Privacy Policy

Last updated: June 2026

This Privacy Policy explains what personal data cripta.to ("we", "our") collects, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable data protection laws.

1. Data We Collect

Account data

  • Email address — used for authentication and service communications.
  • Password — stored as a bcrypt hash; we never store or transmit your plaintext password.

Infrastructure credentials

  • Cloud provider API tokens (e.g. Hetzner Cloud) — stored encrypted in AWS Secrets Manager (AES-256). Used solely to provision and destroy Mail Environments on your behalf.
  • Mail server admin passwords — stored encrypted in AWS Secrets Manager and permanently deleted when a Mail Environment is destroyed.
  • SSH key names — stored as plain text; these are not sensitive secrets.

Deployment metadata

  • Domain names, server IP addresses, mail hostnames, deployment status, and timestamps — stored in our database to operate the Service.

Audit logs

  • Actions you perform (creating or destroying Mail Environments) are logged for security and debugging purposes.

Website analytics

  • Approximate country — derived from your IP address at the moment of your visit to cripta.to. The IP address itself is never stored or logged.
  • Browser language, pages and blog posts viewed, and time spent on each page — used to understand which content is useful and where visitors drop off during onboarding.
  • A temporary visit identifier — a random value held in your browser's session storage, not a cookie, cleared automatically when you close the tab. It only lets us tell whether page views within a single visit belong together; it is never used to recognise you across visits.

This analytics is first-party only — we do not use any third-party analytics provider — and the data is never shared, sold, or used for advertising. If your browser sends a Do Not Track or Global Privacy Control signal, no analytics data is collected for that visit.

Data we do NOT collect

  • We do not have access to the emails you send or receive. Your mail server runs on your infrastructure and we do not process email content.
  • We do not use tracking pixels, third-party analytics, or advertising networks.

2. How We Use Your Data

  • To authenticate you and maintain your account.
  • To deploy, configure, and destroy Mail Environments you request.
  • To send transactional emails (deployment status, security alerts).
  • To improve and debug the Service.
  • To comply with legal obligations.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Data Retention

  • Account data is retained as long as your account is active. You may request deletion at any time.
  • API tokens and admin passwords are deleted from Secrets Manager when you delete the associated provider or destroy the Mail Environment.
  • Audit logs are retained for 12 months.
  • Deployment metadata for destroyed environments is retained in anonymised form for analytics.
  • Website analytics events (Section 1, "Website analytics") are retained for 90 days, then automatically deleted.

4. Data Storage and Security

Our backend infrastructure runs on AWS in the eu-central-1 (Frankfurt, Germany) region. Sensitive credentials are encrypted at rest using AWS KMS. We apply the principle of least privilege to all service components.

5. Your Rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.

To exercise any of these rights, email us at privacy@cripta.to. We will respond within 30 days.

6. Cookies and Local Storage

We use only a single session cookie to maintain your authenticated state; we do not use tracking or advertising cookies. Website analytics (Section 1) uses your browser's session storage rather than a cookie, purely to tell whether page views within one visit belong together — it is cleared automatically when you close the tab and never persists across visits.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email. Continued use of the Service after changes are posted constitutes acceptance.

8. Contact

For privacy-related questions: privacy@cripta.to.