Skip to content

Legal

Privacy Policy

Effective date: May 12, 2026

1. Who processes your data

The data controller within the meaning of the Personal Data Protection Act of Ukraine and the GDPR (for users in the EU) is Sole Proprietor Knysh Alla Oleksandrivna (Tax ID / RNOKPP: 3735804403, Ukraine, 08297, Kyiv Region, Bucha District, Bucha, Nove Highway 42) (Mailcraft, the Service).

For any questions about data processing please reach out to contact{'@'}mailcraft.org.

2. What data we collect

Account data: email address, name, hashed password, chosen interface language, registration and last-activity timestamps.

Payment data: top-up, order and charge amounts, transaction IDs from the payment provider. Mailcraft does not receive or store actual card or wallet details — those are processed exclusively by the payment processor (NowPayments, the acquiring bank).

Technical data: IP address, browser User-Agent, session cookies, action logs within the Service (mailbox creation, message opens, setting changes).

Mailbox content: incoming messages and their metadata (sender, subject, date) are stored on our mail servers and in the web cache. Message bodies are not stored in the main database and are read over IMAP on demand from the Client.

3. Why we process it

To deliver the paid service: creating and maintaining mailboxes, delivering incoming mail, billing and refunds.

To keep things secure: fraud prevention, protection from automated attacks, investigating abuse.

To comply with the law: responding to lawful requests from authorized government bodies as required by Ukrainian law.

4. Legal basis

The main grounds for processing are performance of the contract with the Client (Public Offer), the Service's legitimate interest in security and fraud prevention, and the consent given by the Client at sign-up.

5. Whom we share data with

Payment providers (NowPayments, Monobank Acquiring and the like) — to process transactions.

Infrastructure partners (hosting provider, domain registrar Cloudflare, server provider Hetzner / hostiq.ua) — to the extent necessary to run the Service.

Mailcraft does not sell personal data to third parties and does not share it for marketing on behalf of others.

6. Retention periods

Account data is retained while the account is active. If the account is deleted, the data is erased within 30 calendar days, except for information we are required by law to keep (for example, accounting records — 3 years).

Messages in Trial mailboxes are deleted after 30 days, in Standard mailboxes after 90 days. Messages in Premium mailboxes are retained while the account is active.

Action logs and technical logs are retained for up to 12 months and then automatically purged.

7. Cookies

Mailcraft uses only strictly necessary cookies: session identifiers for authentication, the chosen interface language and the CSRF protection token. There are no advertising or marketing cookies. Without strictly necessary cookies authentication is not possible.

8. Your rights

The Client has the right to request access to their personal data, correction, erasure, restriction of processing, and portability of the data in machine-readable form.

To exercise these rights send a request from the email registered on the account to contact{'@'}mailcraft.org. We will respond within 30 calendar days.

If you believe your rights have been violated you may file a complaint with the Ukrainian personal data protection authority or, if you reside in the EU, with your local supervisory authority.

9. Security

User passwords are stored as cryptographic hashes (bcrypt). IMAP mailbox passwords are encrypted using Laravel Crypt and are available only to the mailbox owner. Traffic between the browser and the Service is protected with TLS.

Despite these measures, no system can guarantee absolute security. We will notify affected users of any known personal-data incidents within the timeframes required by law.

10. Policy changes

The current version of this Policy is always available at /privacy. We will warn users by email at least 14 days before material changes take effect.

Questions? Email us at contact@mailcraft.org .