Privacy Policy

1. Responsible Party and Scope

This policy covers information processing for FlashMail accounts, purchases, top-ups, orders, and API access. Send privacy inquiries to the support email on this page. Describe your request without including full passwords, API Keys, or payment credentials.

Email providers, third-party payment pages, Telegram, and other external services have their own data practices. Review their privacy notices when using those services.

2. Information and Purposes

Registration, sign-in, and password operations submit an email address and relevant authentication information or verification codes to platform endpoints. These support account identification, verification, and protected functions. Account pages display information such as balances, membership, and API Keys.

Purchases and top-ups involve products, quantities, order numbers, amounts, currencies, and transaction status for charging, delivery, reconciliation, and order queries. Payment methods and information received by third parties must be verified for each actual channel.

Mail retrieval endpoints receive the required account credentials, folder or time parameters, and return message content. Order questions and redacted screenshots sent to support support communication and investigation. Do not provide unrelated third-party personal information.

3. Cookies and Browser Storage

Session cookies portal_access_token and portal_refresh_token maintain authentication. The frontend currently sets maximum ages of 2 hours and 7 days; refresh or sign-out updates or clears the session. These are not backend data-retention periods.

Preferences: flashmail_lang stores the language choice in a cookie with a maximum age of 1 year and in local storage. theme stores the theme and checkout_show_details stores the purchase-details preference. These local-storage entries have no automatic expiry set by the current code.

Optional remembering and session display: when remembering an email is selected, flashmail_remembered_email stores the email locally, not the password. flashmail_loaded uses session storage for first-visit display state. Disabling the email option or clearing site storage removes the relevant information; clearing storage may also sign you out or reset preferences.

4. Recipients and External Services

The website sends relevant requests to its configured platform backend. A top-up may open a payment-service URL returned by the API. Contacting support through Telegram or email involves the selected communication service in processing that communication.

5. Retention and Security

Browser-storage periods are listed above. Backend retention for accounts, orders, top-ups, delivery data, mail retrieval, logs, and backups follows the actual backend configuration. Signing out or clearing cookies does not establish that those records have been deleted.

The principles are purpose-limited access and retention, credential protection, review of sensitive information in URLs and logs, and incident-handling procedures. Specific measures must match the actual system; this text does not guarantee absolute security or zero risk.

6. Privacy Requests and Choices

Use the support email to request access, correction, deletion, account closure, or other privacy-related handling, identifying the account and matter involved. Do not send passwords publicly. Identity verification should request only information necessary for verification.

The process is to acknowledge the request, perform the necessary verification, assess applicable rights and retention duties, and communicate the result. Whether one-click closure or deletion of all data is available depends on the functionality actually provided.

Contact FlashMail