Privacy policy
This is placeholder text created for design review. It is not legal advice and not DMCN's final privacy policy — replace with counsel-reviewed language before publishing.
This policy explains what information DMCN does and does not process when your organization uses our encrypted email service. The short version: mail is encrypted on your devices, keys stay inside your organization, and we are built so there is as little to collect as possible.
1. Our approach
We designed DMCN to minimize the data we hold. Where ordinary email providers can read your organization's messages, we cannot: mail is encrypted on your devices and we only ever handle the encrypted form between DMCN inboxes. We hold no encryption keys — not even encrypted copies.
2. What we can and can't see
We cannot read the contents of DMCN-to-DMCN mail. We do process a limited amount of operational data needed to run the Service, such as account addresses, domain configuration and billing status.
Mail sent to or received from a regular email address is decrypted at the bridge to interoperate with standard email; it is protected in transit but is not end-to-end encrypted.
3. Administrator custody, disclosed
On a managed domain, your organization's administrator custodies account keys and can recover mailboxes. That is a relationship between account holders and their own organization — not with us — and it is disclosed in the product: managed accounts are visibly identified as managed.
4. Information we process
Account data: addresses and settings on your organization's domain. Billing data: your plan and payment status (payments are handled by our payment processor; we do not store full card numbers). Operational logs: minimal metadata needed for reliability and abuse prevention, retained for a limited period.
5. No ads, no tracking
We do not use advertising, third-party trackers, or content scanning. We do not sell or rent data. This site makes no third-party requests at all — fonts, styles and icons are served from our own origin.
6. Data retention
We keep operational data only as long as needed to provide the Service and meet legal obligations. When your organization leaves, you export your mail, and we delete associated operational data within a reasonable period, except where we must retain limited records by law.
7. Your rights and controls
Depending on jurisdiction, account holders may have rights to access, correct, export or delete personal data. Organizations can export their mail at any time. Contact us to exercise any additional rights.
8. Third parties
We use a small number of processors (for example, payment and infrastructure providers) strictly to operate the Service. They are bound to handle data only on our instructions and cannot access the contents of encrypted mail.
9. Changes to this policy
We may update this policy as the Service evolves. If we make material changes, we will notify your administrator before they take effect.