Privacy Policy

Version 1.0, 2 September 2026.

1. Who is responsible

To be completed before launch. This section must name the company as controller — registered name, address, organisation number and contact address — in the wording confirmed with the company's accountant.

We are the controller for the data described below, except for the mail that arrives at your addresses: for that we act as processor on your instructions, and the Data Processing Agreement sets out the terms. Questions about this policy go to fabricatedemail-support@blackcurrantsecurity.com.

2. What we hold, where it lives, and for how long

Data Where it is stored How long
Mail sent to your addresses — headers, subject, text and HTML bodies, sender and recipient Cloudflare D1, EEUR region (European Union) 24 hours from receipt, or until the address expires or is deleted, whichever is sooner
The addresses you register Cloudflare D1, EEUR region Until they expire or you delete them
API keys — a hash of the key, its name and creation date Cloudflare D1, EEUR region; key metadata also in Azure Until the key is revoked or the account is deleted
Usage counters — messages stored and dropped, per month Cloudflare D1, EEUR region Two months, then pruned
Your account — the email address you sign in with, your identity provider's user identifier, your tier and account state Azure Cosmos DB, Sweden Central Until you delete the account
Sign-in sessions Azure, Sweden Central 30 days
Synchronisation logs, which record account identifiers and the changes pushed between our two systems Azure, Sweden Central 90 days
Stripe customer and subscription identifiers Azure Cosmos DB, Sweden Central Until the account is deleted — see section 6
Request logs from the API Cloudflare Workers Logs 3 days
Application logs and metrics from the dashboard Azure Application Insights, Sweden Central 30 days

The API itself runs on Cloudflare Workers, which execute at the Cloudflare location nearest the caller — so a request may be processed outside the European Union even though the data it reads is stored in the EEUR region.

To be completed before launch. The geography of the Microsoft Entra External ID tenant that holds customer sign-in identities must be recorded here.

3. Mail is other people's data too

The mail we store is sent by third parties, and it can contain personal data about people who are not you. We keep it for 24 hours because a test reads it within seconds, and holding it longer would enlarge what we hold about those people for no benefit. We do not index it, profile it, use it to train anything, or share it. Nobody at our end reads it as a matter of routine; we may inspect a specific message where a report or a legal obligation makes it necessary, as the Acceptable Use Policy describes.

4. Why we are allowed to hold it

We send no marketing email. Every message we send is a service message: quota warnings at 80% and 100% of the monthly cap, suspension notices, account-deletion confirmations.

5. Who else processes it

Sub-processor What for Where
Cloudflare Inbound mail routing, the API, the message and address database D1 in the EEUR region; Workers at the global edge
Microsoft — Azure The account store, the dashboard, logs and metrics Sweden Central
Microsoft — Entra External ID Customer sign-in See the note in section 2
Microsoft — Azure Communication Services Sending the service emails listed in section 4 Sweden Central
Stripe, including Link Payments as merchant of record: taxes, receipts, invoices and subscription management Stripe's own infrastructure, under its terms

We will update this table before adding a sub-processor. Transfers outside the European Economic Area rest on the providers' standard contractual clauses and their own transfer frameworks.

6. Payments

Purchases are sold through Link, Stripe's merchant-of-record service. We never see or store your card details. Stripe is the controller for the payment data it collects, under its own privacy policy; we hold only the customer and subscription identifiers it gives us, so that we know which tier your account is on.

To be completed before launch. The retention of Stripe customer records after account deletion — whether the customer record is deleted with the account or kept for the statutory bookkeeping period — must be stated here in the wording confirmed with the company's accountant. Until it is confirmed, deleting an account cancels its subscription and deletes the Stripe customer record.

7. Your rights

You may ask for a copy of your data, for it to be corrected or deleted, for processing to be restricted, and to object to processing based on our legitimate interests. Deleting your account from the dashboard does most of this immediately: your addresses, the mail held for them, your keys and your account record are removed, and the account record leaves only a marker that ensures the identifier is never reused.

Data export is manual. Write to fabricatedemail-support@blackcurrantsecurity.com from the address on the account and we will send a JSON file containing your account record, your key metadata, your usage counters and your live addresses, within ten business days. Stored mail is not included: it expires within 24 hours, and you can read it through the API while it exists.

If you believe we have handled your data wrongly, please write to us first. You also have the right to complain to a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).

8. If someone else's mail is here

If mail addressed to you has been sent to a fabricatedemail address and you want it removed, write to abuse@fabricatedemail.com with the address and the approximate time. Mail is deleted 24 hours after it arrives in any case; using our addresses to receive mail intended for real people is prohibited by the Acceptable Use Policy, and an account doing it is suspended.

9. Changes

We will update the version and date at the top of this page when it changes, and email account holders before a change that materially affects them takes effect.