Privacy Policy
This policy covers the ohmail.app website, operated by TrafficFlow GmbH, Staubstrasse 1, 8038 Zürich, Switzerland (support@ohmail.app).
No analytics, no trackers
This website uses no analytics, no advertising trackers, no third-party scripts, and no tracking cookies. Your theme preference is stored in your own browser (localStorage) and is never transmitted.
The live demo
The product demo on this site runs entirely in your browser with fictional sample data. Nothing you click or type in the demo is transmitted anywhere.
The sign-up form
The waitlist form currently saves your entry in your own browser only — nothing is sent to us yet. When accounts open, sign-up data will be processed on EU servers, and this policy will be updated before that happens.
Hosting and server logs
ohmail.app is served by Vercel Inc. (USA). Like every web server, Vercel processes technical connection data (IP address, request time, user agent) in server logs for delivery and security. Legal basis: our legitimate interest in operating the website securely. We add no logging of our own.
Your rights
Under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the GDPR, you may request access to, correction of, or deletion of personal data concerning you. Given the above, we typically hold none. Contact: support@ohmail.app.
The ohmail product
ohmail Desktop is designed so your mail never touches our servers. That design is not shipped yet: the Desktop apps available today are a preview of the interface, with no IMAP client and no network access at all, and the local engine is in development.
ohmail Cloud stores a full copy of your mail — bodies, headers, subjects and senders, not only metadata — on EU servers, solely to provide sync, push and search. It is encrypted at rest and your mailbox credentials are additionally encrypted at the application level, but the mail itself is not: it is not end-to-end encrypted, and a small number of people with production database access could technically read it. Connections between your devices and ohmail use TLS; the connection onward to your own mail provider uses TLS on the standard secure ports and opportunistic STARTTLS on submission ports, and ohmail does not currently refuse a provider that offers no encryption at all.
Optional AI features send message content to Anthropic under commercial API terms: your mail is never used to train models, and Anthropic retains requests only briefly under its standard policy (currently up to 30 days). We have not negotiated a zero-retention agreement and do not claim one. Sensitive mail such as verification codes and login links is never sent to AI at all. No live model is connected in production yet — the AI features switch on with the beta.
Who processes what, where, and for how long is published in full on the subprocessors and retention page — including how account deletion works. The complete product privacy policy, with the legal bases and the transfer mechanisms, publishes before the first real mailbox connects; until then there is no customer mail on our servers for it to describe.