Home · Pricing · Help · Terms · Privacy · Cookies · Acceptable use · Sign in
Privacy Policy
What Stellomail collects, why, and how long we keep it. No ads, no selling data, drafts checked on your device, mail stored only in the EU.
Who we are
This Privacy Policy is issued by Stellomail Μονοπρόσωπη Ι.Κ.Ε., a single-member private company incorporated in Greece and registered with the General Commercial Registry (ΓΕΜΗ) under number 123456701000, with its registered office at Ermou 40, 105 63 Athens, Greece (“Stellomail”, “we”, “us” or “our”). Stellomail is the controller of the personal data described in this policy for the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Greek Law 4624/2019.
This policy applies to the Stellomail email service, including @stellomail.com addresses and any custom domains connected to the service, the web application, our iOS, Android and desktop applications (together, the “Service”), and our website at stellomail.com (the “Website”). It also applies when you contact our support team.
We have appointed a Data Protection Officer, who can be reached at privacy@stellomail.com or by post at the address above marked “Attn: Data Protection Officer”. Where this policy refers to “you”, it means anyone whose personal data we process in connection with the Service or the Website, including account holders, team members on a Corinthian plan, and people who correspond with Stellomail users.
Information you give us
Account information. When you create an account we collect your name, your chosen Stellomail address or username, your password, your time zone, your preferred language and your sign-off preference. We never store your password in plain text; we store only a salted cryptographic hash of it. If you register a passkey, we store only the passkey’s public key; the private key never leaves your device. You may also give us a recovery email address or a recovery phone number so that you can regain access to your account.
Plan and billing information. When you subscribe to a paid plan, payment is handled by our payment processor, Stripe. You enter your card details directly with Stripe, and we never receive or store your full card number. From Stripe we receive and keep your plan, your billing history, and your card brand, the last four digits of your card, its expiry date and your billing country.
Mail, contacts and calendar. We store the messages you send and receive, their attachments, your folders and labels, your saved replies (“amphorae”), your contacts and your calendar entries. We process this content solely to provide the Service to you: to deliver, store, sync, search and display it on your devices. Messages you move to Trash are purged automatically after 30 days.
Support conversations. When you contact support we keep the correspondence and any information you choose to include, so that we can resolve your request and refer back to it if the issue recurs.
Collected automatically
Delivery metadata. For every message that passes through the Service we process the sender and recipient addresses, timestamps, message size and the IP addresses of the sending and receiving mail servers. We use this metadata to route and deliver mail and to filter spam and malicious messages. Spam filtering is automated and runs entirely on our own servers in the European Union.
Security logs. When you sign in or use the Service we record the IP address used, the type of device and the time of access. We use these logs to protect your account, to detect unauthorised access and to show you recent sign-in activity. Security logs are kept for 90 days.
Website and network logs. Requests to the Website and the Service pass through Cloudflare, which provides content delivery, security and protection against denial-of-service attacks. Cloudflare and our web servers generate standard technical logs, including IP address, requested URL, time, browser user-agent and response status. These logs are kept for 14 days. The Website contains no analytics tools, no advertising, no third-party trackers and no social media embeds, and our fonts are hosted on our own servers.
Features that run on your device. The oracle’s pre-send checks (for example, a missing attachment, a mistyped or unusual recipient, a reply-all to ten or more people, a message arriving during the recipient’s night, or a subject that does not match the body) run locally in your browser or app. Your drafts are never uploaded to us to be checked, and we receive no record of what the oracle flagged.
From third parties
People who write to you. When someone sends mail to a Stellomail address, we receive the personal data contained in that message and its headers. We process it on behalf of our user, solely to deliver and store the message. To offer sunrise delivery, which schedules a message to arrive during the recipient’s morning, we infer a correspondent’s time zone from the headers of mail that correspondent has sent you, or from the contact card you keep for them. That inferred time zone is stored with your contacts, is visible only to you, and is never shared with anyone else.
Imports from other providers. If you choose to import mail, contacts or calendars from Gmail, Outlook or iCloud, you grant us an OAuth access token through that provider. We use the token only to copy your data into Stellomail, and we discard it as soon as the import completes. We do not retain ongoing access to your other account.
Payment processor. Stripe tells us whether a payment succeeded and provides the limited card details described above.
Team administrators. If your account is part of a Corinthian team, your organisation’s administrator may create your account and provide your name, address and team role, and may configure single sign-on through your organisation’s identity provider, in which case we receive the identity information needed to sign you in.
Team accounts and admins
On the Corinthian plan, an organisation may connect its own custom domain, create shared inboxes, and appoint one or more administrators who manage the team’s accounts. For accounts managed in this way, the organisation decides how those accounts are used and, for that purpose, acts as the controller of the team members’ data, with Stellomail processing it on the organisation’s instructions under our agreement with that organisation.
Administrators can create, suspend and delete team accounts; reset passwords and passkeys; configure single sign-on and security requirements; manage custom domain settings and shared inbox membership; view account-level information such as names, addresses, storage use, sign-in activity and security logs; and, where permitted by the law that applies to them and the policies of the organisation, export or retain the contents of team mailboxes. Messages in a shared inbox are visible to every member of that inbox.
If you use a team account, please read your organisation’s own privacy notice, and direct requests about your data to your organisation in the first instance. We will assist the organisation in responding to your requests.
Cookies and local storage
The Website sets no cookies. The web application sets a single strictly necessary cookie, named “sm_session”, which keeps you signed in. It is marked HttpOnly, Secure and SameSite=Lax, and it expires after 30 days of inactivity or when you sign out, whichever comes first.
The web application also uses your browser’s local storage to remember interface preferences, such as dense or comfortable view, and to autosave drafts on your own device. This information stays in your browser and is not used to track you.
We use no advertising, analytics, social media or cross-site cookies. Full details are set out in our Cookie Policy.
How we use information
Providing the Service. We use your account information, mail, contacts, calendar, delivery metadata and preferences to create and operate your account, to send, receive, store, sync and search your mail, to run features such as sunrise delivery, amphorae and imports, and to strip spy and tracking pixels from incoming mail so senders cannot tell when or where you opened a message. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR).
Security, spam and abuse prevention. We use delivery metadata, security logs and network logs to filter spam, phishing and malware, to detect and stop unauthorised access, to enforce our Acceptable Use Policy and to protect the Service and its users. Legal basis: our legitimate interests, and those of our users and the wider email ecosystem, in keeping mail secure and free of abuse (Article 6(1)(f) GDPR). Processing the personal data of people who write to our users, including the time zone inferred for sunrise delivery, also rests on the legitimate interest of our users in receiving, organising and replying to their mail.
Billing. We use plan and billing information to take payment, issue invoices and handle refunds. Legal basis: performance of our contract (Article 6(1)(b) GDPR). We retain billing records to meet our obligations under Greek tax and accounting law. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
Account and service notices and support. We use your contact details to send essential messages about your account, such as security alerts, billing receipts and changes to the Service or to this policy, and we use support conversations to help you. Legal basis: performance of our contract (Article 6(1)(b) GDPR). Where you grant our support staff access to part of your mailbox to resolve a specific issue, we rely on your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
Legal compliance. We process personal data where necessary to comply with the law, to respond to lawful requests from public authorities, and to establish, exercise or defend legal claims. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR) and our legitimate interests (Article 6(1)(f) GDPR). Automated spam filtering does not produce decisions with legal or similarly significant effects on you within the meaning of Article 22 GDPR, and you can always review your spam folder and mark messages as not spam.
What we never do
We do not show advertising in the Service or on the Website. We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising as that term is defined under California law. We do not build advertising profiles about you or anyone who writes to you.
We never use your mail to train AI models.
Stellomail staff cannot read your mail. The only exceptions are where you explicitly grant our support team access for a specific issue, in which case access is limited to what you authorise and ends when the issue is resolved, or where we are legally compelled to disclose it. We review every legal demand, challenge requests that are overbroad or lack a proper legal basis, and notify the affected user before disclosure wherever the law allows. We publish a transparency report every year describing the requests we have received and how we responded.
Sharing and processors
We disclose personal data only to the following categories of recipients. Each processor acts solely on our documented instructions under a data processing agreement that meets the requirements of Article 28 GDPR.
Stripe Payments Europe, Limited, based in Ireland, processes payments and holds your full card details. Cloudflare, Inc. and its affiliates provide content delivery, network security and protection against denial-of-service attacks, and see IP addresses and request data in transit. Our data-centre partners in Athens and Frankfurt provide the physical facilities, power and connectivity for the servers on which your mail and account data are stored; they do not have access to the content of your data. An EU-based transactional email relay delivers account notices, such as security alerts and receipts, to your recovery or billing address.
We may also disclose personal data where required by law or by a binding order of a competent court or authority, subject to the safeguards described under “What we never do”; to professional advisers such as lawyers and auditors who are bound by confidentiality; and, in the event of a merger, acquisition or sale of all or part of our business, to the acquiring entity, which will remain bound by this policy, with notice to you in advance.
When you send an email, the Service necessarily delivers it and its headers to the recipients you choose and to their mail providers. That is a disclosure you direct, not one we make of our own accord.
How long we keep it
Account data, mail, contacts and calendar: kept while your account is open. After you close your account, they are deleted from our live systems within 30 days and from our backups within a further 60 days.
Mail in Trash: purged automatically 30 days after it is moved there. Billing records: kept for five years, as required by Greek tax law. Security logs: kept for 90 days. Support conversations: kept for two years after the conversation ends. Cloudflare and web server logs: kept for 14 days. OAuth tokens used for imports: discarded as soon as the import completes.
We may keep specific data for longer where it is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim, and only for as long as that need lasts.
How we protect it
Your mail and account data are stored on servers in Athens, Greece and Frankfurt, Germany, and remain in the European Union. Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
We apply technical and organisational measures appropriate to the risk, including strict role-based access controls, the principle of least privilege, strong authentication for staff, logging and review of administrative access, regular security testing, and confidentiality obligations for everyone who works for us. You can strengthen the protection of your own account by using a passkey and keeping your recovery details up to date.
No system is entirely immune to attack. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours of becoming aware of it and will inform you without undue delay where the law requires.
Your GDPR rights
Under the GDPR you have the right to access your personal data and receive a copy of it; to have inaccurate data corrected; to have your data erased; to restrict our processing of it; to receive the data you have provided to us in a structured, commonly used and machine-readable format and to have it transmitted to another controller (data portability); to object at any time to processing based on our legitimate interests; and, where we rely on your consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before its withdrawal.
You can export your data and delete your account directly from Settings → Privacy. You can exercise any of your rights by emailing privacy@stellomail.com. We may need to verify your identity before acting on a request, normally by asking you to make it while signed in or from your Stellomail address. We respond within one month of receiving your request. Where a request is complex or we receive many requests, we may extend this period by up to two further months, as Article 12(3) GDPR permits, and we will tell you within the first month if we do so. Exercising your rights is free of charge.
You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr. You may also complain to the data protection authority in the EU member state where you live or work, or where you believe an infringement took place. We would welcome the chance to address your concern first, so please contact our Data Protection Officer if you can.
California privacy rights
This section applies to residents of California under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”). In the past 12 months we have collected the following categories of personal information, from the sources and for the business purposes described in this policy: identifiers (such as name, email address, IP address and account username); customer records (such as recovery contact details and billing information); commercial information (such as your plan and billing history); internet or other electronic network activity (such as security logs and delivery metadata); and the contents of your mail, contacts and calendar. We do not collect precise geolocation.
Some of this information is “sensitive personal information” under the CCPA, namely your account log-in credentials and the contents of your mail. We use and disclose sensitive personal information only to provide the Service you request and for the other purposes permitted by the CCPA regulations, and never to infer characteristics about you. We keep each category for the periods set out under “How long we keep it”.
You have the right to know what personal information we collect, use and disclose; to delete it; to correct inaccurate personal information; to opt out of the sale or sharing of personal information; to limit the use and disclosure of sensitive personal information; and not to be discriminated against for exercising any of these rights. We do not sell or share personal information, and we have not done so in the past 12 months, so there is nothing to opt out of; and because we already limit our use of sensitive personal information to permitted purposes, the right to limit is honoured by default. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
To make a request, use Settings → Privacy or email privacy@stellomail.com. We verify requests by asking you to sign in to your account or to reply from your Stellomail address. You may use an authorised agent, who must provide your signed written permission, and we may ask you to confirm your identity directly with us. We do not charge a fee. We respond within 45 days, and where reasonably necessary we may extend this by a further 45 days after telling you why.
Children’s privacy
You must be at least 15 years old to create a Stellomail account, which is the age of digital consent in Greece under Article 21 of Law 4624/2019. The Service and the Website are not directed at children under 15, and we do not knowingly collect personal data from them.
If we learn that we have collected personal data from a child under 15, we will delete the account and the associated data promptly. If you believe a child under 15 has created an account, please contact privacy@stellomail.com.
International transfers
Your mail, contacts, calendar and account data are stored and processed in the European Union, in Athens and Frankfurt, and are not transferred outside the European Economic Area.
Limited categories of personal data may be transferred to the United States where our processors Stripe or Cloudflare process data there, for example payment data handled by Stripe’s group companies or network request data processed by Cloudflare. Such transfers rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework, where the recipient is certified under it, and/or on the Standard Contractual Clauses adopted by the European Commission, together with supplementary measures where appropriate. You may request a copy of the relevant safeguards by writing to privacy@stellomail.com.
Changes to this policy
We may update this Privacy Policy to reflect changes in the Service, in our practices or in the law. The date at the top of this page shows when it was last revised.
If we make a material change, we will notify you by email to your Stellomail address and by a notice in the Service at least 30 days before the change takes effect, unless a shorter period is required by law or necessary to address a security risk. Where a change requires your consent under applicable law, we will ask for it. Previous versions of this policy are available on request.
Contact us
The controller of your personal data is Stellomail Μονοπρόσωπη Ι.Κ.Ε., Ermou 40, 105 63 Athens, Greece, registered with the General Commercial Registry (ΓΕΜΗ) under number 123456701000.
Our Data Protection Officer can be contacted at privacy@stellomail.com, or by post at Ermou 40, 105 63 Athens, Greece, marked “Attn: Data Protection Officer”. For help with your account, write to support@stellomail.com. For legal matters, write to legal@stellomail.com. To report abuse, write to abuse@stellomail.com.
You may also contact the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr, or the data protection authority in your own EU member state.