Privacy, stated plainly.
Trainmail is an ad-free hosted email service. Running email requires processing message content and account metadata. This page explains the current model without claiming protections that are not implemented.
The short version
Trainmail processes data to deliver mail, authenticate users, prevent abuse, provide support, maintain security, and operate the service. Trainmail does not claim that mailbox content is unreadable to the service itself.
Data the service processes
- Account data: mailbox address, authentication and recovery configuration, preferences, and account status.
- Email data: message headers, body content, attachments, folders, delivery metadata, and read state.
- Security data: IP address, approximate location derived from IP, device/browser details, session activity, failed sign-ins, and anti-abuse signals.
- Support and API data: tickets, API applications, key scopes and prefixes, request metadata, rate-limit events, and administrative audit records.
Operational and administrative access
Authorized administrators may access account metadata and, when necessary, mailbox content to investigate abuse, resolve a support request, respond to a security incident, maintain the mail system, or comply with a valid legal obligation. This is an operational capability of the current service and is why Trainmail should not be described as end-to-end encrypted.
Access should be limited to people who need it for those tasks and recorded where the relevant administrative workflow supports auditing. Users should never send passwords or session tokens to support.
Retention and deletion
Messages remain in a mailbox until they are deleted, moved by the user, removed by mailbox rules, or the account is closed or restricted under service policy. Security notifications are currently presented with a 90-day retention period. Operational logs, abuse evidence, support records, and backups may be retained for a limited period when needed for reliability, security, dispute handling, or legal obligations.
Backup deletion is not instantaneous. If a precise deletion deadline is important for a specific request, contact support before relying on the service for that data.
Encryption boundaries
Trainmail uses encrypted network connections for the web interface and supported mail protocols. Encryption in transit protects traffic between devices and servers when correctly negotiated. It does not make messages end-to-end encrypted and does not stop the sender's provider, recipient's provider, or Trainmail's mail infrastructure from processing message content.
Trainmail does not currently publish a claim that every mailbox and backup is encrypted at rest with user-controlled keys.
Your choices
- Use 2FA and review active sessions.
- Block external images by default in client security settings.
- Delete messages and attachments you no longer need.
- Contact support to ask about account closure, data access, or correction.
- Do not use Trainmail as the sole repository for data requiring end-to-end confidentiality unless you encrypt that content before sending it.
Privacy questions can be sent to support@trainmail.online with “Privacy request” in the subject.
Trainmail