0wn.si
privacy policy · last updated 4 October 2026

What we know about you, and what we refuse to learn.

You pay us $9.99 a year to carry your mail. That is the entire relationship. We have no advertisers, no analytics and no model to feed, so we keep as little as a mail service can.

01who is responsible

0wn.si is run by 0wn.si (seller name not set), the data controller for everything described here.

seller: 0wn.si (seller name not set)
address: Street 1, 00-000 City
country: PL
VAT ID: PL0000000000
contact: billing@0wn.si

Privacy questions and requests: write to the contact address above from any address. We answer within 30 days, usually much sooner.

02the short version

  • No ads, no tracking, no analytics, no third-party scripts on our pages.
  • Your mail is never used to train a model. Not ours, not anyone’s.
  • Automated-sender detection works on headers and rules. Message bodies are never sent to a model.
  • Two first-party cookies. That is all of them.
  • You can export everything as mbox at any time, and delete the account whenever you like.

03what we store

account
your username, an Argon2id hash of your password (never the password), an optional recovery email, two-factor secrets (TOTP seed, hardware-key public keys, hashed recovery codes), your settings
mail
the messages in your mailbox and a search index of them, on the same encrypted volume. The index exists so search with wildcards is fast; it is deleted with the message
sessions
one record per signed-in device: IP address and browser user agent. You can see and revoke them in settings → account
sign-in history
time, IP address, user agent and outcome of sign-in attempts, to detect break-ins and to show you
billing
invoices, payment references and a ledger of what was paid. Card numbers never reach our servers
sender choices
what you tell us about senders: “this is a human”, “this is a machine”, “always load images”, your allow and block lists
logs
structured server logs with no message content and no personal data beyond a user id, kept for 30 days

We do not ask for your name, phone number, date of birth or postal address, and we have nowhere to put them.

04what we never do

  • Show ads, build an advertising profile, or sell, rent or share your data for marketing.
  • Run analytics or tracking on the website or in the inbox.
  • Train machine-learning models on your mail, or let anyone else do it.
  • Send read receipts. Nobody learns when, or whether, you opened a message.
  • Read your mail. Staff tools show account and billing data; they have no view of message content.

05how mail is processed

Incoming mail is checked on our own server: sender authentication (SPF, DKIM, DMARC, ARC), public blocklists, and a spam filter that scores the message with rules and statistics. Marking something as spam or not spam trains the filter for your mailbox.

Mail from automated senders is tagged “auto” using headers and rules only, such as List-Unsubscribe, Precedence, Auto-Submitted, no-reply addresses and known bulk-mail signing domains. Bodies are not analysed by a model, here or anywhere else.

When you open a message we remove tracking pixels and known tracker domains, strip link-tracking parameters (utm_*, fbclid, gclid and similar), and block remote images. If you choose to load images they are fetched through our proxy, so the sender sees our server and not you.

The longer account is on the how we handle your mail page.

06payments

Card payments are handled by Stripe. Card details go from your browser straight to Stripe; we receive a payment reference, the card brand and last four digits, and the result. Stripe is loaded only when you choose to pay by card.

Bitcoin and Lightning payments go through a BTCPay Server that we host ourselves. Payments in ETH, USDC and SOL are processed by NOWPayments, which sees the payment itself and nothing about your mailbox. Blockchains are public: a crypto payment is visible to anyone who knows the address.

07cookies

own_session
keeps you signed in to the inbox. httpOnly, first-party, set when you sign in
own_csrf
protects forms against cross-site request forgery. httpOnly, first-party, set when you start a checkout or open the inbox

There are no other cookies, no local tracking identifiers and no cookie banner, because there is nothing to consent to.

08who else touches your data

DigitalOcean
hosting: the server your mail lives on
S3-compatible storage
encrypted backups. The provider stores ciphertext and never holds the key
Stripe
card payments
NOWPayments
ETH, USDC and SOL payments

That is the complete list. Nobody on it receives your mail in readable form.

09how long things live

trash
purged automatically after 30 days
plan expiry
30 days of grace: mail still arrives, reading and export work, sending is off
after grace
the account is suspended and incoming mail is rejected
60 days later
the account and its mail are deleted. We email you at each step
account deletion
when you ask for it: 14 days to change your mind, then everything is deleted
backups
encrypted, kept 7 daily / 4 weekly / 6 monthly; deleted data ages out within 6 months
logs
30 days
billing records
as long as accounting law requires, typically five years

10security

Connections use TLS 1.2 or newer. Mail and the database sit on an encrypted disk. Passwords are hashed with Argon2id. Two-factor sign-in (authenticator app or hardware key) is available to everyone and mandatory for staff. Every staff action is written to an append-only audit log.

Mail between providers is only as private as the other side allows: we always offer TLS and publish MTA-STS, but a message to a provider without encryption travels unencrypted. For end-to-end secrecy use PGP or S/MIME in your own client.

11your rights

You can see, correct, export and delete your data yourself: settings shows what we hold, export gives you everything as mbox, and delete account removes it. If you are in the EU or the UK you also have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your data-protection authority.

We process your data to perform our contract with you (running your mailbox), to meet legal obligations (accounting records), and for our legitimate interest in keeping the service secure and free of abuse (sign-in history, rate limits, spam filtering).

12legal requests

We answer valid, binding orders from authorities with jurisdiction over 0wn.si (seller name not set), and nothing else. We can only hand over what we have: see “what we store”. Unless the law forbids it, we tell you.

13changes

If this policy changes in a way that matters, we email you at least 30 days before it takes effect. The date at the top always shows the current version.