Privacy Policy
Most privacy policies exist to disclose how much of you gets collected. Ours is short because the honest answer is: almost nothing, on purpose, by architecture.
Your messages are encrypted with keys derived from your passphrase. We do not have your keys, we cannot decrypt your mail, and no request, breach, or employee can change that. Every promise below is easier to keep because of this one.
01What We Collect
02What We Will Never Do
- Read, scan, or analyze the contents of your mail — we can't, and that's the product
- Show ads, run trackers, or load any third-party scripts
- Sell, rent, share, or "anonymize and monetize" any data, to anyone, ever
- Build advertising or behavioral profiles of any kind
- Keep logs longer than operations genuinely require
03Legal Requests
We comply with valid legal process. What that yields is what we hold: account registration details and recent connection metadata. Message content is stored as ciphertext and is produced as ciphertext — we possess no means to decrypt it. We deal in lawful cooperation, not backdoors, and we will publish a transparency report counting the requests we receive.
04Your Rights
- Export: take a full copy of your mailbox at any time
- Delete: close your account and your stored data is erased from the live system, with backups rotating out on schedule
- Correct: fix any account detail by writing to admin@classified.fi
Our servers are in Finland, in the European Union; if you're in the EU, GDPR rights apply to the account data described above. The service is operated from the United States — jurisdiction stated plainly, because vagueness is what you should distrust in a privacy product.
05The Honest Warning
Zero-access cuts both ways: if you lose your passphrase and your recovery kit, your mail is gone. Not "contact support" gone — mathematically gone. We cannot reset what we cannot read. Print the recovery kit the app offers you. This paragraph is the only part of this policy we hope you never think about again.