redd.email

Privacy Policy

redd.email hosts your mail. That means we hold the contents of your mailbox, so it matters that you know exactly what we keep, who we share it with, and how to get rid of it.

Effective July 31, 2026

1. Who this covers

This policy describes how redd.email (“we”, “us”) handles personal information when you use the redd.email website, mobile apps, and mail servers (together, the “Service”). It applies to account holders, to people invited to claim a mailbox, and to visitors of https://redd.email.

It does not cover mail you send to or receive from people outside redd.email. Once a message leaves our servers it is governed by the receiving provider’s policies, not this one.

2. Information we collect

Information you give us

  • Your phone number. redd.email has no email-and-password sign-in. Your phone number is your account identifier and is verified by a one-time SMS code every time you sign in on a new device.
  • A display name, if you set one, plus any other profile details you choose to enter.
  • Domains and mailbox names you register or connect, and the DNS records we create to make mail work on them.
  • Phone numbers of people you invite. If you administer a domain and invite someone to claim a mailbox on it, you give us their number so we can text them the claim link.

Your mail

  • Message content. We store the messages you send and receive in full — sender and recipient addresses, subject lines, message bodies, headers, and attachments — along with the original raw message as it arrived. This is not incidental; storing your mail is the product.
  • Drafts you have not sent yet, and read/unread and folder state.

Information collected automatically

  • Session cookies that keep you signed in. We do not use advertising or tracking cookies, and we run no third-party analytics or advertising scripts on the site.
  • App passwords. When you connect Apple Mail or another IMAP client, we generate a password, show it to you once, and store only a bcrypt hash of it.
  • Device push tokens from your phone or browser, so we can notify you about new mail, plus the platform (iOS, Android, or web) each token belongs to.
  • Server and connection logs generated by our hosting providers, which can include IP addresses, timestamps, and error diagnostics.

Payment information

Paid plans and domain registrations are processed by Stripe. Stripe collects and holds your card details directly — we never see or store a full card number. We keep the resulting subscription and order status so we know what your account is entitled to.

3. How we use it

  • To deliver, store, sync, and search your mail, and to run spam and abuse protection.
  • To authenticate you, including sending one-time sign-in codes by SMS.
  • To notify you about new mail on devices where you have enabled notifications.
  • To register and configure the domains you ask us to set up.
  • To bill you, and to send account and service notices you need to receive.
  • To investigate abuse, security incidents, or violations of the Terms of Use.
  • To comply with the law.

4. What we do not do

  • We do not sell or rent your personal information, and we never have.
  • We do not show ads, and we do not read or profile your mail to target advertising.
  • We do not use the contents of your mailbox to train machine learning models.
  • We do not share your mail with anyone except the providers below or as Section 8 requires.

5. Service providers

The Service is assembled from infrastructure we do not own. These providers process data on our instructions, and each holds only the slice listed here:

ProviderRoleWhat it holds
SupabaseDatabase, file storage, authenticationYour account, mail, attachments, and raw messages
CloudflareInbound routing, outbound sending, DNS, domain registrationMessages in transit, domain and DNS records
Fly.ioIMAP and SMTP gateway for mail appsMessages in transit to and from your mail client
VercelWeb app hostingRequest logs
TwilioSign-in verification codesYour phone number and code delivery status
StripePaymentsYour payment details and billing history
Apple and GooglePush notification deliveryDevice tokens and notification content

Mailbox invitations are sent through a messaging relay we operate ourselves rather than through Twilio.

6. Text messages

We send SMS for two reasons only: one-time codes when you sign in, and a single invitation message when a domain administrator creates a mailbox for you. We do not send marketing texts. Message and data rates may apply. If you invite someone by phone number, you are confirming that you have their permission to have us text them.

7. Security, and what it does not cover

Traffic to the website, to our mail servers, and between our providers is encrypted with TLS. Stored mail and attachments are encrypted at rest by our storage providers. Access to production data is limited to the people who operate the Service, and app passwords are stored only as hashes.

To be direct about the limit: redd.email is not end-to-end encrypted. Because we store mail in a form the web app and your mail client can read, we hold the keys and are technically capable of reading it, and we can be compelled to produce it. If you need mail that no provider can read, use message-level encryption such as PGP on top of the Service.

Email itself is an old and leaky protocol. We cannot guarantee that a message is encrypted after it leaves us for another provider, and no system is perfectly secure.

8. When we disclose information

We disclose personal information outside the providers in Section 5 only when:

  • you ask us to, or you direct it (for example, by sending a message to someone);
  • we are required by law — a valid subpoena, warrant, or court order;
  • it is necessary to investigate suspected fraud, abuse, or a threat to someone’s safety or to the integrity of the Service; or
  • the Service is sold or transferred, in which case your information moves with it and this policy continues to apply until you are given notice of a replacement.

Where the law allows it, we will try to tell you before handing over your data in response to a legal request.

9. Retention and deletion

  • Mail is kept until you delete it. Deleting a message removes it from your mailbox; copies may persist in encrypted backups for up to 30 days before they age out.
  • Accounts. Write to support@redd.email from your redd.email address and we will delete your account, mail, attachments, app passwords, and push tokens within 30 days.
  • Billing records are kept as long as tax and accounting law requires, even after an account is deleted.
  • Logs are retained on our providers’ default schedules, generally under 90 days.
  • Domains you registered are yours. Deleting your account does not cancel a domain registration; tell us if you want it transferred out or allowed to lapse.

10. Your choices

  • Access and export. Connect any IMAP client to download a complete copy of your mail, or ask us for an export.
  • Correction. Update your display name and profile in the app at any time.
  • Deletion. Delete individual messages in the app, or ask us to delete the whole account.
  • Notifications. Turn off push notifications in your device settings; revoke app passwords in the app.

Depending on where you live, you may also have the right to know what we hold, to object to certain processing, or to complain to a data protection authority. We honor these requests regardless of where you live. We will not charge you or degrade your service for exercising them. Write to support@redd.email and we will respond within 30 days.

11. Children

redd.email is not intended for children under 13, and we do not knowingly collect their information. If you believe a child has created an account, contact us and we will remove it.

12. Where your data lives

Our providers store and process data in the United States. If you use the Service from elsewhere, you are sending your information to the United States, where privacy law differs from your own.

13. Changes

We may update this policy. If a change materially affects how we handle your information, we will notify you by email or in the app before it takes effect, and we will update the effective date at the top of this page.

14. Contact

Questions, requests, or complaints: support@redd.email.

Read the Terms of Use
© redd.email·Privacy·Terms