Privacy Policy

Last Updated: April 17, 2026

At Haamly, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our encrypted email service. Please read this policy carefully.

IMPORTANT PRIVACY NOTICE

By using Haamly, you consent to the data practices described in this policy. If you do not agree with our policies, please do not use the Service.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when using our Service:

  • Account Information: Email address for OAuth authentication (Gmail, Outlook, etc.)
  • Encrypted Email Content: Encrypted messages you send and receive through Haamly (we cannot read these)
  • Encrypted Metadata: Encrypted subject lines, sender addresses, and recipient addresses (we cannot read these)
  • Contact Approvals: Your list of approved and pending contacts (stored encrypted)
  • Subscription Preferences: Your mailing list subscription choices
  • Cryptographic Keys: Public keys for end-to-end encryption (stored on our servers), private keys (stored only on your devices)
  • Support Communications: Information you provide when contacting customer support via bug reports

1.2 Automatically Collected Information

We automatically collect certain information when you use the Service:

  • Usage Data: Login timestamps, features used, and interaction patterns
  • Device Information: IP address, browser type, operating system, device identifiers
  • Log Data: Server logs, error reports, and performance data
  • Cookies: Session cookies for authentication and functionality

1.3 Third-Party Service Data

When you connect third-party email services (Gmail, Outlook), we collect OAuth tokens and access permissions necessary to provide the Service. We do not store your third-party service passwords.

2. How We Use Your Information

We use collected information for the following purposes:

  • Service Provision: To route and store encrypted emails, enforce consent-based inbox rules, and maintain the service
  • Communication Routing: To deliver encrypted emails between Haamly users (we cannot read the content)
  • Authentication: To verify your identity through OAuth providers (Gmail, Outlook, etc.)
  • Consent Enforcement: To enforce your sender approval preferences and prevent unapproved senders from reaching your inbox
  • Key Exchange: To facilitate X3DH key exchanges between users for end-to-end encryption
  • Support: To respond to bug reports and provide customer support
  • Security: To detect, prevent, and address fraud, abuse, and security issues (without accessing encrypted content)
  • Legal Compliance: To comply with legal obligations (note: we cannot access encrypted message content or metadata)

What We CANNOT Do

Due to our zero-knowledge encryption design, we cannot read your message content, subject lines, or see who you're communicating with (sender/recipient metadata). We also cannot scan your emails for marketing, advertising, or analytics purposes.

3. Data Storage and Security

3.1 Encryption

Haamly implements end-to-end encryption for messages between Haamly users:

  • AES-256-GCM Encryption: Each message encrypted with a unique random key
  • X3DH Key Exchange: Establishes secure channels with forward secrecy
  • RSA-OAEP Key Wrapping: Per-recipient key wrapping for multi-device support
  • Zero-Knowledge Metadata: Message content, subject lines, sender, and recipient information are encrypted on your device before reaching our servers
  • Blind Index Privacy: Server routes messages using HMAC tokens, never seeing actual addresses
  • Client-Side Keys: Private decryption keys never leave your device

Important: We encrypt metadata (who you're emailing and message subjects) in addition to message content. This means Haamly servers cannot read your message content, subject lines, or see who you're communicating with.

Messages are encrypted in transit using TLS/SSL. When you use OAuth to authenticate with external email services (Gmail, Outlook), your identity is verified through those providers, but they cannot access your encrypted Haamly messages.

3.2 Data Storage

Your encrypted data is stored on secure cloud servers (Railway platform). We implement a zero-knowledge architecture:

  • Encrypted at Rest: All message content and metadata is stored in encrypted form
  • Local Decryption: Messages are decrypted only on your devices using keys that never leave your devices
  • No Server Access: Haamly servers cannot decrypt your messages, even if compelled by legal orders
  • Device-Side Storage: Messages are also stored locally on your devices using IndexedDB (browser storage)

We implement reasonable physical, technical, and administrative safeguards to protect your information. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Our zero-knowledge design ensures that even in the event of a server compromise, your message content and metadata remain protected.

3.3 Data Retention

We retain your information for as long as your account is active or as needed to provide you services. You may request deletion of your account and data at any time. After deletion, we may retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution).

SECURITY DISCLAIMER

While we employ industry-standard security measures, you acknowledge that you use the Service at your own risk. We are not liable for unauthorized access, data breaches, or loss of data.

4. Information Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We may share data with third-party service providers who perform services on our behalf (e.g., hosting, analytics, payment processing). These providers are contractually obligated to protect your data.

4.2 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or government request, or if we believe disclosure is necessary to:

  • Comply with legal obligations
  • Protect our rights, property, or safety
  • Prevent fraud or abuse
  • Respond to emergency situations

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. You will be notified of any such change.

4.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5. Third-Party Services

Haamly integrates with third-party email services (Gmail, Outlook) via their APIs. When you connect these services, you are subject to their respective privacy policies:

We are not responsible for the privacy practices of third-party services. Please review their policies before connecting your accounts.

6. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access: Request access to the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Data Portability: Request a copy of your data in a structured format
  • Opt-Out: Opt out of certain data collection and marketing communications
  • Withdraw Consent: Withdraw consent for data processing where consent is the legal basis

To exercise these rights, please contact us at haamlyapp@gmail.com. We will respond to your request within 30 days.

California Residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete personal information, and the right to opt-out of the sale of personal information. We do not sell personal information.

European Residents (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including rights to access, rectification, erasure, restriction of processing, data portability, and the right to lodge a complaint with a supervisory authority.

7. Cookies and Tracking

We use cookies and similar tracking technologies to maintain your session and improve your experience. You can control cookies through your browser settings, but disabling cookies may affect your ability to use the Service.

Types of Cookies We Use:

  • Essential Cookies: Required for authentication and basic functionality
  • Analytics Cookies: Help us understand how users interact with the Service
  • Preference Cookies: Remember your settings and preferences

8. Children's Privacy

Haamly is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected information from a child under 13, we will delete it immediately. If you believe a child has provided us with personal information, please contact us at haamlyapp@gmail.com.

9. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your country. Data protection laws may differ between jurisdictions. By using the Service, you consent to the transfer of your information to the United States and other countries where we operate.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the Service. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy. We encourage you to review this policy periodically.

11. Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law. Notification will be provided without undue delay and will include information about the breach and steps you can take to protect yourself.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Privacy & Legal

Email: haamlyapp@gmail.com

Website: www.haamly.com

By using Haamly, you acknowledge that you have read, understood, and agree to this Privacy Policy.