Tilomail
FeaturesSecurityPricingHelp
Sign in Create account
Legal

Privacy Policy

Last updated: August 3, 2026

Tilomail is built on a simple idea: your email is yours. This Privacy Policy explains what information we collect, why we collect it, how we protect it, and the choices and rights you have. We have tried to write it in plain language, without the usual legal fog — and where a term has a specific legal meaning, we say so.

On this page

  1. About this policy
  2. Information we collect
  3. How we use your information
  4. Zero-access encryption
  5. What we never do
  6. Cookies and local storage
  7. Legal bases for processing
  8. Data retention and deletion
  9. Your privacy rights
  10. International transfers & EU residency
  11. Service providers and sub-processors
  12. How we protect your data
  13. Government and legal requests
  14. Children's privacy
  15. Changes to this policy
  16. How to contact us

1. About this policy

Tilomail (“Tilomail,” “we,” “us,” or “our”) operates the Tilomail email service, including our web application, our mobile and desktop apps, and this website (together, the “Service”). This policy describes how we handle personal information when you create an account, use the Service, or visit our site.

For most personal accounts, we act as the data controller of your personal information — we decide how and why it is processed. For organization or business accounts, the organization is usually the controller and we act as a processor on its behalf; in that case the organization's own privacy notice governs, and we process data under our agreement with it.

This policy does not cover third-party services you choose to connect to Tilomail, or the way other providers handle mail once you send it to them. Email is a federated system, and messages you send leave our Service at your instruction.

↑ Back to contents

2. Information we collect

We collect as little as we can while still running a reliable, secure email service. Here is the full picture.

Account data

When you sign up we collect your chosen email address and, optionally, a display name. If you add them, we also store a recovery email or phone number and your authentication settings (such as two-factor authentication or passkeys), along with preferences like plan, language, and theme. Your password is stored only as a salted, hashed value — we never keep it in a readable form and cannot see it.

Mail content

Your mailbox contents — messages, attachments, drafts, calendar events, and contacts — are stored so we can deliver them to you across your devices. This content is encrypted, as described in Zero-access encryption. We do not read it, scan it for advertising, or use it to build a profile of you.

Metadata

To route and deliver mail, our systems necessarily process certain metadata: sender and recipient addresses, subject lines, timestamps, message sizes, and the IP addresses of connecting mail servers. This is inherent to how email (SMTP) works across the internet. We minimize what we retain and for how long.

Technical and log data

When you use the Service, we automatically receive limited technical data — your IP address, browser or app type and version, device and operating system, and security-relevant actions your client takes (such as sign-ins and message sends). We keep these logs for a limited period to detect abuse, troubleshoot problems, and keep the Service secure.

Website analytics

On our public website we measure how the site is performing: which pages are opened and in what order, how long a visit lasts, where a visitor arrived from (the referring site, and an approximate location and network derived from the IP address), the browser, device and language in use, and — on the sign-up form — the address that was checked for availability or submitted. This is first-party measurement kept on our own infrastructure; it is not shared with advertising networks and is not linked to any activity on other sites. We use it to understand demand, to detect abuse and automated sign-up attempts, and to improve the site.

Payment data

If you buy a paid plan, our payment processor collects your billing details and card information directly. We receive only a record of the transaction — plan, amount, date, and limited card metadata such as the card brand and last four digits — never your full card number.

Support and communications

If you contact us for help, we keep your messages and contact details so we can respond, follow up, and improve our support.

↑ Back to contents

3. How we use your information

We use the information above only for the following purposes:

  • Provide and operate the Service — deliver your mail, sync your calendar and contacts, and keep your account working across devices.
  • Authenticate and protect you — verify sign-ins, support two-factor authentication and passkeys, and secure your account.
  • Prevent abuse — detect and stop spam, phishing, fraud, and automated abuse that would harm you or others.
  • Support you — answer your questions and resolve issues.
  • Handle payments — process subscriptions, invoices, and renewals for paid plans.
  • Send essential service messages — security alerts, billing notices, and important changes. We do not send marketing email unless you opt in, and you can opt out at any time.
  • Meet legal obligations — comply with laws that apply to us, and respond to valid legal process.
  • Improve the Service — using aggregated, non-identifying diagnostics, and only where the law allows.

We do not use the contents of your mailbox for any of these purposes beyond storing your mail and delivering it to you and the recipients you choose.

↑ Back to contents

4. Zero-access encryption

The core of Tilomail's design is that we cannot read your mailbox. Your messages, attachments, calendar events, and contacts are encrypted at rest. The key that unlocks your mailbox is derived from your password, which we never store in a readable form. As a result, your stored mail is not accessible to us in plain text — and we cannot hand over readable mailbox contents that we do not have.

Mail in transit is protected with TLS wherever the receiving server supports it. End-to-end encryption is available for messages between Tilomail users and for anyone using OpenPGP.

An honest caveat. Email is a federated system. When you send a message to, or receive one from, a provider that does not support encryption, that message may travel or be stored unencrypted on the other side, outside our control. The metadata required to route mail (described above) is also, by necessity, processed in a readable form on our servers.

Because of zero-access encryption, if you lose your password and every recovery method you have set up, we may be unable to restore access to your existing encrypted mail. We explain your recovery options during setup — please keep them current.

↑ Back to contents

5. What we never do

Some commitments are easier to keep when they are absolute. We never:

  • scan or read the content of your mail to target advertising — Tilomail shows no ads on any plan;
  • sell, rent, or trade your personal information or mailbox contents to anyone;
  • build advertising profiles about you, follow you across other websites, or share your data with data brokers;
  • use your mailbox to train advertising models.

Tilomail is funded by subscriptions, so our incentives are aligned with protecting your privacy rather than exploiting it.

↑ Back to contents

6. Cookies and local storage

We use a small number of strictly necessary cookies and local-storage entries to run the Service: to keep you signed in, remember your theme and language, protect against cross-site request forgery, and support the bot-protection challenge on our sign-up and sign-in forms.

We do not use advertising cookies, cross-site trackers, or third-party analytics that follow you around the web. Because the storage we do use is essential to a service you actively request, most of it is exempt from consent requirements. If we ever introduce a non-essential cookie, we will ask for your consent first.

Our public website also stores a short-lived identifier for the current browser tab, so that the pages opened during one visit can be counted as a single visit rather than several. It is cleared when you close the tab, is never shared with third parties, and is not used to recognise you on other sites.

You can clear cookies and local storage in your browser at any time, though doing so will sign you out and reset your preferences.

↑ Back to contents

7. Legal bases for processing

If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under one or more of these legal bases:

  • Performance of a contract — to provide the Service you sign up for, including your account, mail delivery, and billing.
  • Legitimate interests — to secure the Service, prevent abuse and fraud, and keep limited operational logs, balanced against your rights and freedoms.
  • Legal obligation — to comply with laws that apply to us, such as tax and accounting rules and valid legal process.
  • Consent — where we ask for it, such as optional communications. You can withdraw consent at any time without affecting processing that already took place.
↑ Back to contents

8. Data retention and deletion

We keep personal data only as long as we need it for the purpose we collected it, or as the law requires.

  • Mailbox contents are kept until you delete them or close your account. Deleted messages sit in Trash for a limited window and are then permanently removed.
  • Logs and security metadata are retained for a limited period — typically measured in days to a small number of months — and then deleted or aggregated into non-identifying statistics.
  • Backups are encrypted and may persist for a short additional window after deletion before routine rotation removes them.
  • Account closure — when you delete your account, we begin removing your data promptly and complete the process within a defined period, except for the limited records we must retain for legal, accounting, or fraud-prevention reasons.
↑ Back to contents

9. Your privacy rights

Wherever you live, you can exercise these core rights over your Tilomail data:

  • Access — get a copy of the personal data we hold about you.
  • Export & portability — export your mail, contacts, and calendar in standard formats at any time from your account.
  • Correction — fix inaccurate account information.
  • Deletion — delete individual items or your entire account.
  • Restriction & objection — ask us to limit or stop certain processing.
  • Withdraw consent — where our processing is based on consent.

EEA, UK, and Switzerland (GDPR)

You have all of the rights above, plus the right to lodge a complaint with your local data protection supervisory authority. We will not discriminate against you for exercising your rights.

California (CCPA/CPRA)

We do not sell or share your personal information as those terms are defined under California law, and we do not use it for cross-context behavioral advertising. California residents have the right to know, delete, correct, and to be free from discrimination for exercising these rights. Because we do not sell or share, there is nothing to opt out of — but we honor requests all the same, and you may use an authorized agent.

How to exercise your rights

Most actions are self-serve in your account settings. For anything else, email privacy@tilomail.com. We will verify your request (usually through your account) and respond within the timeframe the law requires — generally within 30 days under GDPR and 45 days under the CCPA, with extensions where permitted. Exercising your rights is free unless a request is manifestly excessive or repetitive.

↑ Back to contents

10. International transfers & EU data residency

We store Tilomail mailbox data on infrastructure located in the European Union, and we aim to keep the contents of your mailbox within that data-residency footprint.

Some limited processing — for example, customer support or company operations — may involve staff or service providers in other countries. When personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, such as European Commission adequacy decisions or Standard Contractual Clauses, so that your data continues to receive an equivalent level of protection.

↑ Back to contents

11. Service providers and sub-processors

To run the Service we rely on a small set of carefully chosen service providers (“sub-processors”) that process data on our behalf and under our instructions. We describe them here by category rather than exposing your data to any provider we have not vetted:

  • Cloud infrastructure and data hosting — servers, storage, and networking; located in the EU for mailbox data.
  • Payment processing — to take and manage payments for paid plans.
  • Anti-abuse and security tooling — to detect spam, phishing, and fraudulent activity and keep the Service safe.
  • Transactional messaging — to send essential email or SMS, such as verification codes and security alerts.
  • Customer support tooling — to receive and respond to your support requests.

Every sub-processor is bound by a data-processing agreement that requires confidentiality, appropriate security, and processing limited to our instructions. We do not permit them to use your data for their own purposes, and we do not sell your data to them. A current list of sub-processor categories is available on request at privacy@tilomail.com.

↑ Back to contents

12. How we protect your data

We protect your data with a layered approach: zero-access encryption of mailbox contents, TLS in transit, strong authentication (two-factor and passkeys), sender validation with SPF, DKIM, and DMARC, continuous abuse monitoring, least-privilege internal access, and encrypted backups.

No online service can promise perfect security, but we work continuously to protect your data and to respond quickly if something goes wrong. If a personal-data breach ever affects you, we will notify you and the relevant authorities as required by law. You can read more about our approach on the Security page.

↑ Back to contents

13. Government and legal requests

We treat requests for user data as exceptional and handle them with care.

  • We require valid legal process appropriate to the requesting authority's jurisdiction, and we reject requests that are overbroad, improper, or not legally binding.
  • We interpret requests narrowly and provide only the specific data we are legally compelled to provide — and only data we actually have. Because of zero-access encryption, we cannot produce readable mailbox contents we do not hold the keys to; in most cases the data we can provide is limited metadata.
  • Where we are legally permitted, we notify affected users before disclosing their data, so they have the opportunity to challenge the request.

We are committed to transparency. To the extent the law allows, we intend to publish periodic transparency reports describing the volume and types of requests we receive.

↑ Back to contents

14. Children's privacy

Tilomail is not directed to children. You must be old enough to use the Service (see our Terms of Service). We do not knowingly collect personal information from children under 16, or under the minimum age of digital consent in your country if that age is higher.

If you believe a child has provided us with personal data without appropriate consent, contact us at privacy@tilomail.com and we will delete it.

↑ Back to contents

15. Changes to this policy

We may update this Privacy Policy from time to time as the Service and the law evolve. When we make material changes, we will update the “Last updated” date above and, for significant changes, notify you by email or an in-app notice before they take effect.

Your continued use of the Service after an update takes effect means you accept the revised policy.

↑ Back to contents

16. How to contact us

Questions, requests, or complaints about privacy are always welcome.

Privacy team: privacy@tilomail.com

General support: Help center or support@tilomail.com

If you are in the EEA or UK and are not satisfied with our response, you have the right to contact your local data protection authority.

↑ Back to contents
Tilomail

Private, encrypted email for people who'd rather not be the product.

All systems operational

Product

FeaturesSecurityPricingCreate account

Company

AboutHelp centerContactSecurity

Legal

Privacy PolicyTerms of ServiceStatus
© 2026 Tilomail. All rights reserved.Made for a quieter inbox.