Subprocessors and retention
ohmail Cloud is operated by TrafficFlow GmbH, Staubstrasse 1, 8038 Zürich, Switzerland (support@ohmail.app). Running it means using other companies. Here is every one of them, what it holds, and where.
ohmail Desktop uses none of this. It has no account and no server: nothing on this page touches you if you never sign up for Cloud. Desktop’s own local engine is still in development — the apps you can run today hold no mail at all.
Some of these are not processing anything yet — no live AI model is connected in production, so no mail has ever been sent to Anthropic, and no customer mailbox has connected at all. They are listed anyway, because this page is meant to be complete before it is flattering, and because a subprocessor added quietly on the day it starts processing is exactly the thing this page exists to prevent.
Subprocessors
| Company | What it does for us | Data it can hold | Where |
|---|---|---|---|
| Neon | The database | Your mail, rules, tags, notes, account | EU (Frankfurt) |
| Vercel | Website and API hosting | Requests in transit; connection logs | USA |
| Railway | The sync worker | Your mail, while it is being fetched and filed | EU |
| Anthropic | The AI model | Message content sent for a suggestion or a draft | USA |
| Stripe | Payments | Your billing details. Never your mail. | USA / EU |
| Resend | Our own transactional mail to you | Your address and the message we send you | USA / EU |
Anthropic processes under commercial API terms: your mail is never used to train models, and requests are retained only briefly under its standard policy (currently up to 30 days). We have not negotiated a zero-data-retention agreement, and we will say here when we do. Sensitive mail — verification codes and login links — is never sent to AI at all, structurally, with no setting that turns that off.
How long things are kept
| What | Kept for |
|---|---|
| Mail, rules, tags, notes | As long as your account exists, then 30 days in backups |
| Blocked-tracker records | Until you delete your account — no automatic expiry yet |
| Login and session tokens | Stop working 24 hours after they are issued; the rows go when you delete your account — no automatic expiry yet |
| Sync change log | Until you delete your account — no automatic expiry yet |
| Billing records | 10 years, pseudonymised (Swiss CO art. 958f) |
| Backups | 30 days maximum, then they expire on their own |
“No automatic expiry yet” means exactly that, and we would rather write it than publish a period no job enforces. Today the only time-based deletion that actually runs is the sweep of expired idempotency keys; everything else is removed when you delete your account, which erases it in one transaction. Shortening those three to real, enforced windows is queued work, and this table changes the day each sweep ships — not before.
Deleting your account
Deleting your account removes every user, mailbox, message, body, credential, rule, tag and note from live systems immediately, and from backups when those backups expire — within 30 days. What survives is the billing record, under a random account id with no name attached: Swiss law requires a business to keep its books, and a money trail that can be deleted on request is not a money trail.
The copy we hold is what goes. The originals were never ours: they are on your own IMAP server, in the ohmail/… folders ohmail created there, and deleting your account leaves that mailbox exactly as organised as it was.
How to do it, honestly: the erasure runs as a single database transaction behind a step-up-authenticated endpoint, and it is tested. The button that calls it is not in the apps yet. Until it is, email support@ohmail.app and we run it — no retention interview, no delay. We would rather tell you that than let a screenshot of a settings pane do the promising.
Reporting a security problem
Email support@ohmail.app with SECURITY in the subject. That address covers this website, app.ohmail.app and the ohmail Cloud backend as well as the open-source desktop apps, whose policy is published in that repository. We acknowledge within 5 working days, tell you our assessment and a rough timeline, and credit you if you want the credit. We do not run a bug bounty, and we will not threaten anyone who reports in good faith. Please do not test against other people’s accounts or mailboxes.
If personal data of yours is ever breached, we will notify the competent authority within 72 hours of becoming aware, and you directly where the risk to you is high.
The full policy
This page is the list. The full product privacy policy — legal bases, the mechanism for the two transfers to the USA, the data-subject procedure, and the conditions under which a human at TrafficFlow can reach production data — publishes before the first real mailbox connects. Until then no customer mail exists on our servers to describe.