What we know about you, and what we refuse to learn.
You pay us $9.99 a year to carry your mail. That is the entire relationship. We have no advertisers, no analytics and no model to feed, so we keep as little as a mail service can.
01who is responsible
0wn.si is run by 0wn.si (seller name not set), the data controller for everything described here.
seller: 0wn.si (seller name not set)address: Street 1, 00-000 City
country: PL
VAT ID: PL0000000000
contact: billing@0wn.si
Privacy questions and requests: write to the contact address above from any address. We answer within 30 days, usually much sooner.
02the short version
- No ads, no tracking, no analytics, no third-party scripts on our pages.
- Your mail is never used to train a model. Not ours, not anyone’s.
- Automated-sender detection works on headers and rules. Message bodies are never sent to a model.
- Two first-party cookies. That is all of them.
- You can export everything as mbox at any time, and delete the account whenever you like.
03what we store
- account
- your username, an Argon2id hash of your password (never the password), an optional recovery email, two-factor secrets (TOTP seed, hardware-key public keys, hashed recovery codes), your settings
- the messages in your mailbox and a search index of them, on the same encrypted volume. The index exists so search with wildcards is fast; it is deleted with the message
- sessions
- one record per signed-in device: IP address and browser user agent. You can see and revoke them in settings → account
- sign-in history
- time, IP address, user agent and outcome of sign-in attempts, to detect break-ins and to show you
- billing
- invoices, payment references and a ledger of what was paid. Card numbers never reach our servers
- sender choices
- what you tell us about senders: “this is a human”, “this is a machine”, “always load images”, your allow and block lists
- logs
- structured server logs with no message content and no personal data beyond a user id, kept for 30 days
We do not ask for your name, phone number, date of birth or postal address, and we have nowhere to put them.
04what we never do
- Show ads, build an advertising profile, or sell, rent or share your data for marketing.
- Run analytics or tracking on the website or in the inbox.
- Train machine-learning models on your mail, or let anyone else do it.
- Send read receipts. Nobody learns when, or whether, you opened a message.
- Read your mail. Staff tools show account and billing data; they have no view of message content.
05how mail is processed
Incoming mail is checked on our own server: sender authentication (SPF, DKIM, DMARC, ARC), public blocklists, and a spam filter that scores the message with rules and statistics. Marking something as spam or not spam trains the filter for your mailbox.
Mail from automated senders is tagged “auto” using headers and rules only, such as List-Unsubscribe, Precedence, Auto-Submitted, no-reply addresses and known bulk-mail signing domains. Bodies are not analysed by a model, here or anywhere else.
When you open a message we remove tracking pixels and known tracker domains, strip link-tracking parameters (utm_*, fbclid, gclid and similar), and block remote images. If you choose to load images they are fetched through our proxy, so the sender sees our server and not you.
The longer account is on the how we handle your mail page.
06payments
Card payments are handled by Stripe. Card details go from your browser straight to Stripe; we receive a payment reference, the card brand and last four digits, and the result. Stripe is loaded only when you choose to pay by card.
Bitcoin and Lightning payments go through a BTCPay Server that we host ourselves. Payments in ETH, USDC and SOL are processed by NOWPayments, which sees the payment itself and nothing about your mailbox. Blockchains are public: a crypto payment is visible to anyone who knows the address.
07cookies
- own_session
- keeps you signed in to the inbox. httpOnly, first-party, set when you sign in
- own_csrf
- protects forms against cross-site request forgery. httpOnly, first-party, set when you start a checkout or open the inbox
There are no other cookies, no local tracking identifiers and no cookie banner, because there is nothing to consent to.
08who else touches your data
- DigitalOcean
- hosting: the server your mail lives on
- S3-compatible storage
- encrypted backups. The provider stores ciphertext and never holds the key
- Stripe
- card payments
- NOWPayments
- ETH, USDC and SOL payments
That is the complete list. Nobody on it receives your mail in readable form.
09how long things live
- trash
- purged automatically after 30 days
- plan expiry
- 30 days of grace: mail still arrives, reading and export work, sending is off
- after grace
- the account is suspended and incoming mail is rejected
- 60 days later
- the account and its mail are deleted. We email you at each step
- account deletion
- when you ask for it: 14 days to change your mind, then everything is deleted
- backups
- encrypted, kept 7 daily / 4 weekly / 6 monthly; deleted data ages out within 6 months
- logs
- 30 days
- billing records
- as long as accounting law requires, typically five years
10security
Connections use TLS 1.2 or newer. Mail and the database sit on an encrypted disk. Passwords are hashed with Argon2id. Two-factor sign-in (authenticator app or hardware key) is available to everyone and mandatory for staff. Every staff action is written to an append-only audit log.
Mail between providers is only as private as the other side allows: we always offer TLS and publish MTA-STS, but a message to a provider without encryption travels unencrypted. For end-to-end secrecy use PGP or S/MIME in your own client.
11your rights
You can see, correct, export and delete your data yourself: settings shows what we hold, export gives you everything as mbox, and delete account removes it. If you are in the EU or the UK you also have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to your data-protection authority.
We process your data to perform our contract with you (running your mailbox), to meet legal obligations (accounting records), and for our legitimate interest in keeping the service secure and free of abuse (sign-in history, rate limits, spam filtering).
12legal requests
We answer valid, binding orders from authorities with jurisdiction over 0wn.si (seller name not set), and nothing else. We can only hand over what we have: see “what we store”. Unless the law forbids it, we tell you.
13changes
If this policy changes in a way that matters, we email you at least 30 days before it takes effect. The date at the top always shows the current version.