Privacy Policy
Version 1.1, 23 September 2026.
1. Who is responsible
We are the controller for the data described below, except for the mail that arrives at your addresses: for that we act as processor on your instructions, and the Data Processing Agreement sets out the terms. Questions about this policy go to fabricatedemail-support@blackcurrantsecurity.com.
2. What we hold, where it lives, and for how long
| Data | Where it is stored | How long |
|---|---|---|
| Mail sent to your addresses — headers, subject, text and HTML bodies, sender and recipient, and the name, type and size of each attachment (never its content) | Cloudflare D1, EEUR region (European Union) | 24 hours from receipt, or until the address expires or is deleted, whichever is sooner |
| The addresses you register | Cloudflare D1, EEUR region | Until they expire or you delete them |
| API keys — a hash of the key, its name, and when it was created and revoked | Cloudflare D1, EEUR region; key metadata also in Azure | Until the account is deleted; revoking a key marks it revoked and keeps this record |
| Usage counters — messages stored and dropped, per month | Cloudflare D1, EEUR region | Two months, then pruned |
| Your account — the email address you sign in with, your identity provider's user identifier, your tier and account state, and the reason for a suspension while one lasts | Azure Cosmos DB, Sweden Central | Until you delete the account |
| Your sign-in — the email address you sign in with and the user identifier Microsoft Entra External ID gives it | Microsoft Entra External ID, on Microsoft's own infrastructure, under its terms | Until you delete the account, unless you use the same sign-in for another of our products; Microsoft then keeps it restorable for 30 days. A sign-in we refuse to open an account for stays until you ask us to delete it |
| The dashboard's sign-in token | Your browser tab's session storage; we store no sign-in session on our servers | Until you close the tab or sign out |
| Synchronisation logs, which record account identifiers and the changes pushed between our two systems, and a record of each service email we send: the address it went to and its subject | Azure, Sweden Central | 90 days |
| Quota-warning markers — your account identifier and the month a warning was sent | Azure, Sweden Central | 7 days |
| Stripe customer, subscription and price identifiers | Azure Cosmos DB, Sweden Central | Until the account is deleted — see section 6 |
| Logs of each API request and each incoming message, including the address the message was sent to | Cloudflare Workers Logs | 3 days |
| Cloudflare's log of every message sent to the mail domain — sender, recipient, subject, the SPF, DKIM and DMARC results, and whether it was delivered or rejected | Cloudflare Email Routing | 31 days |
| Application logs from the dashboard and its scheduled jobs | Azure Log Analytics, Sweden Central | 30 days |
Expired mail and addresses are deleted by a cleanup that runs every hour, so they normally remain for up to an hour past the times above, and longer if a cleanup run fails.
Both databases keep a restorable history for 7 days: Cloudflare D1 (mail, addresses, keys and usage counters) and Azure Cosmos DB (accounts, synchronisation logs and quota-warning markers). Data deleted from them can therefore be restored for up to 7 days after it was deleted.
The API itself runs on Cloudflare Workers, which execute at the Cloudflare location nearest the caller — so a request may be processed outside the European Union even though the data it reads is stored in the EEUR region.
3. Mail is other people's data too
The mail we store is sent by third parties, and it can contain personal data about people who are not you. It expires within 24 hours, and a cleanup that runs every hour deletes it: a test reads it within seconds, and holding it longer would enlarge what we hold about those people for no benefit. We do not index it, profile it, use it to train anything, or share it. Nobody at our end reads it as a matter of routine; we may inspect a specific message where a report, a platform-safety concern or a legal obligation makes it necessary, as the Acceptable Use Policy describes.
4. Why we are allowed to hold it
- Performing our contract with you (GDPR Article 6(1)(b)) — your account, your keys, your addresses, the mail we store for you to read, and the service emails we send you about quota, suspension and account deletion.
- Our legitimate interests (Article 6(1)(f)) — logs, usage counters and synchronisation records, kept to run the service, to keep it available, and to detect and stop abuse.
- A legal obligation (Article 6(1)(c)) — accounting records, and responses to valid legal process.
We send no marketing email. Every message we send is a service message: quota warnings at 80% and 100% of the monthly cap, suspension notices, account-deletion confirmations.
5. Who else processes it
| Sub-processor | What for | Where |
|---|---|---|
| Cloudflare | Inbound mail routing, the API, the message and address database | D1 in the EEUR region; Workers at the global edge |
| Microsoft — Azure | The account store, the dashboard, logs and metrics | Sweden Central |
| Microsoft — Entra External ID | Customer sign-in | Microsoft's own infrastructure, under its terms |
| Microsoft — Azure Communication Services | Sending the service emails listed in section 4 | Europe |
| Stripe, including Link | Payments as merchant of record: taxes, receipts, invoices and subscription management | Stripe's own infrastructure, under its terms |
We will update this table before adding a sub-processor. Transfers outside the European Economic Area rest on the providers' standard contractual clauses and their own transfer frameworks.
6. Payments
Purchases are sold through Link, Stripe's merchant-of-record service. We never see or store your card details. Stripe is the controller for the payment data it collects, under its own privacy policy; we hold only the customer, subscription and price identifiers it gives us, so that we know which tier your account is on. Deleting your account cancels its subscription and deletes the Stripe customer record.
7. Your rights
You may ask for a copy of your data, for it to be corrected or deleted, for processing to be restricted, and to object to processing based on our legitimate interests. Deleting your account from the dashboard does most of this immediately: your addresses, the mail held for them, your keys and your account record are removed, and the account record leaves only a marker that ensures the identifier is never reused. The restorable histories described in section 2 keep deleted data for up to 7 more days.
Data export is manual. Write to fabricatedemail-support@blackcurrantsecurity.com from the address on the account and we will send a JSON file containing your account record, your key metadata, your usage counters and your live addresses, within ten business days. Stored mail is not included: it expires within 24 hours, and you can read it through the API while it exists.
If you believe we have handled your data wrongly, please write to us first. You also have the right to complain to a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).
8. If someone else's mail is here
If mail addressed to you has been sent to a fabricatedemail address and you want it removed, write to abuse@fabricatedemail.com with the address and the approximate time. In any case, mail expires within 24 hours of arriving and a cleanup that runs every hour deletes it; using our addresses to receive mail intended for real people is prohibited by the Acceptable Use Policy, and an account doing it is suspended.
9. Changes
We will update the version and date at the top of this page when it changes, and email account holders before a change that materially affects them takes effect.