Alcitron Privacy Notice
What data Alcitron keeps to host your e-mail, what for, who sees it and how long it stays.
Last updated: 9 October 2026
What we keep
Client area: each user’s name, e-mail address and password, the password only as a hash; if two-step verification is on, its settings and recovery codes, the codes also hashed; the organisation’s name, legal name, tax number, country, address and billing e-mail; and a telephone number, website and notes if given in the application.
Domains and mailboxes: the domains, their DNS verification codes and signing keys; the addresses, display names and storage limits of the mailboxes; where aliases, forwarding and catch-all addresses deliver; and mailbox passwords, only as hashes.
Mail: the messages and attachments stored in the mailboxes and those in transit; in the webmail, its users’ address books and preferences. To deliver mail and fight spam, the mail servers also record, for each message, the sender and recipient addresses, the IP addresses of the servers involved, dates, sizes and the result of the spam and malware checks.
Payments: the plan, orders, amounts and the references PayPal returns; for Monero, the address created for the order, the amounts and the identifiers of the transactions received. Card details are entered with PayPal, not with us. Technical data: what every browser sends, used to serve pages, limit requests and protect the service.
Whose data it is
The messages and other mailbox data belong to the organisation that holds the account: we handle them on its behalf. Mailbox users should take their requests to that organisation; we may pass on to it any request we receive. The client area, payments, the security of the service and visits to this site are our own responsibility.
What we use it for
To host, filter, store and send mail and manage accounts, domains and mailboxes; to detect spam, malicious software and abuse and protect the servers’ reputation; to bill; and to meet legal obligations. We do not sell data or use it for advertising. Classifying a message as spam is an automatic filter, not a decision about you.
Who else sees it
The recipients each sender chooses, through their own mail servers. The people the organisation authorises, according to their role; each organisation’s data is kept apart from the others’.
The providers that host the service, relay outgoing mail where one is used, and take payments (PayPal) see what their job needs. Monero payments travel over the Monero network, which we do not run. Authorities, when the law requires it. E-mail crosses borders by nature, and our providers may be in other countries.
Cookies
Only the ones the site and the webmail need to work: keeping you signed in, protecting forms, and remembering your language and your cookie choice.
How long we keep it
Messages stay in a mailbox until its user or the organisation deletes them, or until the mailbox or its domain is removed. Mail records and technical data are kept only as long as delivery, security and the investigation of abuse need.
Account data stays while the account is open; after that we delete or anonymise it, except what accounting, tax or legal duties require us to keep. One-time links, such as invitations and password resets, expire on their own. Deleted data may remain in backups until they rotate out.
Security
Encrypted connections, hashed passwords, optional two-step verification for the client area, signed outgoing mail, automatic spam and malware checks, and each organisation’s data kept apart. No system is completely secure; if a breach affects your data, we will report it as the law requires.
Your rights and questions
You can ask to see, correct, export or delete your data, or object to how we use it, by writing to postmaster@alcitron.com. For what is inside a mailbox, ask the organisation that gave it to you. You can also complain to the data protection authority where you live. If this notice changes, the new version is published here with its date.