Privacy Policy
This policy explains what data WeMails ("we", "us") collects, why, how we protect it, and the rights you have. We built the product so that your mailbox credentials and message content are encrypted and never used for anything other than performing the migration or backup you requested.
1. Who is the controller
DestinoLivre Tecnologia Ltda · São Paulo, Brazil is the data controller. For any privacy request, contact privacy@wemails.com.
2. Data we collect
2.1 Account data
- Your name and email, and a password that is stored only as a one-way hash (bcrypt/Argon2) — we can never read it.
- Optional two-factor (TOTP) secret, stored encrypted.
- Plan, subscription status and usage counters (bytes/emails migrated).
2.2 Mailbox credentials (source/destination)
- To connect to your mailboxes we need the server, port, username and password you provide. The password is encrypted with AES-256-GCM before being written, kept only in the isolated database of that job, and wiped as soon as the job completes.
- We use these credentials solely to log in via IMAP/POP3 and move or read your messages for the job you started.
2.3 Message content
- During a migration, messages pass through our server in transit and are written to your destination account. We do not keep copies afterwards.
- The only place message content is retained is inside the backups you create — and there each message is encrypted individually with a key derived (PBKDF2) from your backup passphrase. Without that passphrase the archive cannot be read.
- We never index, read, profile or use your message content for advertising or model training.
2.4 Migration/backup metadata
Job settings (hosts, usernames, folder names, message counts, sizes, status, timestamps) so we can show progress and let you manage jobs.
2.5 Technical & security data
IP address, User-Agent, session identifiers and an audit log of security-relevant actions (logins, credential access, admin actions, denied access). This is used to keep your account safe and detect abuse.
2.6 Payment data
Payments are processed by Stripe. We never receive or store your full card details — only a customer/subscription reference.
2.7 Cookies
We use strictly-necessary cookies for your session (HttpOnly, Secure, SameSite) and a cookie to remember your language. No third-party advertising or tracking cookies.
3. How we use data
- To provide the service you asked for (migrate, back up, restore).
- To authenticate you, secure your account and prevent abuse.
- To process payments and manage your subscription.
- To send transactional email (e.g., account and support messages) via Brevo.
- To comply with legal obligations.
We do not sell your personal data, and we do not use it for advertising.
4. How we protect data (encryption & storage)
- In transit: TLS for the web app and for every IMAP/POP3 connection.
- Login passwords: irreversibly hashed — never stored in clear text.
- Mailbox passwords: AES-256-GCM at rest, key held outside the web root, and discarded when the job ends.
- Backups: each message encrypted with a key derived from your passphrase (PBKDF2-SHA256). We cannot decrypt a backup without it.
- Isolation & scoping: every database query is scoped to your account — one user can never access another user's data. Each migration/backup lives in its own isolated store.
- Additional controls: anti-SSRF validation on the hosts you enter, session binding to IP/User-Agent, CSRF protection, login lockout, optional 2FA and comprehensive audit logging.
5. Data retention
- Mailbox passwords: deleted immediately after the job completes.
- Backup archives: kept according to the retention you set (we auto-delete the oldest); deleted when you delete the backup or your account.
- Account & billing records: kept while your account is active and as required by law, then deleted.
- Audit logs: retained for a limited period for security, then purged.
6. Sharing & sub-processors
We share the minimum necessary with:
- Stripe — payment processing.
- Brevo — transactional email delivery.
- Our own infrastructure providers hosting the service.
We do not share your data with anyone else except when required by law.
7. Your rights
Under the LGPD (Brazil), the GDPR (EU) and similar laws you can request to access, correct, export or delete your data, and withdraw consent. Deleting your account removes your data (including backups) from our systems. Contact privacy@wemails.com.
8. International
WeMails is a global service; your data may be processed on servers in different regions, always under the protections described here.
9. Changes
We may update this policy; we'll change the "last updated" date and, for material changes, notify you.
10. Contact
Privacy: privacy@wemails.com · Support: support@wemails.com · DestinoLivre Tecnologia Ltda · São Paulo, Brazil.