Last updated: September 30, 2026
What changed: We added Cloudflare as a subprocessor (the app reaches the internet through its network), filled in the company and provider details, and explained how we ask you to accept changes.
Privacy Policy
This is an English translation for convenience. If it differs from the Spanish version, the Spanish version prevails.
This policy explains how 3-101-084807 Sociedad Anónima ("we", "us") handles personal data when you use Strix Mail, the web and mobile email client. It is designed to comply with Costa Rica's Law 8968 on the Protection of Individuals with regard to the Processing of their Personal Data and its regulations, and also with the EU General Data Protection Regulation (GDPR) and the California privacy law (CCPA/CPRA) where they apply.
The details marked as pending are completed before Strix Mail goes live.
In short
- Strix Mail is a client: your email lives on your provider's server. We keep a working copy to display it quickly and to search it.
- We use your data only to provide the service to you and keep it secure.
- No human reads your email, except for the exceptions explained below (you ask us to, security, or a legal order).
- No advertising, no selling of data, and no training of artificial intelligence models on your email.
- Your mailbox passwords are stored encrypted with AES-256-GCM, and full messages and attachments are encrypted by the app itself before they reach storage.
- Remote images are blocked by default and, if you show them, they go through a proxy that hides your IP address.
- You can request access to, correction of, or deletion of your data by writing to [email protected].
Who is responsible
The data controller (the party responsible for the database and the processing) is 3-101-084807 Sociedad Anónima, corporate ID (cédula jurídica) 3-101-084807, located at San Josecito de San Isidro, Heredia, 50 metros al norte de la Iglesia Católica, mano derecha (código postal 40602), Costa Rica. Privacy contact: [email protected].
If you use Strix Mail through an organization (for example, your employer invited you), that organization decides who joins and with which role. Even so, neither the organization nor its admins can see your mailboxes or your email inside Strix Mail.
What data we handle
Your Strix Mail account
- Identity: name, email address and sign-up date.
- Password: we never store it. We store an Argon2id hash with a salt and an additional server-side secret (pepper).
- Two-step verification: the TOTP secret is stored encrypted with AES-256-GCM; recovery codes are stored as hashes.
- Organizations: the organizations you belong to, your role and invitations (including the invitee's email address and the name of the person who invites).
- Preferences: theme, reading options, senders you allowed to show images, and the undo-send delay.
The mailboxes you connect
- Settings: IMAP and SMTP servers, ports, username, display name, color, signature and sending identities.
- Credentials: the mailbox password (or app password), encrypted with AES-256-GCM. The API never returns it and it never appears in logs. When you connect a Google or Microsoft account with their sign-in (OAuth), the tokens are stored with the same encryption.
- Email: to display and search it, we keep a working copy (cache):
- in the database: folders, headers (sender, recipients, subject, dates, identifiers), flags (read, flagged), size, a snippet and the plain text of the body for search;
- in file storage: the full message (
.eml) with its attachments, encrypted by the app with a different key per file. It is downloaded when you open a message and, so that it opens quickly, also ahead of time for recent messages in Inbox and Sent. - The first sync fetches headers from the last 90 days (up to 2,000 messages per folder); older mail is fetched when you search for it or open it.
- What you write: drafts (also saved to your server's Drafts folder), attachments and images you upload, and the send queue.
- Addresses for autocomplete: the addresses that appear in your messages and those you write to, to suggest them while composing.
Your email content may include data about other people (those who write to you or whom you write to) and, depending on what you receive, sensitive data. We treat it like the rest of your email: only to show it to you and operate the mailbox on your behalf.
Technical and security data
- Sessions: a random identifier (we store only its hash), the IP address and browser you signed in from, and the sign-in and last-use dates. You can see and end them in Settings → Security.
- Sign-in attempts: to stop brute-force attacks we record attempts for a few minutes (including the address typed) and count failures per account.
- Audit log: security events for the account and the organization (sign-up, verification, successful and failed sign-ins, password and two-step verification changes, invitations, role changes). It records what happened, when, and the user's internal identifier; it does not store your IP address, your email address or message content. It is hash-chained to detect tampering.
- Server logs: technical operation and error messages with internal identifiers. They may include the error text returned by your mail server (which sometimes mentions an address). They do not include the content of your messages.
Emails the system sends you
We only write to you when necessary: to verify your address, to reset your password, to let you know someone tried to sign up with your address if you already had an account, and for organization invitations. We do not send advertising.
What we do not collect
We do not use analytics or advertising tools, we do not use third-party cookies, we do not load fonts or scripts from other sites, and we do not ask for your location, your phone contacts or your photos.
Where the data comes from
- From you, when you sign up, set up mailboxes and use the app.
- From your email providers, when we sync the mailboxes you connected.
- From other people: those who invite you to an organization and those who send you email.
What we use it for, and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service: syncing, displaying, searching, organizing, composing and sending email | account, mailboxes, email, preferences | your consent when you sign up and performance of the contract (Terms) |
| Creating and managing your account and organizations | account, organizations, invitations | performance of the contract |
| Security: protecting accounts, detecting abuse, investigating incidents | sessions, sign-in attempts, audit log, logs | legitimate interest in protecting the service and its users; legal security obligations |
| Sending you system emails | email address, name | performance of the contract |
| Complying with legal obligations and responding to authorities | what the order requires | legal obligation |
We do not make automated decisions that have legal effects on you and we do not profile you.
Data from Google and Microsoft
When you connect a Gmail or Google Workspace account, or an Outlook.com or Microsoft 365 account, with the provider's sign-in (OAuth), Strix Mail receives access to your mailbox with the permissions you accept on that screen. We use them only for the email client features you see in the app: reading, organizing, searching and sending your email.
Google Limited Use disclosure:
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Strix Mail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, with the data we receive from Google (and we apply the same to data from Microsoft):
- We use it only to provide and improve the email client features you see in Strix Mail.
- We do not transfer it to third parties, except as necessary to provide those features (to the subprocessors below, under contract), to comply with the law, for security, or as part of a merger or sale of the business with your prior consent.
- We do not use it for any kind of advertising (personalized, retargeting or interest-based).
- We do not sell it, or give it to data brokers or information resellers.
- We do not use it to determine creditworthiness or for lending purposes.
- We do not use it to develop, improve or train generalized (non-personalized) artificial intelligence or machine learning models.
- No human reads it, except for the exceptions in the next section.
No one reads your email
Your email is processed by software, only to provide the service to you. No one on our team reads the content of your messages, unless:
- you ask us to explicitly for specific messages (for example, when you report a problem with a message that does not display correctly);
- it is necessary for security: to investigate abuse or a security incident;
- the law or an order from a competent authority requires it; or
- it is used in aggregated, anonymized form for internal operations (for example, counting how many messages fail to sync), without seeing anyone's content.
Access to the infrastructure is restricted to the staff who operate it, with personal credentials and two-step verification.
Remote images and the proxy
Many emails contain images hosted on other servers that are used to find out whether and where you opened the message. That is why:
- remote images are blocked by default; you show them, per message or always for a given sender;
- when you show them, our server downloads them and passes them to you: the sender sees our server's IP address, not yours, and does not receive your cookies or your browser's details;
- even so, when an image loads the sender can tell that it was loaded: that is why the decision to show images is yours.
International transfers
Data is hosted in Costa Rica, on our own servers. Some of the subprocessors listed above process it outside the country: file storage (encrypted by the app), delivery of system emails, and the Cloudflare network that traffic passes through. We make those transfers outside Costa Rica (or, for users in the European Union, outside the European Economic Area) with your consent, which you give by accepting this policy, and with appropriate safeguards: contracts with data protection clauses (such as the European Commission's standard contractual clauses, where applicable) and the security measures in this policy. You can ask us for more information at [email protected].
Security
- In transit: HTTPS with HSTS between your browser and Strix Mail (the connection arrives through the Cloudflare network, which forwards it encrypted through the tunnel to our servers); with your mail servers, mandatory TLS and no invalid certificates accepted.
- At rest: your mailbox credentials and two-step verification secrets are encrypted with AES-256-GCM; full messages and attachments are encrypted by the app with a key per file (AES-256-GCM) before they reach storage, which is never public.
- Passwords: Argon2id with salt and pepper, and breached passwords are rejected.
- Accounts: optional two-step verification, sign-in attempt limits, sessions that expire and that you can end remotely.
- Isolation: each person's and organization's email data is also separated in the database (row-level security), through a connection that cannot bypass it.
- Incoming email: HTML is sanitized on the server and displayed in isolation, without scripts; remote images go through the proxy.
- Network protection: we do not connect to internal addresses when you type a mailbox server or when downloading images.
- Auditing: a hash-chained log of security events.
No system is infallible. If an incident affects your data, we will notify you and the competent authority (in Costa Rica, the Agency for the Protection of Inhabitants' Data, PRODHAB) within the time limits set by law, explaining what happened, what data was affected and what we did.
How long we keep data
| Data | How long |
|---|---|
| Your account and profile | as long as the account exists. If you delete it from the app, it is deleted immediately; if you ask for deletion by email, within 30 days. |
| Registered accounts that were never verified | 30 days from sign-up. |
| Connected mailboxes and their cache | until you disconnect the mailbox, leave the organization, the organization is deleted, or you delete your account. What you delete on your server leaves the cache on the next sync. |
| Drafts | until you send or discard them. |
| Uploaded attachments that were never sent | 24 hours. |
| Encrypted copy of a sent message (send queue) | 7 days after sending. The copy that remains is the one in your Sent folder, on your server. |
| Addresses for autocomplete, senders allowed to show images, and preferences | until the organization or your account is deleted. |
| Sessions | they expire after 7 days without use and, at most, after 30 days. |
| Verification links, reset links and invitations | 48 hours, 15 minutes and 7 days; deleted when they expire or are used. |
| Sign-in attempts | 10 minutes; the failure counter, 24 hours. |
| Audit log | 24 months. |
| Server logs | 30 days. |
| Backups | renewed every [[COMPLETAR: DIAS_RESPALDOS]] days; deleted data disappears from them within that time. |
When a mailbox, an organization or your account is deleted, the encrypted files become unreadable immediately (their keys are deleted) and are removed from storage within 30 days. We never delete email from your server except by an action of yours (for example, deleting a message or emptying the Trash) or the draft copies the app itself replaces.
Your rights
Under Law 8968 you have the right to:
- Access: know what data about you we process and get a copy.
- Rectification: correct inaccurate or incomplete data (you can change your name yourself in the app).
- Cancellation or erasure: ask us to delete your data. See Delete your data.
- Objection: object to processing on legitimate grounds.
- Withdraw your consent at any time, without retroactive effect. Since the service depends on processing your email, withdrawing it means you stop using it.
If you are in the European Union, you also have the right to data portability, to restriction of processing, and to lodge a complaint with your data protection authority. If you live in California, you have the right to know what data we process, to request its deletion or correction, and not to be discriminated against for exercising your rights; we do not sell or share personal information as defined by the CCPA/CPRA.
How to exercise them: write to [email protected] from your account's address. To protect your data we may ask you to confirm your identity. We respond within the time limits set by applicable law. It is free.
If you are not satisfied with our answer, you can file a complaint with Costa Rica's Agency for the Protection of Inhabitants' Data (PRODHAB) or with the authority in your country.
Minors
Strix Mail is not directed at people under 18 and we do not allow them to create accounts. If you believe a minor gave us their data, write to us and we will delete it.
Changes to this policy
If we change this policy significantly, we will notify you by email or in the app before it takes effect. Once the new version is in effect, the app shows it to you when you sign in and asks you to accept it to keep using Strix Mail; if you do not accept it, you can sign out and delete your account. The date of the last update is shown at the top.
Contact
- 3-101-084807 Sociedad Anónima, corporate ID 3-101-084807, San Josecito de San Isidro, Heredia, 50 metros al norte de la Iglesia Católica, mano derecha (código postal 40602), Costa Rica.
- Privacy and personal data: [email protected]
- Support: [email protected]