Legal
Privacy Policy
You are trusting us with your company's mail. This page says exactly what we hold, what we never look at, where it physically sits, and how you get it all back. No clause here is written to be skipped.
01 Who we are
Mailora is the email service. HostGet is the company behind it. If you have a privacy question, one address reaches a human.
Mailora is a business email service operated by HostGet, of Tower of Aakash, Level 18, 54 Gulshan Avenue, Dhaka 1212, Bangladesh ("Mailora", "we", "us").
This policy covers mailora.io, the Mailora webmail application,
the administrator portals, and mail delivered through our servers. It applies
to two different kinds of people, and the difference matters:
- Our customers — the organisation that buys mailboxes. They decide who gets an account and what the settings are.
- Mailbox users — the people inside that organisation who send and receive mail.
For mail content, the customer organisation is the data controller and we are the processor: we act on their instructions. For billing and account records, we are the controller.
If you use a Mailora mailbox at work
Your employer controls the account. They can reset your password, suspend the mailbox, and — depending on their own policy — access its contents. Requests to delete or export your mailbox should go to your administrator first, not to us.
02 What we collect
Account details, billing records, a log of admin actions, and counts of AI usage. Not the text of your messages.
| What | Examples | Why |
|---|---|---|
| Account | Mailbox address, display name, domain, role, password hash | To run the mailbox and sign you in |
| Billing | Organisation, plan, mailbox count, invoices, payment status | To charge the correct amount and meet tax obligations |
| Administrator log | Who did what and when — actor, action, target, timestamp |
So an organisation can see who created, suspended or deleted an account |
| AI usage counters | Mailbox address, which feature, timestamp | To enforce plan quotas and bill accurately |
| Mail delivery logs | Sender, recipient, size, time, delivery result | Required to deliver mail, fight spam and diagnose failures |
| Mail content | Messages, attachments, drafts, contacts, folders | Stored so you can read it — see section 3 |
What the AI counter actually stores
One row per AI action, holding the mailbox address, the feature name, and the time. There is no column for message text, subject lines, or recipients — so message content cannot appear in it, by construction rather than by promise.
03 Your mail content
We store your mail because that is the product. We do not read it, scan it for advertising, or sell it. Nobody sells ads on Mailora — there are no ads.
We commit to the following, and each is a limit on us, not an aspiration:
- No advertising. Mailora has no advertising business. Your mail is not profiled, segmented, or used to target anything.
- No sale. We do not sell, rent or trade mail content or personal data. There is no exception for "partners".
- No routine human access. Our staff do not read customer mail as part of normal operations.
Our staff may access a mailbox in only three situations:
- You or your administrator explicitly ask us to, in order to fix a problem;
- It is strictly necessary to restore a failing service — for example recovering a corrupted mailbox from backup;
- We are legally compelled (see section 7).
Automated systems do process mail in transit — spam and malware filtering cannot work otherwise. That processing is automatic, is not retained beyond what the filter needs, and produces no profile of you.
04 AI features
AI only runs when someone presses the button. The text of that one message goes to a specialist AI provider, gets used to answer, and is not used to train anything. Your admin can switch AI off for the whole organisation.
Mailora's AI features — compose, reply, summarise, triage and the assistant — are invoked, not ambient. Nothing is analysed in the background; nothing runs across your mailbox on a schedule.
When a user triggers an AI action:
- The relevant text — usually the message being worked on, plus any instruction typed — is sent over an encrypted connection to a specialist third-party AI provider.
- The provider returns a result, which is shown to the user.
- We record that an AI action happened, for quota and billing. We do not store the text sent or the text returned.
Our agreements with AI providers require that content sent through the API is not used to train their models and is retained only briefly, for abuse monitoring, before deletion.
Turning AI off
An administrator can disable AI for an entire organisation from the admin portal. With AI disabled, no message content leaves our servers for AI processing at all. Organisations under confidentiality or regulatory constraints should use this switch.
We will name our current AI sub-processor, and any change to it, on request to support@mailora.io. Where a customer requires advance notice of sub-processor changes in writing, we will agree that in the contract.
05 Where your data lives
Your mail sits on our own servers in Bangladesh — not on Google's or Microsoft's. Only AI requests leave the country, and only when triggered.
Mail, mailboxes, backups and account records are stored on servers we operate in a data centre in Gazipur, Dhaka Division, Bangladesh. This is deliberate: it is the difference between renting space in someone else's platform and running the mail ourselves.
Data leaves that infrastructure in only two circumstances:
- Mail delivery. Sending mail necessarily transmits it to the recipient's provider, wherever they are. That is how email works, and it is outside our control once handed over.
- AI requests. Content sent for an AI action is processed by a provider that may operate outside Bangladesh, typically in the United States. See section 4, including how to disable this entirely.
Encrypted offsite backup copies may be stored with a cloud storage provider outside Bangladesh. Those copies are encrypted before they leave our servers with a key that the storage provider does not hold, so the provider cannot read them.
06 Cookies & local storage
This website sets no cookies at all and calls no third party. The apps store one sign-in token in your browser, which expires after 12 hours.
The mailora.io website
Sets no cookies, runs no analytics, and loads no fonts, scripts, or images from any third party. There is no consent banner on this site because there is nothing to consent to. Our web server does keep standard access logs (IP address, page, time, user agent) for security and troubleshooting.
The webmail and admin applications
After you sign in, the application stores a single session token in your
browser's local storage under the key hostget_token. It exists so
you are not asked for your password on every action, and it
expires 12 hours after sign-in. Signing out removes it
immediately. It is not a tracking identifier and is never shared.
07 Who else touches it
A short list: an AI provider when AI is used, a payment processor when you pay, an encrypted backup store, and the data centre. Plus the law, if it compels us — and we will tell you unless we are forbidden to.
| Category | What they receive | When |
|---|---|---|
| AI provider | The text of the message being acted on | Only when a user triggers an AI feature |
| Payment processor | Billing contact and amount | When you pay. We do not store full card numbers. |
| Offsite backup storage | Encrypted archives only, unreadable to them | Nightly |
| Data centre operator | Physical custody of the servers | Continuously. No access to accounts. |
Legal requests
We disclose data to authorities only where we are legally required to. Where we are permitted to tell you, we will, so that you have the opportunity to challenge it. We do not give any government direct or unsupervised access to our systems, and there is no mechanism in our infrastructure that would allow it.
If the business changes hands
If Mailora is acquired or merged, data may transfer to the acquirer, who would be bound by this policy until you are given notice of any change. You would be told before any such transfer takes effect.
08 How long we keep it
Mail stays until you delete it. Delete it and it is gone within 30 days, backups included. Invoices we must keep for tax law.
| Data | Kept for |
|---|---|
| Mail in an active mailbox | Until you or your administrator delete it |
| Deleted mail | Removed from live systems on deletion; purged from backups within 30 days |
| Mailbox after the account is closed | 30 days, then permanently deleted — this is your window to export |
| Mail delivery logs | 90 days |
| Administrator action log | 2,000 most recent entries per system |
| AI usage counters | Current and previous billing period |
| Invoices and payment records | As required by tax law, typically 6 years |
The 30-day window is real
After an account closes, we hold the mailbox for 30 days so you can still get your mail out. After that it is deleted from live systems and from backups, and we cannot recover it — not for a fee, not on appeal. Export before you close.
09 Security
Encrypted in transit, isolated between organisations, backed up nightly to a second location, and monitored around the clock. If a breach affects you, we tell you.
- In transit. All web and mail connections use TLS. Mail to other providers is delivered over TLS wherever the receiving server supports it.
- Authentication. Passwords are stored hashed, never in plain text. Sessions are signed and time-limited.
- Isolation. Each organisation's data is scoped to its own domain; administrators can reach their own organisation and no other. This is enforced on the server, not in the interface.
- Sender authentication. We publish SPF, DKIM and DMARC records so recipients can verify that mail claiming to be from your domain really is.
- Backups. Nightly, replicated to a second machine, and copied offsite in encrypted form.
- Monitoring. Automated checks run every five minutes across services, ports, certificates, disk and backup freshness, and alert a human on failure.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will notify affected customers without undue delay, telling you what happened, what data was involved and what we did about it.
10 Your rights
Get a copy, fix mistakes, delete it, or take it elsewhere. Mail is portable by design — standard protocols, no lock-in.
You can ask us to:
- Access — give you a copy of the personal data we hold about you.
- Correct — fix anything inaccurate.
- Delete — erase your data, subject to records we must keep by law.
- Export — supply your data in a portable format.
- Restrict or object — limit how we process it.
If you use a mailbox provided by your employer, send these requests to your administrator, who controls the account. We will help them fulfil it. Where we are the controller — billing and account records — write to support@mailora.io. We respond within 30 days and do not charge for reasonable requests.
Portability is built in, not a favour
Mailora speaks standard IMAP, so any mail client can download a complete copy of a mailbox at any time, without asking us. Leaving is a technical operation you can perform yourself.
Customers in the EEA or UK may have additional rights under the GDPR, including the right to complain to a supervisory authority. We will enter into a data processing agreement with any customer who needs one — ask us.
11 Children
Mailora is a business service and is not directed at children. We do not knowingly create accounts for anyone under 16. If we learn that we hold a child's personal data without a proper basis, we will delete it.
12 Changes to this policy
If we change this policy we will update the date at the top. For changes that materially reduce your privacy — a new category of data, a new sub-processor handling mail content, a longer retention period — we will notify account administrators by email at least 30 days before the change takes effect, so you have time to object or leave.
13 Contact
Privacy questions, data requests and complaints:
- Email — support@mailora.io
- Post — Tower of Aakash, Level 18, 54 Gulshan Avenue, Dhaka 1212, Bangladesh
If you are not satisfied with our response, you may escalate to the relevant data protection authority in your country.