Skip to content

Legal

Privacy Policy

Last updated: 1 January 2026 · Airfree Mail Pty Ltd

1. Who we are

Airfree Mail Pty Ltd (ACN 000 000 001) is an Australian proprietary company incorporated in New South Wales, Australia. We operate Airfree Mail — a privacy-first professional email, calendar, drive, and video communications platform — under licence from Airfree Services Pty Ltd.

Our registered address is: Level 7, 1 Bligh Street, Sydney NSW 2000, Australia.

For all privacy matters, contact us at: privacy@airfreemail.com

2. Our privacy commitment

Airfree Mail was built on a simple principle: your email is private. We do not read your emails. We do not build advertising profiles from your inbox. We do not sell your data to third parties. Our business model is selling subscriptions — not your attention or your data.

We collect only what we need to provide the service, protect it with strong encryption, and give you complete control over it at all times.

3. What data we collect

Account data: When you create an account, we collect your name, email address, and password (stored as a one-way bcrypt hash). For paid accounts, we collect billing information processed by our payment provider — we do not store card numbers.

Email data: We store the emails, contacts, calendar events, and files you create or import. This data is stored encrypted at rest. On paid plans, Drive files are end-to-end encrypted and cannot be read by Airfree Mail staff.

Technical data: We collect IP addresses, browser/client type, and access timestamps for security and authentication purposes. We retain this data for 90 days.

Payment data: Billing is handled by our PCI DSS-certified payment processor. We receive a payment token and last-four digits — we never see or store full card numbers.

4. What we do not do

  • We do not read, scan, or analyse the content of your emails for advertising purposes.
  • We do not sell your personal data to third parties.
  • We do not use tracking pixels or link rewriting in emails.
  • We do not build behavioural profiles from your inbox activity.
  • We do not use third-party advertising networks.
  • We do not transfer your data to countries without adequate data protection laws without appropriate safeguards.

5. Data residency

You choose where your data is stored. Available regions are: Australia (Sydney), European Union (Frankfurt), United States East (Virginia), and APAC (Singapore). Your data is stored exclusively in your chosen region unless you configure additional regions.

We do not transfer data between regions without your explicit consent.

6. Security

All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. End-to-end encrypted Drive files are encrypted on your device before upload — only you hold the decryption keys. We are working toward ISO 27001 certification and conduct independent penetration tests.

7. Your rights under GDPR and Australian Privacy Act

Depending on your jurisdiction, you have the following rights:

  • Access: Request a copy of all personal data we hold about you.
  • Rectification: Correct inaccurate personal data.
  • Erasure (GDPR Article 17): Request complete deletion of your account and all associated data within 30 days.
  • Portability: Export your email (MBOX), contacts (vCard), and calendar (ICS) at any time from your account settings.
  • Restriction: Request that we restrict processing of your personal data.
  • Objection: Object to processing based on legitimate interests.

To exercise any right, email privacy@airfreemail.com. We respond to all requests within 30 days.

8. Cookies

We use strictly necessary session cookies for authentication. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. See our Cookie Policy for full details.

9. Data retention

We retain your account data for as long as your account is active. If you delete your account, all personal data is permanently erased within 30 days, except where we are required to retain it by law (e.g., tax records retained for 7 years).

10. Third-party processors

We use a small number of sub-processors to deliver the service, including our payment processor and infrastructure providers. All sub-processors are bound by data processing agreements and may not use your data for any purpose other than providing services to us.

11. Law enforcement

We will only disclose data to law enforcement when legally required to do so by a valid court order or equivalent legal process in Australia. We will notify you of any such request to the extent permitted by law.

12. Governing law

This Privacy Policy is governed by the laws of New South Wales, Australia. EU residents may also lodge a complaint with their local Data Protection Authority.

13. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email at least 30 days before they take effect. The date at the top of this page indicates when the policy was last revised.