Closed beta — effective May 2026
Privacy Policy
What data TELVRIX collects, how it’s used, and your rights.
Closed beta
TELVRIX is pre-release, closed-beta software. Formal compliance certifications (SOC 2, GDPR DPA) and automated deletion SLAs are not yet in place. Do not use TELVRIX for regulated health data (PHI), payment card data (PCI), or other legally regulated content.
Data we collect
Account data
- Email address (used for login and account identification)
- Display name (optional, user-provided)
- Account creation date
Mailbox connection data
- IMAP host, port, username — stored as ordinary columns; a hostname is not a secret
- IMAP password — AES-256-GCM encrypted; never logged or displayed
- SMTP host, port, username, password — same encryption
Synced email data
- Message metadata: sender name, subject, date, folder, flags (read/starred/etc.)
- Message body: plain text and HTML content (stored for display and search)
- Recipient headers (To, CC) for sent message display
- Attachment metadata: filename and content-type (not the file bytes)
- Thread relationships: grouping messages into conversations
Note: TELVRIX stores email content in a Supabase database to enable offline access and full-text search. This is the core function of the service.
App-generated data
- Labels you create and apply
- Draft emails (stored until sent or deleted)
- Contacts extracted from your mail for autocomplete
- Signature content you write
- Response templates you create
- Workspace events (connect mailbox, invite member, etc.)
How we use your data
To provide the service: We sync your emails, store them for display, and use the content for search and filtering within your account only.
No content analysis for advertising: We do not read, analyze, or process your email content for advertising, behavioral profiling, or any purpose other than providing the email client features.
No data selling: We do not sell, rent, or share your personal data or email content with third parties for their commercial purposes.
Service improvement: Aggregate usage patterns (e.g., feature adoption rates, error rates) may be analyzed to improve the product. This does not involve reading email content.
Operator access: Platform operators can view mailbox health status and aggregate system metrics. They cannot access your email content, subjects, or credentials through the admin interface.
Data retention
Plans publish a retention period — 30 days on Free, longer on paid plans — but nothing deletes old messages automatically yet. The limit is stated, not enforced.
Deleting a message moves it to trash, where it stays until you empty the trash yourself. There is no scheduled purge, so treat a deleted message as hidden rather than gone until you remove it.
Disconnecting a mailbox removes the mailbox record and credentials. Synced messages are not automatically deleted when you disconnect — you can delete them manually or contact support.
Account deletion removes all associated data. During closed beta, account deletion requires contacting support, and is handled within a few days.
Your rights
During closed beta, you can:
- Access: All your data is accessible through the TELVRIX interface.
- Export: Contact the operator team to request a data export.
- Delete: Delete messages, labels, and drafts directly in the app. For full account deletion, contact the operator team.
- Disconnect: Disconnect any mailbox at any time in Settings → Mail → Accounts.
Formal rights requests (GDPR Article 17, CCPA deletion) will be supported via a formal process before general availability.
Who else processes your data
TELVRIX is not a closed box. These are the services your data can reach, and what reaches them:
- Supabase — the Postgres database and authentication behind your deployment. Everything TELVRIX stores lives here, including message bodies and encrypted mailbox credentials.
- Your hosting provider — runs the application, so mail passes through its memory in transit.
- Stripe — payment and subscription handling on paid plans. Receives billing identifiers, not mail.
- Anthropic — only if the operator has configured an AI key, and only when you press the AI draft-reply button. When you do, the sender name and address, the subject, and up to 500 characters from each of the last five messages in that thread are sent to Anthropic to compose the draft. Nothing is sent in the background, and with no key configured no message content leaves the deployment for this purpose at all.
- Your own mail provider — the IMAP and SMTP server you connected. Your mail itself is sent and received through your provider, not ours.
- A transactional email provider — Resend, Postmark or Amazon SES, whichever the operator configured. TELVRIX’s own messages to you — invitations, notifications, account mail — go out through it, so it receives the recipient address, the subject and the body of those messages. It never carries mail from your mailbox.
- Sentry — error reporting, and only if the operator configured a key. It receives server exceptions and a sample of performance traces. It is configured not to attach personal data, but an error report describes what the software was doing when it failed, so treat it as a place technical detail about your account can appear.
No third party receives your mail for its own purposes, and none of them is paid with your data.
Cookies and tracking
TELVRIX uses session cookies for authentication (SameSite=Lax). They are not HttpOnly: the browser reads your session out of the cookie, so setting that flag would break sign-in rather than harden it. No advertising cookies, tracking pixels, or third-party analytics scripts are loaded by the app, and remote images in received mail are blocked until you ask for them.
Read receipts (optional, opt-in per email) use a 1×1 tracking pixel in the sent email. This feature is off unless you switch it on for a specific message.
Be aware of what it collects, because it is about someone else: when the pixel loads, TELVRIX records the time, the recipient's IP address and their browser or mail client's user-agent string. Those are personal data belonging to your recipient, not to you, and enabling the feature makes you the one who decided to collect them.
Contact
For data requests, privacy questions, or concerns during closed beta, contact the operator team directly. A formal privacy contact address will be published before general availability.