Legal
Privacy policy
Effective 12 October 2026 · Covers atkober.me and the mailbox at mail.atkober.me
atkober.me ("we", "us") runs a private webmail service. This page explains in plain language what personal data the service handles, why it handles it, who else is involved, how long it is kept, and what you can do about it.
The short version. We store the mailbox account you create and the messages delivered to it. There is no advertising, no analytics, no tracking, no profiling, and no selling of data. One strictly necessary cookie keeps you signed in. Your data lives in a PostgreSQL database and on the hosting provider that runs the app.
1. Who is responsible for your data
The operator of atkober.me is the data controller for this mailbox service.
- Controller: atkober.me
- Contact for every privacy question or request: kober@atkober.me
We have not appointed a Data Protection Officer, because we are not required to appoint one.
2. What we collect
| Data | Where it comes from | What it is used for |
|---|---|---|
Mailbox name (the part before the @ in your address) |
You, when you create the mailbox | To create your address, sign you in, and route mail to the right inbox |
| Password | You, when you create the mailbox | Stored only as a salted scrypt hash. Your password itself is never stored and never sent back to a browser. |
| Messages delivered to your address: sender, recipient, subject, plain-text body, HTML body, delivery time, read status, spam status, and the mail provider's message identifier | Incoming mail, forwarded to the app by our email provider | To show your inbox, spam folder, and unread counts |
Blocked-sender patterns (an address, or a whole domain such as @example.com) |
You, from the inbox page | To discard matching mail before it is stored |
| Session identifier | Your browser, when you sign in | To keep you signed in. It is a random value held in one cookie — see the cookie policy. |
| IP address | Your connection | Kept only in server memory, for a short time, to slow down password guessing. It is not written to the database. |
We do not collect your name, phone number, payment details, location, or advertising identifiers. We do not build profiles and we do not make automated decisions about you.
3. Why we are allowed to use it
| Purpose | Legal basis |
|---|---|
| Creating and running your mailbox: registration, sign-in, storing and displaying your messages | Performance of a contract |
| Keeping the service secure: throttling repeated sign-in failures, honouring the senders you block, keeping secrets out of the browser | Our legitimate interest in a secure service |
| Complying with a legal obligation, for example responding to a lawful request | Legal obligation |
We never use your data for marketing, and we never sell it.
4. Mail that other people send you
Messages in your inbox were written by third parties, not by us. We process their content only to deliver it to your mailbox. For HTML messages we store the HTML, but the inbox shows the plain-text body only — so remote images, tracking pixels, and other remote content in an email are never loaded when you read it.
If you emailed an address at atkober.me and want your message removed, contact the mailbox owner, or write to kober@atkober.me and we will pass the request on.
5. Cookies
This service sets exactly one cookie: mailbox_session, which is strictly necessary to sign in and is set only after you sign in or create a mailbox. There are no advertising, analytics, or third-party cookies. Full detail, including lifetimes and how to block them, is in the cookie policy.
6. Who else is involved
We use a small number of service providers. They process data on our instructions only.
| Provider | What it does | Data it touches |
|---|---|---|
| Cloudflare | Receives mail for atkober.me, runs the email worker that forwards it to the app, and provides DNS, TLS, and edge delivery for the public site | Message content, sender and recipient addresses |
| Render | Hosts the mailbox application | Everything the app processes, including message content while a request is served |
| Neon | Provides the PostgreSQL database in which accounts and messages are stored | Mailbox names, password hashes, messages, blocked-sender patterns |
We do not sell, rent, or trade personal data, and we do not share it for advertising.
7. Transfers outside your country
Our providers are mainly established in the United States, so data may be processed outside the country or region where you live. Where data of people in the EEA or UK is transferred abroad, the transfer relies on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, or the EU–US Data Privacy Framework where the provider is certified under it.
8. How long we keep it
- Messages: until the mailbox owner deletes them or asks us to. There is no automatic expiry.
- Account (mailbox name and password hash): until you ask us to delete it.
- Sign-in sessions: the cookie expires after 7 days; server-side sessions are also dropped whenever the app restarts.
- Failed sign-in counters: at most 15 minutes, held in memory only.
- Blocked senders: until you remove them.
9. How we protect it
- All traffic is served over HTTPS with a valid certificate.
- Passwords are stored as salted scrypt hashes, never in plain text.
- The session cookie is
HttpOnlyandSameSite=Lax, and markedSecurein production, so it cannot be read by scripts in the page. - Responses carry
X-Content-Type-Options: nosniff,X-Frame-Options: DENY, andReferrer-Policy: same-origin. - Only you can read your own inbox; every mailbox endpoint requires your session.
No service on the internet can promise perfect security, but we keep the surface deliberately small.
10. Your rights
If you are in the EEA, the UK, or Switzerland, you have the right to:
- be told what data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it;
- receive your data in a portable format;
- lodge a complaint with a data protection authority.
To exercise any of these, email kober@atkober.me. We answer within one month. The authority for Poland is the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl; if you live elsewhere in the EEA, you may complain to your local authority instead.
You can also ask us to export or delete your mailbox at any time — there is currently no self-service delete button, so a short email is the way to do it.
11. Children
This mailbox is not intended for children under 16, and we do not knowingly create mailboxes for them.
12. Changes to this policy
If we change how the service handles data, we will update this page and the effective date above. Significant changes will be pointed out on the sign-in page.
13. Contact
Questions, requests, or complaints about privacy: kober@atkober.me.