Privacy notice
Last updated: 19 September 2026
This notice explains processing of personal data when you visit or use Cloakmail, as required by Articles 13 and 14 GDPR, the German Federal Data Protection Act (BDSG) and section 25 of the German TDDDG (terminal equipment). It is a transparency document, not a certification and not counsel sign-off.
1. Controller
The controller is the provider of Cloakmail:
Nordiqo Einzelunternehmen, Hohensteiner Straße 2, 27751 Delmenhorst, Deutschland; E-Mail: postmaster@cloakmail.eu
Further provider particulars are in the legal notice (Impressum).
2. Data protection officer
No data protection officer is appointed at this time. Use the email above for rights requests. If Article 37 GDPR or section 38 BDSG later requires an appointment, this notice will be updated.
3. Purposes and legal bases
We process data only for specified purposes:
- Art. 6(1)(b) GDPR: contract or pre-contractual steps — account, Glint, Cloaks, delivering and displaying mail, Premium.
- Art. 6(1)(c) GDPR: legal obligation — in particular tax/commercial retention of billing records and disclosures required by law.
- Art. 6(1)(f) GDPR: legitimate interests — operational security, abuse prevention, rate limiting, integrity of encryption. We do not advertise or profile. Data minimisation and short retention balance the interest.
- Section 25(2) TDDDG: storing or reading information on your device only where strictly necessary to provide the service you requested (session, CSRF protection, chosen language/theme, Glint session).
We do not currently rely on consent under Art. 6(1)(a) GDPR or section 25(1) TDDDG, because we do not use non-essential trackers or third-party cookies. A consent request would appear before that changes.
4. Hosting and infrastructure
Cloakmail runs on the controller’s own infrastructure in the European Union (application, PostgreSQL, Redis, MinIO object storage, mail intake). Message bodies are envelope-encrypted before storage.
Application logs include method, route template, status, timing and a request id. They do not include IP address, user agent, cookie values or message content.
5. Accountless Glint
You can create a temporary address without a name or login email. We store a recovery verifier, not the secret in plaintext. Anyone who has the one-time secret can open the mailbox.
The address and its messages end with the configured lifetime (default 60 minutes), then address quarantine (default 30 days, content already gone), then physical deletion.
The Glint session lives in your browser (localStorage, so every tab shows the same inbox) and on the server until the address expires (default 60 minutes). This is not anonymity; security controls still apply.
6. Account, session and security
An account uses your login email, a password verifier (Argon2id), account status and sessions. The session cookie is HttpOnly. A second cookie supports CSRF protection.
Where abuse correlation needs a network identifier, we store a hash, not the raw IP in application logs. Sessions last until expiry (default 12 hours) or revocation, then a short cleanup window (default 7 days).
Email verification and password-reset tokens are short-lived (default 24 hours and 60 minutes).
7. Mail content and third parties (Art. 14 GDPR)
When someone writes to a Cloak or Glint address we process envelope metadata, a spam verdict and the encrypted body including attachments, so we can show you the message or forward it to a destination you verified.
Third-party messages may contain personal data about the sender or people named in the body. We did not collect that data from those people (Art. 14 GDPR). Notifying every sender individually would be disproportionate (Art. 14(5)(b) GDPR). This public notice stands in, where the law allows.
Legal basis towards you: Art. 6(1)(b) GDPR, and Art. 6(1)(f) for security and spam controls. We do not analyse message bodies for advertising or profiling. Remote images in HTML mail are blocked by default so tracking pixels do not hit your device.
8. Payments (Stripe)
Premium is billed through Stripe. You enter card or wallet details at Stripe. Cloakmail does not store card numbers, CVC or full account numbers. We store Stripe customer and subscription ids, plan status, timestamps, and event ids or hashes for idempotency.
Stripe acts as a processor under Art. 28 GDPR. The contractual basis is the Stripe Data Processing Addendum, accepted by the operator in the Stripe Dashboard:
https://stripe.com/legal/dpa
Stripe privacy notice: https://stripe.com/privacy
Stripe Payments Europe, Limited (Ireland) is the relevant Stripe entity for EEA customers. Stripe may use sub-processors, including in the United States, with adequacy decisions, the EU–US Data Privacy Framework where certified, and Standard Contractual Clauses. Current sub-processors: https://stripe.com/legal/privacy-center
Legal bases: Art. 6(1)(b) and 6(1)(c) GDPR. Stripe event rows are deleted after a short operational window (default 30 days).
9. Storage on your device (TDDDG)
We only store what is needed for the service you asked for. There is no tracking and no cookie banner, because we do not set non-essential third-party cookies.
- Cookie cloakmail_session: sign-in, HttpOnly, Secure in production, SameSite=Lax, lifetime of the session (default 12 hours).
- Cookie cloakmail_csrf: CSRF protection for the same lifetime, readable by our script.
- localStorage cloakmail.tempSession: accountless Glint token, ends when the address expires or you clear site data.
- localStorage cloakmail.locale / cloakmail.theme / cloakmail.density: language, appearance and inbox density you chose.
This storage falls under section 25(2) no. 2 TDDDG (strictly necessary). Clearing cookies and site data ends sessions and local preferences.
10. Recipients and processors
Current overview:
- Own EU infrastructure (application, database, Redis, MinIO, mail intake): operated by the controller; message content is not handed to a third-party hosting brand in normal operation.
- Stripe Payments Europe, Limited: payments; DPA in section 8.
- Transactional system email (verification, password reset), if SMTP egress is configured: only to your account address, never mailbox message bodies.
Authorities receive data only where legally required. We do not sell data. There are no advertising partners and no third-party analytics vendors.
11. International transfers
Mail content and account data stay on the controller’s EU infrastructure. A third-country transfer arises mainly through Stripe (section 8). Where Stripe transfers data to the United States or other third countries, Stripe’s published safeguards apply (adequacy / Data Privacy Framework and Art. 46 GDPR standard contractual clauses).
We do not load US webfonts, tag managers or social plugins.
12. Retention
These periods are engineering defaults and may be extended by configuration or statutory retention:
- Glint content: until address expiry (default 60 minutes), then content deletion.
- Alias after expiry or delete: quarantine without content (default 30 days), then physical delete.
- Account: until deletion, then prompt purge. Payment records may last longer where tax law requires.
- Sessions: expiry plus cleanup (default 7 days).
- Abuse scores: until expires_at (default 30 days).
- Audit events (no message bodies): default 90 days.
- Encrypted backups: default 14 days, separate from the application key.
13. Your rights
You have GDPR rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection to Art. 6(1)(f) processing (Art. 21). Consent can be withdrawn at any time; we do not currently run the service on consent.
In the account you can export data and request deletion. Without an account, Glint ends by expiry. Written requests: postmaster@cloakmail.eu.
You may lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular where you live or work. The German Federal Commissioner for Data Protection and Freedom of Information: https://www.bfdi.bund.de. The authority for the controller is the Land authority of the establishment once the service address is complete in the Impressum.
14. Obligation to provide data
Glint does not require identity data. An account needs an email address. Premium needs the payment details Stripe requests. Without them the corresponding part of the service cannot be performed.
15. Automated decisions
We do not take automated decisions with legal effect under Art. 22 GDPR. Spam and abuse checks may filter mail or limit requests; they are not credit decisions.
16. Data protection impact assessment
Receiving third-party mail, short-lived content, accountless access, abuse controls and key management can be high-risk processing under Art. 35 GDPR. An internal DPIA exists as an operational record. It is not published; a supervisory authority may request it.
17. Children
The service is not directed at children under 16. Glint does not collect age; contractual use requires legal capacity or guardian consent.
18. Changes
We will update this notice when processing or the law changes. The current version applies to future use. The date is stated above.
