Data Protection Officer can be reached at privacy@mailivy.com. If you use Mailivy through an organisation’s Business plan, that organisation controls the data in its accounts and we process it on its behalf, so please contact your administrator first.
2Information you give us
- Account details: your first and last name, your Mailivy address, and any custom domains or aliases you create.
- Recovery email: optional, and used only to help you back into your account and to send essential notices.
- Sign-in credentials: we never store your password in readable form, only a salted one-way hash used to check it. Passkeys stay on your devices.
- Billing details: for paid plans, your name, billing country, VAT number where relevant and payment method. Card details go straight to our payment processor; we only see the card type, last four digits and expiry date.
- Support conversations: the messages you send us and any details you choose to include.
- Imported mail: when you connect Gmail, Outlook or another IMAP account, we use the access you grant only to copy your messages, folders and contacts, and we delete that access when the import ends.
3Information created when you use Mailivy
Message metadata: sender and recipient addresses, subject lines, timestamps, message size and delivery status. We need this to route and deliver mail, file it into Inbox, Updates, Receipts and Newsletters, and detect spam and abuse.
Message content: the bodies and attachments of stored messages are encrypted with keys derived from your password. We can’t read them, and we never scan them for advertising. Incoming mail is checked for malware and spam as it arrives, before it is encrypted and stored.
Device and log data: IP address, device type, operating system, app version and the time of sign-ins and key account events. We use this to keep your account secure, for example to show you recent sign-ins and alert you to unusual activity.
4When you visit our website
When you visit mailivy.com, our hosting and security provider, Cloudflare, processes your IP address, browser type, the page you request and the time of the request. This is needed to deliver the page and protect the site from attacks, and these records are kept only for a short period.
The website sets no cookies of its own and loads no third-party analytics, advertising scripts, social media widgets or tracking pixels. Our fonts are served from our own domain, so your visit isn’t shared with font or advertising networks. Details are in our Cookie Policy.
5What we never do
- We don’t show ads in Mailivy, and we don’t build advertising profiles.
- We don’t sell, rent or trade personal data.
- We don’t read your mail or use its contents for marketing of any kind.
- We don’t put tracking pixels in our emails, and we strip spy pixels from incoming messages before they reach you.
- We don’t use third-party analytics in the Mailivy apps.
6How we use your information
We use personal data only for the purposes below, and only on the legal bases the GDPR allows:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account, delivering and sorting mail | Account details, message metadata, encrypted content | Performance of our contract with you |
| Keeping accounts and the Service secure, and preventing spam, fraud and abuse | Message metadata, device and log data | Legitimate interests (protecting users and the Service) |
| Taking payments and keeping accounting records | Billing details | Contract; legal obligation under Swedish accounting law |
| Answering support requests | Support conversations, account details | Contract; legitimate interests |
| Sending essential notices, such as security alerts and changes to our terms | Mailivy address, recovery email | Contract; legal obligation |
| Sending optional product news | Mailivy address | Consent, which you can withdraw at any time |
| Responding to legally valid requests from authorities | Only the data specifically requested | Legal obligation |
| Delivering and protecting the website | IP address, browser data | Legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and freedoms. You can object at any time, as described in section 11.
7Who we share it with
We share personal data only with the service providers we need to run Mailivy, and only under written agreements that meet the requirements of Article 28 of the GDPR:
- Cloudflare, Inc. delivers the mailivy.com website, provides DNS and protects it from attacks.
- Our payment processor takes payments for paid plans, handles card data and helps prevent payment fraud.
When you send a message, it is delivered to the recipient’s email provider, as email requires. A current list of our processors is available on request from privacy@mailivy.com.
Legal requests. We disclose data to authorities only when a request is legally valid under Swedish law, and we challenge requests that are not. Because stored mail is encrypted, we can’t hand over its content. Where the law allows, we notify the affected user, and we publish a transparency report every year.
Business transfers. If Mailivy AB is involved in a merger, acquisition or sale of assets, personal data may pass to the new owner, who will be bound by this policy. We’ll tell you before that happens.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
8Where your data is stored
All mail and account data is stored on our own infrastructure in data centres in Stockholm and Gothenburg, Sweden. Encrypted backups also stay within the EU.
Some of our providers, such as Cloudflare and our payment processor, may process limited data outside the European Economic Area, including in the United States. When they do, we rely on an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses with additional safeguards. You can ask us for a copy of these safeguards.
9How long we keep it
| Data | How long we keep it | Why |
|---|---|---|
| Mail, contacts and files | Until you delete them or close your account | To provide the Service |
| Closed accounts | Erased within 30 days, and from backups within 90 days | To allow recovery from accidental deletion |
| Unused free accounts | Closed after 24 months without a sign-in, following two warning emails | To limit the data we hold |
| Messages from blocked senders | 30 days | So you can undo a block |
| Sign-in and security logs | 12 months | Account security and abuse prevention |
| Website request records | A short period, normally no more than 30 days | Delivering and protecting the website |
| Support conversations | 2 years after the conversation ends | To help with follow-up questions |
| Billing records | 7 years | Required by Swedish accounting law |
10How we protect it
- Zero-access encryption: stored messages are encrypted with AES-256 using keys derived from your password.
- Encryption in transit: TLS on our website, apps and mail servers.
- Strong sign-in: passkeys, hardware security keys and authenticator apps on every plan, free.
- Limited staff access: only the people who need it, protected by hardware keys, with every access logged.
- Independent audits: third-party security reviews every year, with the reports published.
If a personal data breach is likely to put your rights at risk, we will notify IMY within 72 hours and tell affected users without undue delay.
11Your rights
If you are in the EU, EEA or UK, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data (the “right to be forgotten”);
- restrict how we process your data in certain cases;
- export your data in a portable, machine-readable format;
- object to processing based on our legitimate interests;
- withdraw consent at any time, where we rely on consent.
Most of these can be done directly in Settings → Privacy. For anything else, write to privacy@mailivy.com. We’ll reply within one month and may ask you to confirm your identity first. Exercising your rights is free.
You also have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the data protection authority where you live or work.
12California privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to:
- know what personal information we collect, use and disclose, and why;
- delete personal information we hold about you;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information, although we don’t sell or share it;
- limit the use of sensitive personal information, which we only use to provide the Service;
- not be discriminated against for exercising any of these rights.
In the past 12 months we have collected the following categories of personal information:
| Category | Examples | Collected | Sold or shared |
|---|---|---|---|
| Identifiers | Name, Mailivy address, recovery email, IP address | Yes | No |
| Customer records | Billing name, billing country, card type and last four digits | Paid plans only | No |
| Commercial information | Plan and payment history | Paid plans only | No |
| Internet or network activity | Sign-in times, device type, app version | Yes | No |
| Electronic communications | Message metadata; message content is encrypted and unreadable to us | Yes | No |
| Sensitive personal information | Account sign-in credentials, stored only as a hash | Yes | No |
| Geolocation, biometric data or profiling inferences | — | No | No |
To make a request, email privacy@mailivy.com with the subject “California privacy request”. You may also use an authorised agent. We’ll verify your request and respond within 45 days.
13Children
Mailivy is not directed at children. You must be at least 16, or the age of digital consent in your country if that is higher, to create an account, and we don’t knowingly collect personal data from anyone younger. If you believe a child has created an account, write to privacy@mailivy.com and we’ll delete the account and its data.
14Changes to this policy
We may update this policy when the Service or the law changes. If a change is material, we’ll email you at least 30 days before it takes effect and show a notice in the apps. The “Last updated” date at the top shows when this policy last changed, and previous versions are available on request.
15Contact us
For any question about this policy or your personal data, contact our Data Protection Officer at privacy@mailivy.com, or write to Mailivy AB, Attn: Data Protection Officer, Sveavägen 44, 111 34 Stockholm, Sweden.