Privacy Policy
Version 1.0, 2 September 2026.
1. Who is responsible
To be completed before launch. This section must name the company as controller — registered name, address, organisation number and contact address — in the wording confirmed with the company's accountant.
We are the controller for the data described below, except for the mail that arrives at your addresses: for that we act as processor on your instructions, and the Data Processing Agreement sets out the terms. Questions about this policy go to fabricatedemail-support@blackcurrantsecurity.com.
2. What we hold, where it lives, and for how long
| Data | Where it is stored | How long |
|---|---|---|
| Mail sent to your addresses — headers, subject, text and HTML bodies, sender and recipient | Cloudflare D1, EEUR region (European Union) | 24 hours from receipt, or until the address expires or is deleted, whichever is sooner |
| The addresses you register | Cloudflare D1, EEUR region | Until they expire or you delete them |
| API keys — a hash of the key, its name and creation date | Cloudflare D1, EEUR region; key metadata also in Azure | Until the key is revoked or the account is deleted |
| Usage counters — messages stored and dropped, per month | Cloudflare D1, EEUR region | Two months, then pruned |
| Your account — the email address you sign in with, your identity provider's user identifier, your tier and account state | Azure Cosmos DB, Sweden Central | Until you delete the account |
| Sign-in sessions | Azure, Sweden Central | 30 days |
| Synchronisation logs, which record account identifiers and the changes pushed between our two systems | Azure, Sweden Central | 90 days |
| Stripe customer and subscription identifiers | Azure Cosmos DB, Sweden Central | Until the account is deleted — see section 6 |
| Request logs from the API | Cloudflare Workers Logs | 3 days |
| Application logs and metrics from the dashboard | Azure Application Insights, Sweden Central | 30 days |
The API itself runs on Cloudflare Workers, which execute at the Cloudflare location nearest the caller — so a request may be processed outside the European Union even though the data it reads is stored in the EEUR region.
To be completed before launch. The geography of the Microsoft Entra External ID tenant that holds customer sign-in identities must be recorded here.
3. Mail is other people's data too
The mail we store is sent by third parties, and it can contain personal data about people who are not you. We keep it for 24 hours because a test reads it within seconds, and holding it longer would enlarge what we hold about those people for no benefit. We do not index it, profile it, use it to train anything, or share it. Nobody at our end reads it as a matter of routine; we may inspect a specific message where a report or a legal obligation makes it necessary, as the Acceptable Use Policy describes.
4. Why we are allowed to hold it
- Performing our contract with you (GDPR Article 6(1)(b)) — your account, your keys, your addresses, the mail we store for you to read, and the service emails we send you about quota, suspension and account deletion.
- Our legitimate interests (Article 6(1)(f)) — logs, usage counters and synchronisation records, kept to run the service, to keep it available, and to detect and stop abuse.
- A legal obligation (Article 6(1)(c)) — accounting records, and responses to valid legal process.
We send no marketing email. Every message we send is a service message: quota warnings at 80% and 100% of the monthly cap, suspension notices, account-deletion confirmations.
5. Who else processes it
| Sub-processor | What for | Where |
|---|---|---|
| Cloudflare | Inbound mail routing, the API, the message and address database | D1 in the EEUR region; Workers at the global edge |
| Microsoft — Azure | The account store, the dashboard, logs and metrics | Sweden Central |
| Microsoft — Entra External ID | Customer sign-in | See the note in section 2 |
| Microsoft — Azure Communication Services | Sending the service emails listed in section 4 | Sweden Central |
| Stripe, including Link | Payments as merchant of record: taxes, receipts, invoices and subscription management | Stripe's own infrastructure, under its terms |
We will update this table before adding a sub-processor. Transfers outside the European Economic Area rest on the providers' standard contractual clauses and their own transfer frameworks.
6. Payments
Purchases are sold through Link, Stripe's merchant-of-record service. We never see or store your card details. Stripe is the controller for the payment data it collects, under its own privacy policy; we hold only the customer and subscription identifiers it gives us, so that we know which tier your account is on.
To be completed before launch. The retention of Stripe customer records after account deletion — whether the customer record is deleted with the account or kept for the statutory bookkeeping period — must be stated here in the wording confirmed with the company's accountant. Until it is confirmed, deleting an account cancels its subscription and deletes the Stripe customer record.
7. Your rights
You may ask for a copy of your data, for it to be corrected or deleted, for processing to be restricted, and to object to processing based on our legitimate interests. Deleting your account from the dashboard does most of this immediately: your addresses, the mail held for them, your keys and your account record are removed, and the account record leaves only a marker that ensures the identifier is never reused.
Data export is manual. Write to fabricatedemail-support@blackcurrantsecurity.com from the address on the account and we will send a JSON file containing your account record, your key metadata, your usage counters and your live addresses, within ten business days. Stored mail is not included: it expires within 24 hours, and you can read it through the API while it exists.
If you believe we have handled your data wrongly, please write to us first. You also have the right to complain to a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).
8. If someone else's mail is here
If mail addressed to you has been sent to a fabricatedemail address and you want it removed, write to abuse@fabricatedemail.com with the address and the approximate time. Mail is deleted 24 hours after it arrives in any case; using our addresses to receive mail intended for real people is prohibited by the Acceptable Use Policy, and an account doing it is suspended.
9. Changes
We will update the version and date at the top of this page when it changes, and email account holders before a change that materially affects them takes effect.