Back to home

Privacy Policy

Last updated: July 27, 2026

GDPR CompliantCCPA CompliantCOPPA CompliantZero-Knowledge

PRIVACY POLICY

Last Updated: July 28, 2026

1. INTRODUCTION

NOVA Mail ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our email service operating under the nova-email.com domain ("the Service").

NOVA Mail operates on a zero-knowledge, zero-AI, zero-tracking principle. We collect the minimum data necessary to provide the Service and we do not read, analyze, or sell your data.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. INFORMATION WE COLLECT

2.1 Information You Provide

Account Information:

  • Email address (user@nova-email.com)
  • Display name (optional, you may use a pseudonym)
  • Account type (Standard, Disposable, or Kid)
  • Parent email address (for Kid Accounts)
  • Password (stored as a PBKDF2 hash — we never store plain-text passwords)

Profile Information:

  • Avatar URL (optional)
  • Theme and display preferences
  • Email signature (optional)

2.2 Information Collected Automatically

Email Metadata:

  • Sender email address
  • Recipient email address(es)
  • Subject line
  • Timestamp of send/receive
  • Message size

Connection Data:

  • IP address
  • Browser user agent string
  • Session timestamps
  • Authentication attempts (anonymized after 7 days)

2.3 Information We Do NOT Collect

We expressly do NOT collect, store, or process the following:

  • Email message content for analysis, scanning, or training purposes;
  • Browsing history or activity outside the Service;
  • Location data beyond inferred IP geolocation;
  • Biometric data;
  • Financial information (we do not process payments);
  • Social media data;
  • Device identifiers or fingerprints;
  • Contact lists or address book data from external services;
  • Any data for artificial intelligence or machine learning purposes.

3. HOW WE USE YOUR INFORMATION

We use the information we collect solely for:

a) Providing, maintaining, and improving the Service; b) Authenticating your identity and securing your Account; c) Delivering email messages to their intended recipients; d) Detecting and preventing spam, abuse, and security incidents; e) Complying with legal obligations; f) Communicating with you about the Service (service announcements, security notices).

We do NOT use your information for: a) Advertising or marketing; b) Data mining or analytics; c) Training AI or machine learning models; d) Profiling or behavioral tracking; e) Selling or renting to third parties.

4. SPAM DETECTION

The Service employs automated rule-based spam detection that analyzes email metadata and content patterns to classify incoming messages. This system:

  • Uses predefined rules and keyword matching only;
  • Does NOT use artificial intelligence or machine learning;
  • Does NOT retain message content beyond the spam classification process;
  • Operates entirely within the encrypted storage infrastructure;
  • Can be overridden by users on individual messages.

5. DATA STORAGE AND SECURITY

5.1 Storage Infrastructure

All data is stored on Cloudflare, Inc.'s global network infrastructure, including Cloudflare D1 (serverless SQL database), Cloudflare Workers (compute), and Cloudflare Email Routing.

For a comprehensive technical overview of our security architecture, encryption implementation, and vulnerability disclosure program, see our [Security Policy](/security).

5.2 Encryption

At Rest:

  • All email message bodies are encrypted using AES-256-GCM (Advanced Encryption Standard, 256-bit key, Galois/Counter Mode);
  • Each message receives a unique initialization vector (IV);
  • The encryption key is stored in Cloudflare Secrets, separate from the database;
  • Passwords are hashed using PBKDF2 with SHA-512 at 100,000 iterations with per-user salts.

In Transit:

  • All connections use TLS 1.3 (Transport Layer Security);
  • Email delivery to external servers uses STARTTLS where supported.

5.3 Data Location

Data is processed and stored across Cloudflare's global network. We do not restrict data to specific geographic regions by default.

6. DATA RETENTION AND DELETION

6.1 Retention Periods

Data TypeRetention Period
Active Account DataDuration of Account activity
Email MessagesUntil Account deletion or user deletion
Session Tokens24 hours
Login Attempt Records7 days
Verification Codes10 minutes
Deleted Account DataPermanently deleted within 30 days
Disposable Account Data10 days (or immediately upon manual deletion)

6.2 Account Deletion

When you delete your Account: a) All messages, folders, labels, and settings are immediately flagged for deletion; b) Associated data is permanently and irreversibly deleted within 30 days; c) The email address becomes available for new registration after deletion is complete.

6.3 Disposable Account Expiration

Disposable Accounts expire 10 days after creation. Upon expiration: a) All associated data is immediately flagged for deletion; b) Data is permanently deleted within the next cleanup cycle (runs every 6 hours); c) The email address becomes available for new disposable registration.

7. DATA SHARING AND DISCLOSURE

7.1 No Sale of Data

We do not sell, rent, trade, or license your personal information to any third party.

7.2 Service Providers

We use the following sub-processors:

ProviderServiceData Accessed
Cloudflare, Inc.Hosting, Database, Email Routing, ComputeAll data processed through the Service

7.3 Legal Requirements

We may disclose your information if required to do so by law or in the good-faith belief that such action is necessary to: a) Comply with a legal obligation (subpoena, court order, or governmental request); b) Protect and defend the rights or property of NOVA Mail; c) Prevent or investigate possible wrongdoing in connection with the Service; d) Protect the personal safety of users or the public.

7.4 Aggregate Data

We may share anonymized, aggregate data that cannot reasonably be used to identify you.

8. YOUR RIGHTS AND CHOICES

8.1 Access and Portability

You may access and export your data at any time through Account settings. We will provide your data in a machine-readable format.

8.2 Correction

You may update your account information and settings at any time through Account settings.

8.3 Deletion

You may delete your Account at any time. See Section 6 for deletion details.

8.4 Withdrawal of Consent

You may withdraw consent at any time by deleting your Account.

8.5 Opt-Out of Communications

Service-related communications (security alerts, legal notices) are mandatory. We do not send marketing or promotional communications.

9. COOKIES AND TRACKING

The Service does NOT use:

  • Tracking cookies;
  • Third-party analytics;
  • Advertising cookies;
  • Fingerprinting scripts;
  • Social media pixels;
  • Session replay scripts;
  • Cross-site tracking mechanisms.

We use browser localStorage for session management (the authentication token) and UI preferences (theme, folder state). No cookies are used. For full details, see our [Cookie Policy](/cookies).

10. INPUT SANITIZATION

The Service supports composing and rendering email messages in HTML format. All HTML content passes through a strict server-side sanitizer before storage and rendering. The sanitizer removes:

  • All script, iframe, object, embed, and applet tags
  • All inline event handlers (onclick, onerror, onload, etc.)
  • javascript: URLs and other pseudo-protocols
  • Base tags and other document-manipulating elements

This sanitization is applied automatically and cannot be bypassed. It ensures that even if a malicious message is sent to your NOVA inbox, it cannot execute scripts or compromise your session.

11. CHILDREN'S PRIVACY

11.1 COPPA Compliance

The Service complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 without verifiable parental consent.

11.2 Kid Accounts

Kid Accounts are subject to additional privacy protections:

  • Parent must provide verifiable consent during registration;
  • Parent controls all Account settings and permissions;
  • Parent can view all Account activity;
  • Content filtering is enabled by default;
  • External sending is restricted by default;
  • Parent may delete the Account at any time.

11.3 Parental Rights

Parents have the right to:

  • Review their child's data;
  • Request deletion of their child's data;
  • Refuse further collection or use of their child's data;
  • Modify parental control settings at any time.

To exercise these rights, contact privacy@nova-email.com.

12. INTERNATIONAL USERS

12.1 GDPR (European Economic Area)

If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to Access: You may request a copy of your personal data.
  • Right to Rectification: You may correct inaccurate data.
  • Right to Erasure: You may request deletion of your data.
  • Right to Restrict Processing: You may restrict how we use your data.
  • Right to Data Portability: You may receive your data in a machine-readable format.
  • Right to Object: You may object to our processing of your data.
  • Right to Withdraw Consent: You may withdraw consent at any time.

Legal Basis for Processing:

  • Contract performance (providing the Service);
  • Consent (Account creation, Kid Account setup);
  • Legitimate interests (security, abuse prevention).

Data Protection Officer: Contact dpo@nova-email.com.

12.2 CCPA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we collect.
  • Right to Delete: You may request deletion of your personal information.
  • Right to Opt-Out: We do not sell personal information, so no opt-out is necessary.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

12.3 UK Users

Users in the United Kingdom have rights equivalent to those under GDPR, as implemented by the UK Data Protection Act 2018.

12.4 International Transfers

Data may be transferred to and processed in any country where Cloudflare maintains infrastructure. We ensure appropriate safeguards are in place for international data transfers.

13. DATA BREACH NOTIFICATION

In the event of a data breach that affects your personal information, we will:

a) Notify affected users within seventy-two (72) hours of becoming aware of the breach; b) Provide details of the nature of the breach, categories of data affected, and steps taken to mitigate; c) Notify relevant supervisory authorities as required by applicable law.

14. THIRD-PARTY LINKS AND SERVICES

The Service allows you to connect external email accounts via IMAP. These third-party services have their own privacy policies and we are not responsible for their practices. We encourage you to review the privacy policies of any third-party services you connect.

15. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address associated with your Account. The date at the top of this policy indicates when it was last updated.

We encourage you to review this Privacy Policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

16. CAN-SPAM COMPLIANCE

NOVA Mail complies with the CAN-SPAM Act of 2003. When sending emails through the Service:

  • Accurate Headers: All "From," "To," "Reply-To," and routing information identifies the actual sender.
  • Honest Subjects: Subject lines accurately reflect message content.
  • Physical Address: All commercial emails include: 548 Market St, PMB 92696, San Francisco, CA 94104.
  • Opt-Out: Every commercial email includes a visible unsubscribe mechanism.
  • Timely Processing: Opt-out requests are honored within 10 business days.
  • Consent Records: Opt-in consent is recorded and maintained.

As a user, you must not send deceptive or unsolicited commercial email through the Service.

17. COMPLIANCE CERTIFICATIONS

The Service is designed to be compliant with:

  • GDPR (General Data Protection Regulation) — European Union
  • CCPA (California Consumer Privacy Act) — California, USA
  • COPPA (Children's Online Privacy Protection Act) — United States
  • CAN-SPAM Act — United States
  • PIPEDA (Personal Information Protection and Electronic Documents Act) — Canada
  • LGPD (Lei Geral de Proteção de Dados) — Brazil

17. CONTACT INFORMATION

Privacy Inquiries:

  • Email: privacy@nova-email.com
  • Legal: legal@nova-email.com
  • DPO: dpo@nova-email.com

Support:

  • Issues: issues@nova-email.com
  • Docs: https://nova-email.com/docs
  • Report: https://nova-email.com/report

Mailing Address: NOVA Mail Legal Department c/o Privacy Officer privacy@nova-email.com

---

© 2026 NOVA Mail. All rights reserved.

Questions? Contact privacy@nova-email.com

Data Protection Officer: dpo@nova-email.com

© 2026 NOVA Mail. All rights reserved.