Privacy
Last updated 30 September 2026
This policy covers Clova.Email, the email service at clova.email. Clova.Email is run by Despoina Labs LLC, a California limited liability company; “we” and “us” below mean Despoina Labs.
The short version
- We do not sell your data. Not to anyone, not in aggregate, not ever.
- No human reads your mail unless abuse is reported and confirmed.
- No advertising, no analytics, no trackers.
- If you sign in with Google, we use your email address to know it is you, and your name and photo only to fill in your profile. Nothing else, and never for advertising (see Google user data).
- Your browser talks to three other companies, each for one thing: Google while you sign in with Google, Backblaze for attachments — which it only ever sees encrypted — and Stripe while you pay.
The rest of this page is the same thing said precisely. It is worth reading — it names some things most policies leave out.
What we hold
Who you are
If you sign in with Google, we never see or store a password. What Google tells us, and exactly what we do with it, is set out under Google user data, below.
If instead you chose a username and a password, we store the username and a scrambled form of the password — a hash, which cannot be turned back into what you typed. The same goes for the one-time recovery code you were shown at signup: what we keep is a hash of it, which is why we can check the code you type and cannot ever show it to you again.
A password account can add a recovery email address. That is the one piece of information we hold purely so that there is a way back in; it is optional, and you can remove it.
Whichever way you sign in, we keep the time of your most recent sign-in and the IP address it came from — only the latest one, replacing the one before — to protect your account and to notice abuse.
Your profile holds what you choose to put in it: a birth year, optionally the day and month to go with it, and optionally a phone number and the country it belongs to. The phone number and the picture are genuinely optional and nothing stops working without them.
Your mail
We store the messages people send to your inboxes — the text, the attachments, and the full headers — because storing them is the service. Attachments are kept encrypted, each under a key of its own (see Backblaze, below).
Kept beside each message is what the delivery itself told us: the IP address the sending server connected from, the name it announced itself as, the envelope sender, and the results of the SPF, DKIM and DMARC checks we ran. That record is what makes it possible to answer "who actually sent this?" later, and it stays with the message for as long as you keep it. We also record when you first opened a message.
Anything you write is stored too: drafts, their attachments, and when they were last saved or scheduled to go out.
A domain you brought
If you brought a domain of your own, we keep the domain name, the verification token we issued for it, when it was last checked, and how many checks in a row have failed. The domain name is also your account's name, so it appears wherever the account does.
We look up your domain's DNS every week, for as long as the account exists, to confirm the verification record is still published. Those are ordinary public DNS queries about your domain — we ask resolvers what your domain says, which anybody can do, and it tells them nothing about you.
What you pay
No card details, ever. Not the number, not the expiry, not the last four digits. The form you type them into belongs to Stripe and runs on their site inside this page; what comes back to us is an identifier. If a screen ever shows you which card is on file, it is asking Stripe at that moment rather than reading something we kept.
What we do keep is the subscription itself: which plan, monthly or yearly, when the period ends, and whether the last payment went through. A free account has none of this, because there is nothing to record.
Logs
Our servers keep ordinary operational logs, and those include IP addresses — the machines connecting to deliver mail, and the ones connecting to read it. We use them to keep the service up and to see what is attacking it. Nothing advertising-shaped is built from them. (The one IP address we do keep beside your account is your latest sign-in's, described above.)
They age out on their own as the disk fills, which currently works out at roughly two weeks. We would rather state a firm number here, and intend to.
Invitations
If you joined with an invitation code, we keep the record of which code you claimed and when. That record is how invitations are prevented from being reused.
Google user data
If you sign in with Google, Google shares three things from your Google Account with Clova.Email, after asking you on its own consent screen:
- your email address, with Google's confirmation that it is verified;
- your name;
- the link to your profile photo, if you have one.
That is all. We ask Google only for the basic sign-in permissions (openid, email and profile). We have no access to your Gmail, your contacts, your calendar, your Drive or anything else in your Google Account, and we never see your Google password.
How we use it
- Your email address is how we know it is you. It is the key your account is filed under: each time you sign in with Google we match the address Google confirms to your account and start a session for it, and we note when you signed in and from which IP address (only the latest, as above).
- Your name fills in the name on your profile so it is not empty on your first day. You can change it whenever you like.
- Your photo, if you have one and your profile has no picture, is downloaded by your browser from Google and saved as your profile picture. It is optional: you can replace it or remove it from your profile at any time, and once you have removed it we do not copy it again.
We use Google user data for nothing else. We do not use it for advertising of any kind, we do not sell it, and we do not use it to develop, improve or train artificial intelligence or machine-learning models.
Who we share it with
Nobody. We do not sell, rent or transfer Google user data, and we do not share it with advertisers, data brokers or information resellers. It is kept on servers we run, and in our nightly backups at Backblaze, which are encrypted before they leave our servers so Backblaze cannot read them. We would disclose it only where the law compels us to (see Law enforcement, below).
How we protect it
Everything between your browser and us travels over encrypted connections. Your email address is held in our own account database and your name and photo in your account's own profile, apart from every other account's, on servers only the people who run Clova.Email can reach. Backups are encrypted with a key that is kept off those servers. No third-party scripts, trackers or analytics run on our pages to see any of it.
How long we keep it, and deleting it
- Your email address, name and photo are kept for as long as you have an account. You can change the name or remove the photo from your profile at any time.
- If you sign in with Google but never create an account, we keep the record of that sign-in — your email address, when, and from which IP address — for 30 days after your last one, and then delete it. The deleting is done by a weekly pass, so allow up to a week more.
- When you close your account, all of it is erased once the 30 days in which you can change your mind are up, and it leaves our backups about two weeks after that (see Deleting things).
- You can stop Google sharing anything more with us at any time by removing Clova.Email's access at myaccount.google.com/permissions. That stops sign-ins with Google; it does not delete what we already hold. To have that deleted, close your account or write to privacy at clova.email.
Clova.Email's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If we ever change how we use Google user data, we will tell you in the app, and change this page, before the change takes effect.
Reading your mail: what is automatic and what is not
Mail arriving here is inspected automatically, always. That inspection checks who sent it and looks for spam, abuse, and material that is illegal. It is software, it runs on every message, and no person is involved in it.
No human at Clova.Email reads the contents of your email or opens your attachments as a matter of course. There is one exception, and it is worth stating exactly: when something has been flagged as abusive, as spam, or as illegal and a complaint is filed about it, a person here may read the message in question in order to decide what to do — which may include closing an account or reporting it to the authorities.
That is the whole of it. We do not read mail to improve a product, to train a model, to build a profile of you, or out of curiosity.
What we never do
We do not sell your personal information, and we do not share it for money or for anything else of value. That includes aggregated and anonymised forms of it, which are the usual way this promise is quietly broken.
We run no advertising and no analytics. There are no third-party trackers, no pixels and no cookies beyond the one that keeps you signed in. Even the typefaces on this site are served from our own servers rather than from Google's, because loading them from somewhere else would hand that company the address of everybody who reads the page.
Your browser also keeps a few things of its own, in its local storage: your sign-in token, which domain you last signed in under, and which tips you have dismissed. They never leave your browser, and clearing your browser data clears them.
Who else ever sees anything
Five, and no others.
Google, if you sign in with them. They know you have an account here. They do not receive your mail or anything in your mailbox. Sign in with a username and password instead and Google is not involved at all.
Have I Been Pwned, when you choose or change a password. We will not store a password that is known to have leaked, and checking that means asking somebody who keeps the list. What is sent is the first five characters of a hash of the password — never the password, never your address, never anything naming you. They answer with every leaked hash starting with those five characters, and the comparison happens here. It is a well-known design precisely because it lets the question be asked without revealing the answer.
Spamhaus, whose blocklists we check to keep spam out. For each incoming connection we ask them about the sending server's IP address and the domain it claims — never about you, your address, or anything in the message.
Stripe, if you pay for a plan. Card details are entered into their own form and go straight to them — the card number never reaches our servers, and we could not store it if we wanted to. They are told your account name, so a payment can be traced to the mailbox it is for. They are not given your mail, your addresses, or anything in your mailbox. Stay on the free plan and Stripe is not involved at all.
The people you write to. Sending an email means handing it to whoever's server receives it, and what they do with it is governed by their rules, not ours.
We also use ordinary infrastructure to run the service — a hosting provider whose machines the data sits on, and a certificate authority that issues our TLS certificates. Neither is given access to mailboxes.
Backblaze stores our nightly backups, and every attachment — the files on mail you receive and the ones you attach yourself. All of it is encrypted before Backblaze gets it: backups on our own server, with a key that never leaves our hands, and each attachment under a key of its own that is kept with your mail, on our servers, and never given to them. What Backblaze holds it cannot read, and it is never told whose it is.
Attachments travel between your browser and Backblaze directly rather than through us, which is what keeps a large file quick. Your browser encrypts a file before it sends it there and decrypts one after fetching it, so Backblaze only ever sees the encrypted form. It does see your browser's IP address when you upload or download one, as any server your browser talks to does.
Deleting things
You can delete a message, a whole conversation, a draft, or an entire inbox at any time, and deleting an inbox takes the mail in it with it. A temporary inbox can be set to wipe what it holds when its time is up. You can remove your profile picture whenever you like. Deleted mail is cleared from our storage by a background pass rather than instantly, so allow a little time for the space to actually come back. An attachment you delete is erased from Backblaze a week later, and stays encrypted until it is.
You can close the account yourself, from the Danger Zone at the bottom of your profile. Nothing is erased for 30 days: you are signed out immediately but can sign back in, and the Recovery Zone on that same page undoes it completely. Mail carries on arriving during that month, so that people writing to you are not bounced while you are still deciding.
Once the 30 days are up, a weekly pass erases the mail and its attachments, your profile — name, birthday, phone number, photograph — and whatever links you to the account: the entry naming your Google sign-in, or your username, the hashed password, the hashed recovery code and any recovery address, and the record of your latest sign-in. Because that pass runs weekly rather than continuously, allow up to a week beyond the 30 days for the data itself to go; the account is shut and unreachable that whole time.
What is left afterwards is a small record that the account was closed — enough to keep it closed, and not enough to say who you were.
Backups outlast deletion, but not by long. Every night we make an encrypted copy of each account and keep one for each of the last seven days, and a copy that has been replaced is kept for one more week. So anything deleted — a message, or a closed account's mail when it is erased — is gone from our backups as well within about two weeks. Ordinary logs may hold traces of deleted material for a short while too.
Law enforcement and legal process
We comply with the laws that apply to us, in the United States and elsewhere where they apply.
We give user data to federal or local authorities when they ask for it properly: with documentation, and with the authorisation of a judge where the law requires one. We do not hand over mailboxes on an informal request, and we push back on demands that are overbroad or improperly served.
Keeping it safe
Mail arrives over an encrypted connection wherever the sending server supports it, and everything between your browser and us is encrypted. Mailboxes are stored separately from one another, and the parts of the service that touch the internet run with as few privileges as they can. Attachments and backups are encrypted before they leave our servers. No system is perfect and anyone who tells you otherwise is selling something.
Changes
If this policy changes in a way that matters, we will say so here and move the date at the top. Continuing to use the service after that means the new version applies.
Getting in touch
Questions about any of this, or about what we hold on you, and requests to see or delete it, go to privacy at clova.email. Clova.Email is run by Despoina Labs LLC, a California limited liability company.