Skip to content
extort.fans
Pricing Help Status
DE EN
Sign in

Privacy

Last updated: 31 August 2026

In short

No tracking, no analytics, no ad networks, no external scripts and therefore no consent banner. Message content is encrypted and inaccessible to the operator. What gets processed is what running a mail server technically cannot avoid.

Controller

Details of the controller within the meaning of Art. 4 (7) GDPR are in the legal notice. Data protection enquiries to [email protected].

Data processed

When visiting the website

The web server processes IP address, timestamp, requested address, status code and volume transferred. These logs serve to fend off attacks and to find faults. The legal basis is Art. 6 (1) (f) GDPR, legitimate interest in secure operation. Retention 7 days, IP addresses truncated.

For temporary addresses

Stored are the generated address, your browser's public key, the lifetime, the IP address at the time of creation, and for each message the sender, recipient, timestamp and size. Subject, preview, content and attachments exist only in encrypted form.

The IP address serves solely to enforce the limit of three addresses per hour. The legal basis is Art. 6 (1) (f) GDPR. When the address expires everything is deleted; the address itself stays on a block list for 30 days so that it is not immediately handed back out.

For permanent mailboxes

Stored are the chosen address, a salt, an authentication verifier, your encrypted master key, your public key and your encrypted private key, plus display name, signature, quota and settings. The password is not stored, not even as a hash from which the key could be derived. The legal basis is Art. 6 (1) (b) GDPR, performance of the usage relationship.

For every message, sender, recipient, timestamp, size, folder and flags are held in the clear, because without them neither delivery nor sorting would be possible. Subject, preview, content, attachment names and attachment contents are encrypted.

For sessions and sign-ins

For every active session, the IP address, browser identification and timestamps are stored so that you can spot and end sessions that are not yours. They lapse on sign-out or on expiry.

For abuse reports

Category, description, a voluntarily supplied contact address and the IP address of the reporting person, to prevent misuse of the form. Kept until the case is closed, at most 12 months.

What is technically inaccessible

Message contents, subject lines, preview texts, attachment names, attachment contents, contact notes and search indexes are stored encrypted before they are written to any storage medium. The corresponding key is derived from your password in your browser and does not exist on the server. The operator therefore cannot disclose this content, not even under an official order.

Metadata is not protected. Who wrote to whom and when is part of every email delivery and cannot be encrypted without making delivery impossible.

Recipients

There is no disclosure to third parties for advertising or analytics purposes. Data is transmitted only as far as delivering mail to the receiving server requires, or where a legal obligation exists.

Access to the website runs through a content delivery network which, as a processor, handles IP addresses and connection data. Mail traffic does not go through it but straight to the server.

Cookies and browser storage

Only technically necessary values are set: a session cookie after sign-in, plus, in the browser's local storage, the chosen colour scheme, the chosen language and the identifier of your temporary address. IndexedDB holds the private key of your temporary address and, if you have saved mailboxes for the switcher, their session material. None of it leaves your device, and none of it serves cross-site recognition.

Retention at a glance

DataRetention
Messages in permanent mailboxesuntil you delete them
Trash30 days
Messages of temporary addressesuntil the address expires
Blocked address names30 days
Web server logs7 days
Mail server logs7 days
Audit log for administrative actions90 days
Abuse reportsup to 12 months

Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Access and portability naturally relate to the data accessible to the operator; you export your own content yourself using the export function in the settings. You also delete your account there yourself.

There is a right to lodge a complaint with a data protection supervisory authority.

Pricing Help Status Abuse Legal notice Privacy Terms of use
© 2026