Privacy policy
How we process your data
This covers visits, contact, accounts, and files shared with you. Mail, files and calendars you store for others are covered by the DPA.
Last updated 2026-09-26.
Controller
Controller for account data is PineCore Systems, a trading name of Bröderna Saxin AB, company registration number 559379-4364, Lindesby 152, 713 94 Nora.
Write to contact@pinemail.app. You do not need an account to contact us.
Account
An account stores your email address, name, password hash and sessions, and, if you turn it on, your authenticator secret and recovery codes. We also keep which plan the account is on and how much storage and sending it uses, to apply the limits and, once card payment opens, to bill by use. Legal basis is the contract for the account and our legitimate interest in protecting it. Sessions last at most seven days.
Mail, files and calendars
Messages, attachments, files, calendars, contacts, recipients, subjects and delivery events are stored to provide the service you asked for. For that processing you are the controller and we are the processor; see the DPA. The database, with the message text, is on our server in Helsinki, Finland; attachments, original messages and files are stored encrypted on a server we run ourselves in Sweden, which also holds encrypted backups of the database. Message text, original messages, attachments and files are encrypted before they are written to disk; subjects, addresses, calendars and contacts are not. Which companies see content on its way is on the security page.
No AI training
We do not use your data, or the mail, files, calendars and contacts you store, to train AI models, and we do not sell it or hand it to anyone who does. This is also a term of the DPA and one of our promises.
When someone shares a file with you
If a PineMail user shares a file with your address or sends you large files, we use your address to send you the email with the link. If the file is shared with named people, you open it with a code we send to your address, valid for 15 minutes; after that a cookie in that browser lets you open it again for 24 hours. The person who shared the file sees whether your address has opened it and how many times the file has been downloaded.
The person who shared the file decides this and is the controller; we process it for them. A shared link stops working at the end date they chose or when they remove it. Large files sent this way are deleted when their time runs out, after 1 to 14 days, or sooner if the sender removes them.
How long we keep it
Account data is kept while the account exists. Mail you delete is removed for good 30 days after it goes to the trash. Codes for shared files expire after 15 minutes and are removed a day later. When the account ends, its data is deleted or, on request, returned first, except where the law requires us to keep it. Encrypted backups are at present kept without an end date, so deleted data remains in them; they are used only to restore the service after a failure.
Cookies and measurement
Sign-in uses necessary security cookies. No third-party analytics, no embedded social widgets. See cookies.
Who processes data for us
Hetzner Online GmbH, dedicated server in Helsinki, Finland, where the service and its database run, with the keys. Attachments, original messages and files are stored encrypted on a server we run ourselves in Sweden, which also holds the encrypted backups of the database.
Cloudflare answers DNS only. Cloudflare, Inc. is a US company; standard contractual clauses.
Amazon SES (AWS EMEA, part of the US company Amazon) in Stockholm relays outbound mail and sees it in transit. Content is stored only on our own servers. AWS DPA.
The public list is on /subprocessors.
Your rights
You have the right of access, rectification, erasure, objection, and restriction. You may complain to Integritetsskyddsmyndigheten (imy.se). Write to us first if you can.
TermsPrivacyPromisesSecurityDPASub-processorsCookiesAccessibilityPricingStatusAboutContact