redd.email

Privacy Policy

redd.email hosts your mail. That means we hold the contents of your mailbox, so it matters that you know exactly what we keep, who we share it with, and how to get rid of it.

Effective August 16, 2026

1. Who this covers

This policy describes how redd.email (“we”, “us”) handles personal information when you use the redd.email website, mobile apps, and mail servers (together, the “Service”). It applies to account holders, to people invited to claim a mailbox, and to visitors of https://redd.email.

It does not cover mail you send to or receive from people outside redd.email. Once a message leaves our servers it is governed by the receiving provider’s policies, not this one.

2. Information we collect

Information you give us

  • Your phone number. redd.email has no email-and-password sign-in. Your phone number is your account identifier and is verified by a one-time SMS code every time you sign in on a new device.
  • A display name, if you set one, plus any other profile details you choose to enter.
  • Domains and mailbox names you register or connect, and the DNS records we create to make mail work on them.
  • Phone numbers of people you invite. If you administer a domain and invite someone to claim a mailbox on it, you give us their number so we can text them the claim link.

Your mail

  • Message content. We store the messages you send and receive in full — sender and recipient addresses, subject lines, message bodies, headers, and attachments — along with the original raw message as it arrived. This is not incidental; storing your mail is the product.
  • Drafts you have not sent yet, and read/unread and folder state.

Information collected automatically

  • Session cookies that keep you signed in. We do not use advertising or tracking cookies, and we run no third-party analytics or advertising scripts on the site.
  • App passwords. When you connect Apple Mail or another IMAP client, we generate a password, show it to you once, and store only a bcrypt hash of it.
  • Device push tokens from your phone or browser, so we can notify you about new mail, plus the platform (iOS, Android, or web) each token belongs to.
  • Server and connection logs generated by our hosting providers, which can include IP addresses, timestamps, and error diagnostics.

Payment information

Paid plans and domain registrations are processed by Stripe. Stripe collects and holds your card details directly — we never see or store a full card number. We keep the resulting subscription and order status so we know what your account is entitled to.

3. How we use it

  • To deliver, store, sync, and search your mail, and to run spam and abuse protection.
  • To authenticate you, including sending one-time sign-in codes by SMS.
  • To notify you about new mail on devices where you have enabled notifications.
  • To register and configure the domains you ask us to set up.
  • To bill you, and to send account and service notices you need to receive.
  • To investigate abuse, security incidents, or violations of the Terms of Use.
  • To comply with the law.

4. What we do not do

  • We do not sell or rent your personal information, and we never have.
  • No mobile information is sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party except the messaging provider that delivers the message on our behalf.
  • We do not show ads, and we do not read or profile your mail to target advertising.
  • We do not use the contents of your mailbox to train machine learning models.
  • We do not share your mail with anyone except the providers below or as Section 8 requires.

5. Service providers

The Service is assembled from infrastructure we do not own. These providers process data on our instructions, and each holds only the slice listed here:

ProviderRoleWhat it holds
SupabaseDatabase, file storage, authenticationYour account, mail, attachments, and raw messages
CloudflareInbound routing, outbound sending, DNS, domain registrationMessages in transit, domain and DNS records
Fly.ioIMAP and SMTP gateway for mail appsMessages in transit to and from your mail client
VercelWeb app hostingRequest logs
TwilioSign-in verification codesYour phone number and code delivery status
StripePaymentsYour payment details and billing history
Apple and GooglePush notification deliveryDevice tokens and notification content

Mailbox invitations are sent through a messaging relay we operate ourselves rather than through Twilio.

6. Text messages

We send four kinds of text message, and you switch each one on yourself. Nothing here is bundled: two of the four are unchecked boxes you have to tick, and creating an account enrolls you in none of them. Full program details, including the exact consent wording for each, are in our SMS Terms.

  • Sign-in passcodes. When you type your own number into https://redd.email/login and tap “Text me a code,” that action is your consent, and we text you a one-time passcode. Frequency is one message per sign-in request — you control it, because nothing is sent unless you ask.
  • Account and security alerts, if you tick that box under Profile → Text messages: sign-ins from a new device, app passwords created or revoked, domain and DNS changes, and billing problems that could interrupt your mail. Up to about 4 messages per month.
  • Product news, if you tick that box: new features, service updates, and occasional offers. Up to about 2 messages per month. This is the only promotional message we send, it is off unless you turn it on, and agreeing to it is never a condition of buying anything.
  • Mailbox invitations. If you administer a domain and create a mailbox for someone, we send that person a single message with a link to claim it. Entering their number is your confirmation that you have their permission to have us text them. These invitations are sent through a messaging relay we operate ourselves, not through Twilio.

Message and data rates may apply. Reply STOP to any message to opt out of every text from us, or HELP for help; you can also untick an individual box under Profile → Text messages, or write to support@redd.email. A blanket STOP also stops your sign-in codes, which means you will not be able to sign in until you opt back in.

When you tick or untick one of those boxes we record the change — what the checkbox said at the time, when you changed it, and the IP address and browser it came from. We keep that record for as long as you have an account, and for three years afterward, because it is the evidence that we had your permission. It is never used for anything else.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party except the messaging provider that delivers the message on our behalf.

7. Security, and what it does not cover

Traffic to the website, to our mail servers, and between our providers is encrypted with TLS. Stored mail and attachments are encrypted at rest by our storage providers. Access to production data is limited to the people who operate the Service, and app passwords are stored only as hashes.

To be direct about the limit: redd.email is not end-to-end encrypted. Because we store mail in a form the web app and your mail client can read, we hold the keys and are technically capable of reading it, and we can be compelled to produce it. If you need mail that no provider can read, use message-level encryption such as PGP on top of the Service.

Email itself is an old and leaky protocol. We cannot guarantee that a message is encrypted after it leaves us for another provider, and no system is perfectly secure.

8. When we disclose information

We disclose personal information outside the providers in Section 5 only when:

  • you ask us to, or you direct it (for example, by sending a message to someone);
  • we are required by law — a valid subpoena, warrant, or court order;
  • it is necessary to investigate suspected fraud, abuse, or a threat to someone’s safety or to the integrity of the Service; or
  • the Service is sold or transferred, in which case your information moves with it and this policy continues to apply until you are given notice of a replacement.

Where the law allows it, we will try to tell you before handing over your data in response to a legal request.

9. Retention and deletion

  • Mail is kept until you delete it. Deleting a message removes it from your mailbox; copies may persist in encrypted backups for up to 30 days before they age out.
  • Accounts. Write to support@redd.email from your redd.email address and we will delete your account, mail, attachments, app passwords, and push tokens within 30 days.
  • Billing records are kept as long as tax and accounting law requires, even after an account is deleted.
  • Logs are retained on our providers’ default schedules, generally under 90 days.
  • Domains you registered are yours. Deleting your account does not cancel a domain registration; tell us if you want it transferred out or allowed to lapse.

10. Your choices

  • Access and export. Connect any IMAP client to download a complete copy of your mail, or ask us for an export.
  • Correction. Update your display name and profile in the app at any time.
  • Deletion. Delete individual messages in the app, or ask us to delete the whole account.
  • Notifications. Turn off push notifications in your device settings; revoke app passwords in the app.

Depending on where you live, you may also have the right to know what we hold, to object to certain processing, or to complain to a data protection authority. We honor these requests regardless of where you live. We will not charge you or degrade your service for exercising them. Write to support@redd.email and we will respond within 30 days.

11. Children

redd.email is not intended for children under 13, and we do not knowingly collect their information. If you believe a child has created an account, contact us and we will remove it.

12. Where your data lives

Our providers store and process data in the United States. If you use the Service from elsewhere, you are sending your information to the United States, where privacy law differs from your own.

13. Changes

We may update this policy. If a change materially affects how we handle your information, we will notify you by email or in the app before it takes effect, and we will update the effective date at the top of this page.

14. Contact

Questions, requests, or complaints: support@redd.email.

Read the Terms of UseRead the SMS Terms
© redd.email·Privacy·Terms·SMS Terms