Email Archive Toolkit

Privacy policy

Your files stay yours.

This policy explains what is processed on your device, what limited information may reach our service providers, and the choices and rights available to you.

Effective and last updated: August 27, 2026

Pre-launch legal identity required

This draft must not be used for a public commercial launch until the operator name, business address, jurisdiction, privacy email, and support email are configured. See the Legal notice.

1. Scope and controller

This policy applies to the public website, browser-based conversion tools, support communications, and paid onboarding services offered under the Email Archive Toolkit name. The data controller or business responsible for personal information is the operator identified in the Legal notice. The complete operator identity and contact details appear in our Legal notice.

2. Email files and generated output

EML files, message bodies, headers, attachments, generated PDFs, checksums, manifests, and ZIP archives are processed locally by your browser. The current website has no document-upload endpoint and does not intentionally transmit these materials to us or store them in a document database.

Processing uses temporary browser memory and download objects. The application does not intentionally place document contents in cookies, localStorage, IndexedDB, analytics events, error reports, or advertising systems. Closing or resetting the page releases application references, although your browser, operating system, downloads folder, extensions, backup software, or device administrator may retain copies outside our control.

3. Information that may reach us

  • Connection and security data: our hosting and network providers may process IP address, request time, requested URL, referring information, device and browser headers, approximate network location, and security events to deliver and protect the site.
  • Messages you send: if you contact privacy, support, or sales, we receive the details and content you choose to provide, plus ordinary email metadata.
  • Transaction records: if you purchase a service later, the selected payment provider will process payment details. We should receive transaction identifiers, status, amount, billing contact details, and tax records—not full card numbers.

Do not attach confidential email files to support or sales messages unless we expressly request them and provide an approved secure transfer method.

4. Purposes and legal bases

Where a legal basis is required, we process ordinary connection data to provide and secure the website based on performance of requested services and legitimate interests in reliable, abuse-resistant operations. We process inquiries to respond to your request, take steps before a contract, perform a contract, or pursue legitimate business interests. We retain legally required transaction records to meet accounting, tax, fraud-prevention, and legal obligations.

We do not use locally processed email content for advertising, artificial-intelligence training, profiling, or automated decisions about individuals.

5. Cookies, analytics, and advertising

The current application does not set advertising cookies, analytics cookies, or cross-site tracking identifiers and does not include third-party advertising or analytics scripts. The hosting provider may use strictly necessary security mechanisms when needed to detect abuse. See our Cookie Policy.

If analytics, advertising, or optional storage is added, this policy and the Cookie Policy must be updated before activation, and consent will be requested where applicable.

6. Disclosures and service providers

We may disclose the limited information described above to infrastructure, security, email, professional-adviser, and payment providers only as reasonably necessary for their services; to comply with law or protect rights and safety; or as part of a genuine merger, financing, acquisition, or sale subject to appropriate confidentiality and notice. Providers have their own legally required processing and retention practices.

We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not disclose locally processed email files because the current service does not receive them.

7. Retention

We do not retain locally processed documents. Hosting and security logs are retained according to provider settings and operational necessity. Routine support and sales correspondence is normally deleted or anonymized within 24 months after the last meaningful interaction unless a shorter request is valid or longer retention is necessary for an active relationship, dispute, security investigation, or legal obligation. Transaction and tax records are kept for the period required by applicable law.

8. International processing

Hosting, email, and other providers may process limited information in countries other than yours. Where required, we will use a recognized transfer mechanism or another lawful safeguard. Local processing of your email files substantially limits the document data exposed to international transfers.

9. Your privacy rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may appeal or complain to a privacy regulator. You may also have rights to know categories and sources of information, recipients, and purposes, and to receive equal service when exercising a right.

We will verify requests proportionately and respond within the legally required period. Because document content never reaches us, we cannot retrieve, delete, or provide a copy of a file that remained solely on your device.

10. Children

The service is intended for business and general adult use and is not directed to children under 16. Do not use the service to submit information to us about a child without appropriate legal authority. Contact us if you believe a child has provided information directly to us.

11. Security and incident scope

We use data minimisation, a static hosting model, security headers, dependency review, and automated tests. No system can be guaranteed secure. Compromised devices, browser extensions, downloaded files, third-party providers, and user-configured storage remain outside the application boundary. Our Security page describes these limits.

12. Changes and contact

We may update this policy when functionality, providers, or laws change. Material changes will be identified by a new effective date and, where legally required, additional notice or consent.

Privacy requests must be sent to the privacy contact listed in the Legal notice. You may also complain to the data-protection or consumer-protection authority where you live.