Subprocessors and retention
ohmail Cloud is operated by TrafficFlow GmbH, Staubstrasse 1, 8038 Zürich, Switzerland (support@ohmail.app). Running it means using other companies. Here is every one of them, what it holds, and where.
ohmail Desktop uses none of this. It has no account and no server of ours: nothing on this page touches you if you never sign up for Cloud. On macOS, Windows and Linux alike the app is a real mail client, running against your own server rather than ours.
Not all of these are processing on any given day. They are listed regardless, because this page is meant to be complete before it is flattering, and because a subprocessor added quietly on the day it starts processing is exactly the thing this page exists to prevent.
Subprocessors
| Company | What it does for us | Data it can hold | Where |
|---|---|---|---|
| Neon | The database | Your mail, rules, tags, notes, account | EU (Frankfurt) |
| Vercel | Website and API hosting | Requests in transit; connection logs | USA |
| Railway | The sync worker | Your mail, while it is being fetched and filed | EU |
| Anthropic | The AI model | Message content sent for a suggestion or a draft | USA |
| Stripe | Payments | Your billing details. Never your mail. | USA / EU |
| Resend | Our own transactional mail to you | Your address and the message we send you | USA / EU |
Anthropic processes under commercial API terms: your mail is never used to train models, and requests are retained only briefly under its standard policy (currently up to 30 days). We have not negotiated a zero-data-retention agreement, and we will say here when we do. Where mail carries a credential — a verification code, a login link, a reset token — the credential is removed before the request is built. Your own client shows you the message in full — it is your own mail — while the model receives a version with the credential removed. Automatic background routing does not send that class of mail to a model at all; a suggestion you ask for reads it with the code gone.
How long things are kept
| What | Kept for |
|---|---|
| Mail, rules, tags, notes | As long as your account exists, then 30 days in backups |
| Blocked-tracker records | None — the tracker blocker is not switched on yet |
| Sign-in links and challenges | 5 minutes |
| Sign-in sessions | A session refreshes while you use it, so using ohmail keeps you signed in. In a browser it stops after 90 days without use; the desktop app renews on every launch and stops after 400 days without use. Signing out, or removing a device, ends it immediately. The rows go when you delete your account — no automatic expiry yet |
| Sync change log | Until you delete your account — no automatic expiry yet |
| Billing records | 10 years, pseudonymised (Swiss CO art. 958f) |
| Backups | 30 days maximum, then they expire on their own |
“No automatic expiry yet” means exactly that, and we would rather write it than publish a period no job enforces. Today the only time-based deletion that actually runs is the sweep of expired idempotency keys; everything else is removed when you delete your account, which erases it in one transaction. Shortening those three to real, enforced windows is queued work, and this table changes the day each sweep ships — not before.
Deleting your account
Deleting your account removes every user, mailbox, message, body, credential, rule, tag and note from live systems immediately, and from backups when those backups expire — within 30 days. What survives is the billing record, under a random account id with no name attached: Swiss law requires a business to keep its books, and a money trail that can be deleted on request is not a money trail.
The copy we hold is what goes. The originals were never ours: they are on your own IMAP server, in the ohmail/… folders ohmail created there, and deleting your account leaves that mailbox exactly as organised as it was.
How to do it: the control is in the app, under your account. It asks for a second factor first — a password alone must not be able to erase an account — and the erasure then runs as a single database transaction behind a step-up-authenticated endpoint. No retention interview, no delay, no email to us required. If you would rather we ran it, support@ohmail.app still works.
Reporting a security problem
Email support@ohmail.app with SECURITY in the subject. That address covers this website, ohmail.app and the ohmail Cloud backend as well as the open-source desktop apps, whose policy is published in that repository. We acknowledge within 5 working days, tell you our assessment and a rough timeline, and credit you if you want the credit. We do not run a bug bounty, and we will not threaten anyone who reports in good faith. Please do not test against other people’s accounts or mailboxes.
If personal data of yours is ever breached, we will notify the competent authority within 72 hours of becoming aware, and you directly where the risk to you is high.
The full policy
This page is the list. The full product privacy policy — legal bases, the mechanism for the two transfers to the USA, the data-subject procedure, and the conditions under which a human at TrafficFlow can reach production data — is still being written. This page is what is true in the meantime rather than a placeholder for it.