Zero-Knowledge Dispatch
We cannot read the content of your deletion requests. Messages are prepared and sent so that replies go directly to you via Reply-To.
Defense-in-depth for automated GDPR deletions. Encryption everywhere, least-privilege by default, and a zero-knowledge dispatch model.
We cannot read the content of your deletion requests. Messages are prepared and sent so that replies go directly to you via Reply-To.
All traffic is protected using TLS (HTTPS). HSTS is enabled to enforce secure connections.
Strict role separation for app, queue and database. Operational access is limited and audited.
We keep only minimal metadata required for troubleshooting and proof (e.g., provider status codes) and delete it on schedule.
Primary: Mailjet; optional SMTP; resilient local queue fallback. Sender verification supported.
WAL mode, timeouts, indices, and integrity checks. Regular maintenance tasks and safe backups with rotation.
No permanent storage of email bodies; metadata only. Queue cleanup after 30 days; outbound log after 180 days.
Incoming provider events (sent, delivered, bounce, …) are normalized and stored as audit metadata.
Article-17 deletion flows, clear lawful basis, DPA with processors, and transparent privacy notices.
We record minimal technical facts (timestamps, provider IDs, status) to demonstrate processing — nothing more.
If you believe you found a vulnerability, please notify us via the contact page (topic “Security”).