Last updated: 23 May 2026
At Mailotte, privacy is not a feature — it is the foundation of everything we build. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have to control your data. Mailotte is operated by MAILOTTE LTD, a company incorporated in England and Wales, and we comply with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018. Although our company is registered in the United Kingdom, your mailboxes, attachments, and account data are stored exclusively on servers located in the European Union (Germany).
The data controller responsible for your personal data is:
We collect the minimum amount of information necessary to provide and secure our email service.
We do NOT scan your emails for advertising, build advertising profiles, sell your data, train machine-learning models on your private email content, or track you across other websites.
We do not sell, rent, or trade your personal information. We share limited data only with trusted service providers (subprocessors) bound by data processing agreements, or where required by law. Our current subprocessors include:
Your stored email content remains in the European Union (Germany) and is never transferred outside the EEA. Because MAILOTTE LTD is a UK company that administers EU-hosted infrastructure, limited personal data (such as account and billing identifiers) may be accessed from the United Kingdom; UK–EU transfers are covered by the mutual adequacy decisions in force between the UK and the EU. Where a subprocessor processes data outside the UK and EEA (for example, Stripe via its US affiliates), the transfer is covered by Standard Contractual Clauses and the UK International Data Transfer Addendum under GDPR Art. 46.
AI processing. Mailotte’s AI features run primarily on a local model hosted on our own servers in Germany, with an EU-resident fallback (Mistral AI). We do not send your email content to OpenAI, Anthropic, Google, or any other US-based AI provider, and we do not train models on your private content.
Push notifications. If you enable browser push, alerts are reached through your browser vendor’s push service (Google, Apple, or Mozilla), which may route through the United States. Each notification is encrypted end-to-end under the Web Push standard (RFC 8291) before it leaves our servers, so the gateway can only relay an opaque message — it cannot read the sender, subject, or content. You can disable push at any time in Settings → Notifications.
Under the UK GDPR and EU GDPR you have the rights of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent. To exercise any of these, visit your Account Settings or contact privacy@mailotte.com. We respond within one month as required by law.
You can export all of your data at any time from your Account Settings in standard, portable formats (e.g. .eml for emails, vCard for contacts). You can also delete your account at any time, which permanently removes your personal data, emails, and associated content from our servers after a short grace period.
We retain personal data only as long as necessary. Account data is kept for the life of your account; security logs and login history for 90 days; mail delivery events for 30 days; items in Trash for 30 days; billing records as required by UK tax and accounting law.
Mailotte uses only essential cookies (authentication, security, and preferences). We do not use advertising cookies, third-party advertising trackers, cross-site tracking, or browser fingerprinting. See our Cookie Policy for full detail.
Mailotte is not directed at children under 16 (or the minimum age required in your country to consent to the processing of personal data). We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice within the service at least 30 days before the changes take effect.
If you believe our processing infringes data protection law, you may lodge a complaint with a supervisory authority. As MAILOTTE LTD is established in the United Kingdom, our lead authority is the UK Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom (ico.org.uk). If you are in the EEA, you may instead complain to the supervisory authority of your country of residence. Please contact us first so we can try to resolve your concern directly.
Questions about this Privacy Policy or your personal data can be sent to our data protection contact at privacy@mailotte.com.