This policy covers the Neir website, webmail, SMTP, IMAP and POP3 services operated from Sweden. Questions or privacy requests can be sent to hello@neir.io. The technical companion to this policy is the public How Neir works Mail clients page.
Neir does not and will never require know-your-customer checks or identity verification to create or use a mailbox. We do not ask for your legal name, home address, phone number, date of birth, government ID, selfie, proof of address, recovery email or identity documents. There is no advertising profile, contact-list upload requirement or mandatory fallback account.
Neir must not be used by anyone under 16, the age of digital consent under the GDPR, unless a lower age (no younger than 13) applies where you live. Because we perform no identity verification, we have no technical way to confirm age; creating an account is itself your representation that you meet this requirement.
Your browser generates an Account Key, a 12-word recovery phrase and an OpenPGP key pair. The private PGP key is encrypted in the browser with an AES-GCM key derived from the Account Key. Registration and login send the Account Key through HTTPS so the server can verify it in memory; it is not retained in plaintext. We store an Argon2id verifier and a keyed lookup hash. The recovery phrase and app passwords are also stored only as one-way verifiers. Losing both the Account Key and recovery phrase means we cannot recover the account.
Signup also performs a first-party cryptographic check to limit automated account creation. After you click the verification control, your browser creates the future Account Key without displaying it, sends a SHA-256 commitment, receives a signed random challenge, searches for a bounded answer in one local background worker, and completes a small 8 MiB Argon2id memory-hard step. Only after verification can you display and finish generating the account credentials. The challenge expires within ten minutes and is bound to that Account Key. Neir temporarily retains only a hash of a redeemed challenge identifier until expiry and five-minute aggregate counts of issued, redeemed and replayed challenges. Those anonymous totals can raise the work equally for everyone during abuse; Tor, VPN and clearnet users are not individually scored. The check sends no CPU count, benchmark, behavior, fingerprint or puzzle interaction to Neir and makes no request to a CAPTCHA provider. Free and Pro signup both require it.
Bounded web, mail and security logs can contain source IP addresses, request paths, protocol events, timestamps and error details. IP addresses are also used for coarse emergency rate limiting and abuse defense, including on challenge and registration endpoints. Shared Tor and VPN exits are not assigned a risk score, blocked as a category or used to vary proof difficulty. These records are not added to an account profile or used for advertising. The system journal is configured for a maximum of 14 days and can expire earlier under storage pressure; other service logs are rotated and size bounded.
Free accounts need no payment data. For an optional Pro purchase, Neir stores the amount, asset and network, deposit address, provider tracking identifier, payment status, transaction hash and, when applicable, the account receiving the subscription. Heleket processes the checkout, and the relevant blockchain exposes its public transaction record. Neir does not add KYC to this process.
Neir has no advertising pixels, cross-site trackers or third-party analytics SDKs. We keep aggregate per-page, per-day counters; the analytics row has no visitor ID, IP, cookie or session attached. Some pages show Neir's own first-party promotional placements; they are served statically by Neir, set no cookies and load no third-party scripts or trackers. Remote images in email are fetched through a constrained Neir proxy, so the image host receives Neir's request instead of a direct request from your browser.
Account, mailbox, session and delivery data are processed to provide the service you request. Security and operational records are processed to prevent abuse, protect users and keep the service reliable. Optional features are activated at your direction. Records may also be processed where Swedish or EU law requires it. Neir does not sell personal data or use it for targeted advertising.
Active mailbox data remains until you delete the message or account, subject to user-selected retention features. Trash and Spam are emptied after 30 days. Completed delivery jobs are retained for at most one hour/100 entries and failed job records for at most seven days/500 entries. Account deletion immediately removes the live database account and makes its mailbox unavailable; Maildir directories are quarantined for three days before erasure so a partial deletion cannot corrupt storage. Local recovery backups rotate over approximately 8–14 days by backup class, so deleted data can remain in a restricted backup until that copy expires. Deletion is irreversible to the account holder.
Ordinary email necessarily involves the sender's and recipient's mail providers. Optional Pro payments involve Heleket and a public blockchain; optional browser notifications involve the browser vendor's push relay. Support tickets opened from the dashboard are handled entirely on Neir's own systems, described above under "Optional account data." If you instead email hello@neir.io or post on our public Telegram/X channels, that channel processes what you send. Neir discloses stored data only when legally required and can provide only data it actually holds. Lawful-request totals are published through the warrant canary where permitted.
You can export account data, correct mailbox settings, revoke sessions and app passwords, unsubscribe push endpoints, disable optional tracking, delete messages and permanently delete the account from Settings. Depending on applicable law, you may also request access, correction, erasure, restriction, portability or object to processing by contacting us. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
We can only provide what the system actually holds. That excludes a stored plaintext Account Key or recovery phrase, but it does not exclude conventional Maildir message content, attachment bytes, readable metadata, operational logs or other data explicitly described above.
Material changes will be reflected on this page with a new update date. The no-KYC commitment is also part of the Terms of Service.