Data Retention Policy
Last updated: 2026-07-21
We retain personal data only as long as we need it for the purpose it was collected, or as required by applicable law. This policy meets the requirements of India's Digital Personal Data Protection Act 2023 §8(7), GDPR Article 5(1)(e), and CCPA §1798.105.
Retention schedule
| Data class | Retention | Basis |
|---|---|---|
| Profile data (name, handle, bio) | While account active + 30 days grace after deletion | Service delivery |
| Verification documents | 7 years after verification, per professional-body rules | Legal / audit |
| Sent & received messages | Until user deletes; 30 days after account deletion | Service delivery |
| Email delivery logs | 90 days | Anti-abuse / audit |
| Audit log (admin actions) | 3 years | Compliance |
| Security events | 1 year | Security |
| Abuse reports & grievances | 3 years after resolution | IT Rules 2021 |
| Backups | 35 days rolling | Disaster recovery |
Deletion on request
You can request account deletion any time from Settings → Danger. Records subject to legal retention are minimised (only the fields required by law are kept).
This page is maintained by the operators of zmail.foo. It reflects app-visible controls and stated practices — not an independent certification. For questions, contact us via the address in Settings.