Compliance & Trust Center

Last updated: 2026-07-21

This page is maintained by the operators of zmail.foo to answer common security and privacy questions about the platform. It is app-owned content, not an independent certification.

Access & authentication

  • Email + password for standard accounts, with optional Google sign-in.
  • Email-only one-time codes for signup verification, password reset, email change, and sensitive account actions. No SMS OTP.
  • Admin sign-in requires an OTP delivered to the admin's registered address on a separate subdomain (admin.zmail.foo).
  • Sessions are held in browser storage as signed tokens. Users can sign out from any device from Settings.
  • Passwords are checked against the Have I Been Pwned dataset at signup and change.

Platform & hosting

  • Application code runs on Cloudflare's edge network with automatic TLS.
  • Data is stored in a managed Postgres cluster with encryption at rest.
  • Row-level security is enabled on every user-owned table; server functions operate under the caller's identity, not a shared admin identity.
  • Uploads are stored in private buckets and served only through short-lived signed URLs.

These are platform capabilities we operate. They are not, on their own, certifications.

Data collection & use

We collect only what is needed to run the account, marketplace, mail, and payment features you use. Full details in the Privacy Policy.

Subprocessors

We rely on the following processors for parts of the service. Each is bound by its own data-processing terms.

  • Cloudflare — application hosting and edge network.
  • Managed Postgres — primary database, storage, and background jobs.
  • Mailgun — inbound and outbound email delivery for the mail.zmail.foo mailbox.
  • Lovable Email API — auth and app transactional email delivery.
  • PayU — payments processing (India).
  • Google — optional Google sign-in and Google Calendar integration when the user connects it.

Cookies & analytics

We use first-party session cookies for authentication and preferences. See the Cookie Policy. We do not run third-party advertising trackers.

Retention & deletion

Retention windows for each category of data are listed in the Data Retention Policy. Account deletion is described in the Account Deletion Policy.

Privacy requests

You can export your personal data or request account deletion from Settings → Data & privacy. Both flows are self-serve; escalations go through the grievance officer.

Security contact

Report vulnerabilities to security@zmail.foo. Full disclosure process in the Security Policy.

Compliance stance

  • DPDP Act 2023 (India): we act as a Data Fiduciary for personal data of Indian residents processed on the platform.
  • IT Act 2000 & IT Rules 2021: grievance officer, 15-day response SLA, and content takedown are described in Grievance Redressal.
  • GDPR: for EU/UK residents using the platform, we honour access, rectification, erasure, portability, and restriction rights via the same request flows.
  • CCPA/CPRA: California residents may exercise "do not sell/share" rights — we do not sell personal information and do not process it for cross-context behavioural advertising.
  • CAN-SPAM: every promotional email includes a one-click unsubscribe.

What this page is not

zmail.foo has not, at the time of writing, undergone SOC 2, ISO 27001, HIPAA, or PCI audits. Claims of "compliance" refer to the operational practices described above, not independent audits.

This page is maintained by the operators of zmail.foo. It reflects app-visible controls and stated practices — not an independent certification. For questions, contact us via the address in Settings.