Legal

Privacy Policy

Last updated: August 13, 2026

Syzzle respects your privacy. This policy explains what information we collect, why we collect it, and how we handle it. In short: we keep data collection to the bare minimum needed to run your account.

Information we collect

Syzzle does not collect or maintain any personally identifiable information other than the following, and only when you create or use an account:

  • Email address — used as your login identifier and to contact you about your account.
  • Cell phone number — if you provide one, used for account verification or login.
  • Password — required to secure your account login.

We do not collect names, mailing addresses, payment card details, location data, browsing profiles, or any other personal information beyond what is listed above, unless you specifically authorize us to do so.

How your information is used

The information above is used solely to authenticate you, secure your account, and communicate with you about your account or the services you use. We do not sell, rent, or share your information with third parties for marketing purposes.

How your information is stored

Account credentials are managed through a third-party authentication provider. Passwords are stored in securely hashed form — Syzzle never stores or has access to your plain-text password. This provider's handling of the data is governed by its own privacy and security practices.

Mobile applications

This policy also covers the Syzzle Status apps for Android, iOS and macOS, which display the health of Syzzle's mail services.

What the apps collect

  • Email address. Used to sign you in. The apps send a one-time sign-in link to your Syzzle mailbox; they never ask for, store, or transmit your mailbox password.
  • Session token. A random token issued after sign-in, stored encrypted on your device and used to authenticate subsequent requests. On Android it is held in Android's encrypted storage, under a key kept in the system keystore and tied to that device. It is deleted when you sign out, when your account is deleted, or when it expires.
  • Device notification token. If you allow notifications, the app registers a token with the platform's push service (Google's Firebase Cloud Messaging on Android, Apple Push Notification service on iOS and macOS) and sends it to our servers so we can alert you when a mail service goes down. This token identifies the app installation on your device, not you personally, and is used for no purpose other than delivering these service alerts.
  • Sign-in records. Each time you sign in, we record your email address, the date and time, the method used, and the IP address the request came from. This is kept for security purposes — so that unauthorised access to an account can be identified. Resuming an existing session is not recorded; only new sign-ins are.

What the apps do not collect

The apps contain no advertising, no analytics or tracking SDKs, and no third-party data brokers. We do not collect the contents of your mail, your contacts, your location, or your device's address book. We do not sell or rent any of this data.

Who it is shared with

Your notification token is necessarily shared with Google (Firebase Cloud Messaging) or Apple (APNs) in order to deliver a notification to your device — this is how push notification delivery works on those platforms, and neither receives the contents of your mailbox. Sign-in records and device tokens are stored in Google Firebase, acting as our data processor. No data is shared with anyone else.

How long it is kept

Session tokens expire automatically and are deleted when they do, or when you sign out. Device notification tokens are deleted when you sign out, when you disable notifications, or automatically once the platform reports the token is no longer valid. Sign-in records are kept for up to 90 days and are then deleted automatically.

Deleting your data

You can delete your account from inside the app, under the Account tab. This immediately revokes every active session and removes every notification token associated with your address, and sends a removal request to our administrators. You can also request deletion at any time by emailing support@syzzle.com. Note that removal of the mailbox itself is carried out by an administrator and is not instantaneous.

Cookies and tracking

We use only the essential cookies or local storage required to keep you signed in during a session. We do not use advertising or third-party tracking cookies.

Your choices

You may request access to, correction of, or deletion of your account information at any time. Deleting your account removes your email, phone number, and credentials from our authentication records.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above.

Contact us

Questions about this policy? Reach us at support@syzzle.com or through our contact page.