Privacy Policy

Last updated 3 August 2026. We collect as little as possible, ask for no real-world identity, and describe the system's real limits without calling conventional email "zero access."

Who this policy covers

This policy covers the Neir website, webmail, SMTP, IMAP, and POP3 services operated from Sweden, including this no-JS edition. Questions or privacy requests can be sent to hello@neir.io.

No KYC and no identity profile

Neir does not and will never require know-your-customer checks or identity verification to create or use a mailbox. We do not ask for your legal name, home address, phone number, date of birth, government ID, selfie, proof of address, recovery email, or identity documents. There is no advertising profile, contact-list upload requirement, or mandatory fallback account.

Account creation and authentication (main JavaScript site)

Your browser generates an Account Key, a 12-word recovery phrase, and an OpenPGP key pair. The private PGP key is encrypted in the browser with an AES-GCM key derived from the Account Key. Registration and login send the Account Key through HTTPS so the server can verify it in memory; it is not retained in plaintext. We store an Argon2id verifier and a keyed lookup hash. The recovery phrase and app passwords are also stored only as one-way verifiers. Losing both the Account Key and recovery phrase means we cannot recover the account.

Account creation and authentication (this no-JS site)

This site cannot run browser-side cryptography. If you choose to sign up here, key generation happens on this server transiently, in memory only, and is disclosed and confirmed with you before it happens (see How it works). If you decline, you can sign up on the main site and use this one afterward. Reading a message on this site similarly requires your explicit, separately confirmed permission for the server to transiently decrypt it on your behalf, since your browser cannot do so without JavaScript.

Mailbox data

Optional account data

Operational logs and abuse prevention

Bounded web, mail, and security logs can contain source IP addresses, request paths, protocol events, timestamps, and error details, used for coarse emergency rate limiting and abuse defense. Shared Tor and VPN exits are not assigned a risk score, blocked as a category, or used to vary difficulty. These records are not added to an account profile or used for advertising.

Payments

Free accounts need no payment data. Pro purchases and payment processing are handled on the main site and are out of scope for this no-JS edition.

Analytics, trackers, and remote content

Neir has no advertising pixels, cross-site trackers, or third-party analytics SDKs. This no-JS site additionally strips all images (including remote images in email bodies) from every page it renders, so no image-based tracking is possible here at all.

Retention and deletion

Active mailbox data remains until you delete the message or account. Trash and Spam are emptied after 30 days. Account deletion immediately removes the live database account and makes its mailbox unavailable; Maildir directories are quarantined for three days before erasure. Local recovery backups rotate over approximately 8–14 days by backup class, so deleted data can remain in a restricted backup until that copy expires. Deletion is irreversible to the account holder.

Your choices and rights

You can revoke sessions and app passwords, disable optional tracking, delete messages, and permanently delete the account from Settings. Depending on applicable law, you may also request access, correction, erasure, restriction, portability, or object to processing by contacting us. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Changes

Material changes will be reflected on this page with a new update date. The no-KYC commitment is also part of the Terms of Service.