Privacy policy
This is a template. Corsair is software you run; the operator of an instance is the data controller for everything on it, and that is you. Adapt this before publishing it, and take advice if the jurisdictions you operate in require it.
What an instance stores#
- Account details — the sign-in email, a password hash, and an optional name and notifications address.
- Domains and addresses you configure.
- Message content — every message delivered to a mailbox, in full, until it is deleted and expunged. This is what a mail server is.
- A message log — sender, recipient, subject, size, timestamp, and the authentication results, retained for 90 days by default.
- Access records — session IP addresses and user agents, and failed mail login attempts, retained for security purposes.
What it does not store#
- Card numbers. Payment details are handled by a payment provider; only the brand, last four digits, and the provider's own token are recorded for display.
- Message content in any form readable without either database access or the object storage credentials.
Retention#
Deleted messages are removed from the store when expunged and purged completely after 30 days. Message logs are kept for 90 days. Terminating an account marks it terminated immediately and stops mail at once.
Disclosure#
An operator should state here who they will disclose data to and under what legal process. Corsair itself transmits nothing anywhere except the mail its users send.