What we hold, who else touches it, and how to take it back.
Not categories of data. The actual records, and the reason each one exists.
Open the network tab while you use Nyxe. Nothing below is requested, because none of it is installed.
Everyone who can see any part of your data, and the exact part they see. There is nobody else.
Deletion here means deletion. The two records that outlive an account are named, because a policy that says everything goes is the kind you find out about later.
Nyxe is operated by MZED Studio Limited, a company registered in England and Wales under number 15854033, with its registered office at 8 Eastfield Close, Townhill, Swansea, Wales, SA1 6SG. We are the data controller for everything described on this page.
For anything about this policy, including a request to see or delete your data, write to mzed@mzed.studio.
Most of it is because you asked us to run a mailbox for you: that is a contract, and we cannot deliver the service without the mail. Sign-in records, rate limits and abuse controls rest on our legitimate interest in keeping the service up and keeping spam off it. Invoices are a legal obligation.
We do not rely on consent for anything, which is why there is no cookie banner to dismiss.
Your mail and your account records are stored on servers in the European Union, and mail you send leaves from there.
Three of the companies above operate outside the UK and EU: Stripe, Google and Expo. Each of them receives a narrow slice, as described, and each transfer is covered by the standard contractual clauses and the UK addendum.
Everything is encrypted in transit, and the credentials that connect the parts of the system to each other are encrypted at rest with AES-256.
Your messages themselves are not end-to-end encrypted. We should be blunt about what that means: an operator with access to the server could read them. We do not, and only a very small number of people can reach production at all, but a promise is not a guarantee and we are not going to dress it up as one. If you need mail nobody but the recipient can read, use PGP or S/MIME inside it, which works here as it does anywhere else.
One cookie, set when you sign in, so the next page knows it is still you. It lasts seven days and renews while you are using the app. It is strictly necessary, it is not shared, and there is nothing else to configure.
Under UK GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and object to anything we do on the basis of legitimate interest. Export is already self-service, and so is deletion, but write to us and we will do it either way.
We answer within one month. If you think we have got it wrong, you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first.
If your mailbox was created for you by an employer or a team, that organisation controls the account. Its administrators can see who is in the team and what has been shared with them, and can suspend or remove a member.
They cannot read an active member's mail. If a mailbox is suspended or handed over, for example when someone leaves, an administrator can export it, because at that point it is the organisation's mail rather than yours.
Flow runs on your Mac. Our servers know three things about it: that your account is entitled to use it, which devices you have activated, and when the licence was last refreshed.
There is no endpoint on our side that accepts audio, text or anything Flow has remembered, so none of it reaches us. If you turn on a cloud model inside Flow, what you send goes to that provider under their terms, not ours.
Nyxe is not for under-16s. We do not knowingly hold data about one, and we will delete the account if we find out.
When this policy changes, the date at the top changes with it. If a change actually affects what we do with your data, rather than how it is worded, we will email you before it takes effect.
A person answers, and data requests get a month at the very most.
one address for support, billing, privacy and security