Privacy Policy

Last updated 10 September 2026. We collect as little as possible, ask for no real-world identity, and describe the system's real limits without calling conventional email “zero access.”

Who this policy covers

This policy covers the Neir website, webmail, SMTP, IMAP and POP3 services operated from Sweden. Questions or privacy requests can be sent to hello@neir.io. The technical companion to this policy is the public How Neir works Mail clients page.

No KYC and no identity profile

Neir does not and will never require know-your-customer checks or identity verification to create or use a mailbox. We do not ask for your legal name, home address, phone number, date of birth, government ID, selfie, proof of address, recovery email or identity documents. There is no advertising profile, contact-list upload requirement or mandatory fallback account.

Age requirement

Neir must not be used by anyone under 16, the age of digital consent under the GDPR, unless a lower age (no younger than 13) applies where you live. Because we perform no identity verification, we have no technical way to confirm age; creating an account is itself your representation that you meet this requirement.

Account creation and authentication

Your browser generates an Account Key, a 12-word recovery phrase and an OpenPGP key pair. The private PGP key is encrypted in the browser with an AES-GCM key derived from the Account Key. Registration and login send the Account Key through HTTPS so the server can verify it in memory; it is not retained in plaintext. We store an Argon2id verifier and a keyed lookup hash. The recovery phrase and app passwords are also stored only as one-way verifiers. Losing both the Account Key and recovery phrase means we cannot recover the account.

Signup also performs a first-party cryptographic check to limit automated account creation. After you click the verification control, your browser creates the future Account Key without displaying it, sends a SHA-256 commitment, receives a signed random challenge, searches for a bounded answer in one local background worker, and completes a small 8 MiB Argon2id memory-hard step. Only after verification can you display and finish generating the account credentials. The challenge expires within ten minutes and is bound to that Account Key. Neir temporarily retains only a hash of a redeemed challenge identifier until expiry and five-minute aggregate counts of issued, redeemed and replayed challenges. Those anonymous totals can raise the work equally for everyone during abuse; Tor, VPN and clearnet users are not individually scored. The check sends no CPU count, benchmark, behavior, fingerprint or puzzle interaction to Neir and makes no request to a CAPTCHA provider. Free and Pro signup both require it.

Mailbox data

  • Your email address(es): one primary address plus the aliases included with your selected plan.
  • Sender, recipients, subject, timestamps, message identifiers, routing headers and folder/flag state as readable metadata needed to route, list, search and synchronize mail.
  • A webmail body copy encrypted to your OpenPGP public key before it is stored in PostgreSQL. Your encrypted private key is returned only to your authenticated session and unlocked in your browser with the Account Key.
  • A standards-compatible RFC message copy in Dovecot Maildir. SMTP, spam/malware filtering, server-side filters, IMAP and POP3 necessarily process or retain plaintext content. This means ordinary email on Neir is not zero-access or end-to-end encrypted unless the sender independently encrypts the message before delivery.
  • Attachments in randomly named, access-restricted server files. Attachment contents do not receive the webmail body's OpenPGP-at-rest protection.

Optional account data

  • Contacts you choose to save (name + address).
  • Filters you create (e.g. "star mail from X").
  • App passwords, stored as a one-way hash: the plaintext is shown to you once, at creation, and never again.
  • A 2FA secret, if you enable two-factor authentication, stored encrypted.
  • Login sessions: your browser's user-agent string and a last-active timestamp, so you can review and revoke devices in Settings. We do not log or store your IP address or geographic location against your account.
  • If you enable push notifications, a browser subscription endpoint and keys. Notifications route through your browser vendor and contain the new message's sender name/address and subject. This is opt-in and off by default.
  • If you enable sender open tracking, a random per-message token and first-open timestamp. External recipients load a Neir-hosted pixel; local recipients are recorded internally without a pixel. This is opt-in and off by default.
  • Support tickets you open from the dashboard: the subject and message text, stored as plain readable text rather than the mailbox body's OpenPGP-at-rest encryption, since staff need to read them to help you. You can delete a ticket and every message in it, permanently, at any time.

Operational logs and abuse prevention

Bounded web, mail and security logs can contain source IP addresses, request paths, protocol events, timestamps and error details. IP addresses are also used for coarse emergency rate limiting and abuse defense, including on challenge and registration endpoints. Shared Tor and VPN exits are not assigned a risk score, blocked as a category or used to vary proof difficulty. These records are not added to an account profile or used for advertising. The system journal is configured for a maximum of 14 days and can expire earlier under storage pressure; other service logs are rotated and size bounded.

Payments

Free accounts need no payment data. For an optional Pro purchase, Neir stores the amount, asset and network, deposit address, provider tracking identifier, payment status, transaction hash and, when applicable, the account receiving the subscription. Heleket processes the checkout, and the relevant blockchain exposes its public transaction record. Neir does not add KYC to this process.

Analytics, trackers and remote content

Neir has no advertising pixels, cross-site trackers or third-party analytics SDKs. We keep aggregate per-page, per-day counters; the analytics row has no visitor ID, IP, cookie or session attached. Some pages show Neir's own first-party promotional placements; they are served statically by Neir, set no cookies and load no third-party scripts or trackers. Remote images in email are fetched through a constrained Neir proxy, so the image host receives Neir's request instead of a direct request from your browser.

Purpose and legal basis

Account, mailbox, session and delivery data are processed to provide the service you request. Security and operational records are processed to prevent abuse, protect users and keep the service reliable. Optional features are activated at your direction. Records may also be processed where Swedish or EU law requires it. Neir does not sell personal data or use it for targeted advertising.

Retention and deletion

Active mailbox data remains until you delete the message or account, subject to user-selected retention features. Trash and Spam are emptied after 30 days. Completed delivery jobs are retained for at most one hour/100 entries and failed job records for at most seven days/500 entries. Account deletion immediately removes the live database account and makes its mailbox unavailable; Maildir directories are quarantined for three days before erasure so a partial deletion cannot corrupt storage. Local recovery backups rotate over approximately 8–14 days by backup class, so deleted data can remain in a restricted backup until that copy expires. Deletion is irreversible to the account holder.

Service providers and disclosures

Ordinary email necessarily involves the sender's and recipient's mail providers. Optional Pro payments involve Heleket and a public blockchain; optional browser notifications involve the browser vendor's push relay. Support tickets opened from the dashboard are handled entirely on Neir's own systems, described above under "Optional account data." If you instead email hello@neir.io or post on our public Telegram/X channels, that channel processes what you send. Neir discloses stored data only when legally required and can provide only data it actually holds. Lawful-request totals are published through the warrant canary where permitted.

Your choices and rights

You can export account data, correct mailbox settings, revoke sessions and app passwords, unsubscribe push endpoints, disable optional tracking, delete messages and permanently delete the account from Settings. Depending on applicable law, you may also request access, correction, erasure, restriction, portability or object to processing by contacting us. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Data requests

We can only provide what the system actually holds. That excludes a stored plaintext Account Key or recovery phrase, but it does not exclude conventional Maildir message content, attachment bytes, readable metadata, operational logs or other data explicitly described above.

Changes

Material changes will be reflected on this page with a new update date. The no-KYC commitment is also part of the Terms of Service.