MAILDIAL

Privacy / review draft · 27 September 2026

Your address.
Your boundaries.

Not a final policy or verification-ready document. Operator legal identity, address, jurisdiction, legal bases, processor/transfer details, and retention schedules still need confirmation and legal review. Contact: support@maildial.contact.

Operator

MailDial Oy, Pentagonveien 1, 1430 Ås, Norway. Contact: support@maildial.contact. Company registration details and data-controller arrangements remain to be confirmed before final publication.

Account and Google sign-in

MailDial uses Supabase for authentication and account storage. Email sign-in associates a verified email with an account and public MailDial number. Google sign-in requests basic identity information: an account identifier, email address, and profile information such as name or avatar supplied by Google. These are used to authenticate and maintain the account. Google sign-in does not grant MailDial access to read your Gmail, Google Drive, or address book.

The browser keeps session credentials in local storage so you can stay signed in. Protect shared devices and sign out when finished. Google identity data is not published as a Pool profile, sold, used for targeted advertising, or used to train studio voices by the current app. Any new use requires updated disclosure and an appropriate permission process.

Private email and Box

Your destination email is not in the public directory. Cloudflare processes incoming email for forwarding to a verified destination; your sender and receiving provider handle their own email records. MailDial stores delivery metadata, not a private conversation inbox. It is not end-to-end encrypted email and does not promise anonymity. The app does not provide an attachment-upload feature; external email may nevertheless contain attachments. Do not treat this as an attachment-scanning promise.

Public Pool and lasting memories

Pool thoughts, reactions, and replies are public while available. Account identifiers link contributions internally for access control and limits. Human thoughts ordinarily expire after 72 hours, with dependent reactions and comments removed during cleanup. Studio editions may remain six months; the reusable editorial library is separate. Writer-opted-in, reviewed public thoughts can enter Memoric Corner beyond ordinary expiry. Private mail and other people's comment text are not archived there. Authors can remove their archived thought.

Circle and presence

Saved contacts and nicknames are private to the account owner. Contact requests reveal the requester's public number to the recipient and require acceptance. Presence is optional and based on recent check-ins, not precise activity or read receipts.

Location and device choices

Location sharing is optional at posting. With permission, the browser obtains a position and rounds coordinates to whole degrees before submission. The app does not continuously track you. Coarse location accompanies a live post and is not a street-level location. City placements of studio thoughts are editorial, not users' whereabouts.

Providers, safety, and legal requests

The current architecture uses Cloudflare for hosting/email routing and Turnstile, Supabase for authentication/database services, Google for optional sign-in, and Resend for configured sign-in email delivery. They process relevant authentication, delivery, infrastructure, and abuse-prevention data under their own applicable arrangements. Final processor regions, cross-border safeguards, and log/backup retention must be confirmed before launch.

We may disclose information actually held where legally required or otherwise lawfully necessary for a proportionate response to a specific safety emergency. This does not grant blanket access to authorities. We do not secretly publish private messages or train studio models on users' thoughts in the current app.

Retention, rights, and contact

Account records persist while needed to operate the account. Exact account-deletion, security-log, delivery-metadata, backup, and legal-hold schedules remain to be finalized. Public expiry does not guarantee immediate deletion from third-party caches or provider backups. Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and complain to a relevant data-protection authority. Contact support to discuss a request; verify ownership without sending passwords or sign-in codes.

The intended minimum age is 16, or any higher local requirement. Material changes will be dated and communicated. This draft must be finalized before public onboarding and OAuth branding submission.