privacy policy.
operator and contact
Ilja Gwawl operates Vael. Send privacy or account-data questions to vael-support@vael.email.
account and security data
We store your chosen addresses, account identity, credential verifiers, sessions, app-credential settings, optional two-factor authentication, entitlements, preferences and activity needed to operate the account. Your account key is verified rather than stored as readable text. No recovery email or personal name is required to register.
Sign-in and abuse protection process connection addresses transiently. Short-lived pseudonymous counters expire and are not persisted as a browser identity. Vael does not use advertising analytics, browser fingerprinting or session replay. Infrastructure providers still process connection information needed to supply their services.
mail and encrypted storage
Mail bodies, attachments and headers are stored in the mail service. Search and organization use related metadata. Mail-storage volumes and rolling backups are encrypted. Website and authenticated mail-client connections require TLS; server-to-server mail uses TLS when the other provider supports it. The running server and its operator can decrypt stored mail; this is not end-to-end or zero-access encryption.
Incoming messages can contain tracking content and connection metadata added by other senders. Remote images are blocked by default. If you approve them, Vael fetches them; the remote server can observe those requests. Any local draft recovery you enable also stores draft data in your browser.
mail health reports
Vael receives aggregate authentication and TLS reports from other mail providers. Report messages are kept for up to seven days, and aggregate domain counts for up to 90 days, within bounded storage. Reports are untrusted observations and do not guarantee delivery. Webmail preloads a limited number of messages into browser memory; this cache is cleared when your session ends.
payments
OxaPay processes payment assets, networks, addresses and blockchain transactions. Vael stores order identifiers, amounts, payment status and entitlement records for billing and reconciliation. Your secret account key is not sent to OxaPay. Public blockchains can expose transaction information independently of Vael.
service providers
Hetzner supplies the server infrastructure. Cloudflare supplies authoritative DNS for Vael’s domains. The currently configured website and mail hostnames use DNS-only records, so their traffic connects directly to Vael’s server. OxaPay supplies cryptocurrency payment processing. Each provider also processes data under its own policies.
Spam protection queries DNS reputation services using sender infrastructure addresses, domains found in messages and, for some lists, hashes of message-related identifiers. These services and DNS resolvers can observe those queries. Malware scanning runs locally; the scanner downloads signed virus-database updates from ClamAV’s distribution service.
retention, deletion and backups
Mail and account settings remain while your account is active, subject to your deletion and inactivity settings. Security access is revoked when an account is deleted. Primary and random address retirement remains permanent. Minimal deletion records are retained to prevent older backups from reactivating a deleted identity.
Encrypted backups use a rolling seven-day retention window with capacity limits. Deleted content may remain in existing backups until their retention and pruning finish; deletion is not an immediate secure erase of historical storage. Billing, security and deletion metadata have operational retention separate from the live mailbox.
Backups are encrypted by Vael before transfer to Cloudflare R2 offsite storage. Cloudflare stores the encrypted backup objects. Recovery depends on separately protected recovery keys and successful backup checks.
your controls
You can export account data and mail, revoke sessions and app credentials, change image permissions, choose an inactivity policy, or delete your account. Contact us to ask about your data or rights available under applicable law.
registration protection
Vael runs its own Cap proof-of-work check for regular registration. The no-JavaScript site and Tor mirror use a text-image challenge. Challenge records and pseudonymous limits are short-lived; there are no CAPTCHA provider calls or browser fingerprinting. Registration cookies bind the challenge to your browser and expire after 30 minutes.