Enveo Mail
Service Access Terms
RU EN
Enter invitation

Privacy Policy

Version of 25 August 2026.

This document describes what data Enveo Mail collects, why it is kept and for how long. It covers the enveo.net website and the mailboxes issued in that domain.

1. What is stored

Data Purpose Retention
Mailbox address Identifying the owner, delivering mail While the mailbox exists
Password hash Verifying sign-in. The password itself is neither stored nor recoverable While the mailbox exists
IP address and time of registration Investigating abuse While the mailbox exists
Message content and attachments The mail service itself: receiving, storing and serving mail to its owner Until the owner deletes the messages
Mail server logs: connecting IP addresses, sender and recipient addresses, timestamps, delivery result Delivery diagnostics, protection against password guessing and spam Up to 30 days
Website server logs Diagnosing website errors Up to 30 days
Website session cookie Operation of the registration form; there are no profiling or advertising cookies Until the browser session ends

2. What the service does not do

  • It does not read your correspondence for advertising, recommendations or model training.
  • It shows no advertising and embeds no third-party analytics.
  • It does not sell or hand over data to third parties for commercial purposes.
  • It does not gather data from outside sources to enrich a mailbox owner's profile.

3. Who has access

The administrator of the service has technical access to the server. They do not read mailbox contents; the exceptions are diagnosing a specific fault at the owner's request and investigating abuse that has been reported. In both cases access is limited to what the investigation requires.

Data may be handed to a third party only under a binding legal requirement. Unless notification is prohibited, the service informs the mailbox owner about such a demand.

4. Infrastructure

The mail server and the website run on a rented server. The infrastructure provider is technically able to access the server's disk — this is a property of any rented hardware and should be taken into account when judging how sensitive your correspondence is.

DNS for the domain is served by Cloudflare: their servers answer DNS queries and therefore see lookups for the domain. Neither website nor mail traffic is proxied through Cloudflare.

Messages you send and receive travel through the mail servers of the people you correspond with. This policy does not cover their handling.

5. Protection

  • Connections to mail and to the website are encrypted with TLS; certificates are issued by Let's Encrypt.
  • Passwords are stored as bcrypt hashes.
  • Password guessing is mitigated: repeated failed attempts block the IP address at the mail server.
  • Messages on the server's disk are not encrypted separately from the file system. For content that must stay closed even to someone with server access, use end-to-end encryption such as OpenPGP or S/MIME in your mail client.

6. Your rights

  • Take your mail with you. Every message is available over IMAP and can be downloaded by any mail client without involving the administrator.
  • Delete the mailbox. On request to postmaster@enveo.net the mailbox and its messages are deleted within 30 days. Log records disappear on their own retention schedule.
  • Find out what is stored. On the owner's request the service replies with the list of data relating to their mailbox.

There are currently no off-site backups, so deleting a mailbox leaves no copies in archives.

7. Changes

A new version is published on this page with its date. Changes that widen the set of collected data are announced by mail to the mailbox at least 14 days in advance.

8. Contact

Questions about data: postmaster@enveo.net. Abuse reports: abuse@enveo.net.

© 2026 Enveo Mail
Terms of Service Privacy Policy Acceptable Use Policy