Privacy Policy
Last updated: July 20, 2026
What we collect
- Account: email address, chosen handle, display name, profession.
- Messages: subject, body, attachments, sender/recipient handles, timestamps, read/delivery status.
- Verification: profession, license number, organization, uploaded documents.
- Technical: session identifiers required to keep you signed in.
How we use it
Your data is used to operate the service: authenticate you, deliver mail, verify credentials, and enforce our Terms. We do not sell your data. We do not use your messages to train AI models.
Where it lives
Data is stored on Lovable Cloud (Supabase-backed) with row-level security so users can only read their own records. Verification documents are stored in a private, non-public storage bucket.
Retention
Account and message data is retained while your account is active. Deleted messages remain in Trash and are purged shortly after. Verification documents are retained for the duration of the account plus a reasonable period for audit.
Your rights
You can export your data or request account deletion by contacting the address in Settings. Where applicable law grants you rights of access, correction, or portability, we honor them.
Subprocessors
See our Data Processing Addendum for the current list of subprocessors.
This page is maintained by the operators of zmail.foo. It reflects app-visible controls and stated practices — not an independent certification. For questions, contact us via the address in Settings.