Privacy Policy

Version 1.1, 23 September 2026.

1. Who is responsible

We are the controller for the data described below, except for the mail that arrives at your addresses: for that we act as processor on your instructions, and the Data Processing Agreement sets out the terms. Questions about this policy go to fabricatedemail-support@blackcurrantsecurity.com.

2. What we hold, where it lives, and for how long

Data Where it is stored How long
Mail sent to your addresses — headers, subject, text and HTML bodies, sender and recipient, and the name, type and size of each attachment (never its content) Cloudflare D1, EEUR region (European Union) 24 hours from receipt, or until the address expires or is deleted, whichever is sooner
The addresses you register Cloudflare D1, EEUR region Until they expire or you delete them
API keys — a hash of the key, its name, and when it was created and revoked Cloudflare D1, EEUR region; key metadata also in Azure Until the account is deleted; revoking a key marks it revoked and keeps this record
Usage counters — messages stored and dropped, per month Cloudflare D1, EEUR region Two months, then pruned
Your account — the email address you sign in with, your identity provider's user identifier, your tier and account state, and the reason for a suspension while one lasts Azure Cosmos DB, Sweden Central Until you delete the account
Your sign-in — the email address you sign in with and the user identifier Microsoft Entra External ID gives it Microsoft Entra External ID, on Microsoft's own infrastructure, under its terms Until you delete the account, unless you use the same sign-in for another of our products; Microsoft then keeps it restorable for 30 days. A sign-in we refuse to open an account for stays until you ask us to delete it
The dashboard's sign-in token Your browser tab's session storage; we store no sign-in session on our servers Until you close the tab or sign out
Synchronisation logs, which record account identifiers and the changes pushed between our two systems, and a record of each service email we send: the address it went to and its subject Azure, Sweden Central 90 days
Quota-warning markers — your account identifier and the month a warning was sent Azure, Sweden Central 7 days
Stripe customer, subscription and price identifiers Azure Cosmos DB, Sweden Central Until the account is deleted — see section 6
Logs of each API request and each incoming message, including the address the message was sent to Cloudflare Workers Logs 3 days
Cloudflare's log of every message sent to the mail domain — sender, recipient, subject, the SPF, DKIM and DMARC results, and whether it was delivered or rejected Cloudflare Email Routing 31 days
Application logs from the dashboard and its scheduled jobs Azure Log Analytics, Sweden Central 30 days

Expired mail and addresses are deleted by a cleanup that runs every hour, so they normally remain for up to an hour past the times above, and longer if a cleanup run fails.

Both databases keep a restorable history for 7 days: Cloudflare D1 (mail, addresses, keys and usage counters) and Azure Cosmos DB (accounts, synchronisation logs and quota-warning markers). Data deleted from them can therefore be restored for up to 7 days after it was deleted.

The API itself runs on Cloudflare Workers, which execute at the Cloudflare location nearest the caller — so a request may be processed outside the European Union even though the data it reads is stored in the EEUR region.

3. Mail is other people's data too

The mail we store is sent by third parties, and it can contain personal data about people who are not you. It expires within 24 hours, and a cleanup that runs every hour deletes it: a test reads it within seconds, and holding it longer would enlarge what we hold about those people for no benefit. We do not index it, profile it, use it to train anything, or share it. Nobody at our end reads it as a matter of routine; we may inspect a specific message where a report, a platform-safety concern or a legal obligation makes it necessary, as the Acceptable Use Policy describes.

4. Why we are allowed to hold it

We send no marketing email. Every message we send is a service message: quota warnings at 80% and 100% of the monthly cap, suspension notices, account-deletion confirmations.

5. Who else processes it

Sub-processor What for Where
Cloudflare Inbound mail routing, the API, the message and address database D1 in the EEUR region; Workers at the global edge
Microsoft — Azure The account store, the dashboard, logs and metrics Sweden Central
Microsoft — Entra External ID Customer sign-in Microsoft's own infrastructure, under its terms
Microsoft — Azure Communication Services Sending the service emails listed in section 4 Europe
Stripe, including Link Payments as merchant of record: taxes, receipts, invoices and subscription management Stripe's own infrastructure, under its terms

We will update this table before adding a sub-processor. Transfers outside the European Economic Area rest on the providers' standard contractual clauses and their own transfer frameworks.

6. Payments

Purchases are sold through Link, Stripe's merchant-of-record service. We never see or store your card details. Stripe is the controller for the payment data it collects, under its own privacy policy; we hold only the customer, subscription and price identifiers it gives us, so that we know which tier your account is on. Deleting your account cancels its subscription and deletes the Stripe customer record.

7. Your rights

You may ask for a copy of your data, for it to be corrected or deleted, for processing to be restricted, and to object to processing based on our legitimate interests. Deleting your account from the dashboard does most of this immediately: your addresses, the mail held for them, your keys and your account record are removed, and the account record leaves only a marker that ensures the identifier is never reused. The restorable histories described in section 2 keep deleted data for up to 7 more days.

Data export is manual. Write to fabricatedemail-support@blackcurrantsecurity.com from the address on the account and we will send a JSON file containing your account record, your key metadata, your usage counters and your live addresses, within ten business days. Stored mail is not included: it expires within 24 hours, and you can read it through the API while it exists.

If you believe we have handled your data wrongly, please write to us first. You also have the right to complain to a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).

8. If someone else's mail is here

If mail addressed to you has been sent to a fabricatedemail address and you want it removed, write to abuse@fabricatedemail.com with the address and the approximate time. In any case, mail expires within 24 hours of arriving and a cleanup that runs every hour deletes it; using our addresses to receive mail intended for real people is prohibited by the Acceptable Use Policy, and an account doing it is suspended.

9. Changes

We will update the version and date at the top of this page when it changes, and email account holders before a change that materially affects them takes effect.