Transparency
What we've been asked for, what we handed over, and a canary we update on a fixed schedule. Operated from European Union.
Last updated 2026-07-06
If this statement is not updated on schedule, or disappears, treat it as a signal. (In production this page carries a PGP-signed version.)
What a valid request actually yields
Because signup needs no identity and we keep almost nothing (see everything we store), a valid legal request typically yields little or nothing: there's no name, no IP, and no message content to hand over. Our full policy is on the abuse & law-enforcement page.
There is no IP log to hand over
Most services answering a subpoena reach for connection logs: who connected, from where, when. We have none. Your IP is used in memory to accept and route mail and is never written to our database, never attached to your account or aliases, and scrubbed from operational logs, and we keep no per-request web access log at all. We also strip the sender's originating IP out of every message before forwarding it.
That matters more than a promise not to look. A policy can change with a board meeting; data that was never recorded cannot be produced later, by us or by anyone who compels us.
Being precise, because a vague "we log nothing" would be untrue for any email service: we cannot refuse to process a routing IP (email requires accepting a connection), but we refuse to keep it. The full reasoning, including what our mail server and OS are configured to discard, is on the privacy page.