TrekMail Privacy and Data Retention
How TrekMail handles data privacy, storage duration, and deletion for accounts, mailboxes, Drive files, audit logs, and public links.
Article details
Type, difficulty, plans, and last updated info.
▼
Article details
Type, difficulty, plans, and last updated info.
- Type
- Policy
- Difficulty
- Beginner
- Plans
- Nano · Starter · Pro · Agency
- Last updated
- Sep 9, 2026
TrekMail stores data to provide the email, file storage, billing, security, and support features of the Service. We do not sell Customer Content or use email or Drive content for advertising. Limited account, transaction, device, and campaign data may be processed by service providers for platform operations and advertising measurement as described in the Privacy Policy.
What We Store
- Account Info: Email, name, billing details.
- Mailbox Data: Email messages, folders, read/unread status.
- Drive Data: Files, folders, file metadata, storage usage, public link settings, and Drive activity needed to provide and secure the feature.
- Usage Logs: SMTP delivery events, bounce logs (for debugging).
- API Tokens: Token name, hashed secret, scopes, domain constraints, expiration, and usage metadata (last used timestamp, IP).
- API Audit Events: Security-relevant API activity may be logged with details such as the token used, resource affected, IP address, request ID, and timestamp. Sampling, retention, and displayed fields may vary by event type and plan.
How Long We Keep It
- Active Accounts: Data is retained while your account is active and as otherwise described below.
- Deleted Accounts: A verified account scheduled for deletion generally has a 7-day grace period before permanent deletion begins. An unverified or otherwise ineligible account may be deleted without that grace period where permitted by the applicable product flow and law.
- Drive Trash: Deleted Drive files may remain in Trash for a limited recovery period and continue to count against storage until permanently removed.
- Public Links: Active public links remain until they expire, reach their download limit, are revoked, the underlying file is deleted, or access is disabled. Revoked link records may be retained for a limited period for audit and abuse prevention.
- Drive Storage Add-on Non-Payment or Cancellation: If payment retries are exhausted or the Add-on ends, the account enters a 7-day read-only grace period. If the account remains over its remaining storage cap after those 7 days, Drive files may be permanently and irreversibly deleted to bring usage within the available cap. There is no additional 30-day grace period for ended or unpaid Add-on capacity.
- Billing Records: Generally retained for the period reasonably required for tax, accounting, fraud-prevention, dispute, and legal obligations; some records may be retained for approximately 7 years or longer where required.
- API Tokens: Revoked and expired tokens are retained for reference while your account is active. Deleted with the account.
- API Audit Logs: Generally retained for a limited operational period; a 90-day window may apply to dashboard-visible events, while security, dispute, or legal records may follow a different schedule.
- Idempotency Keys: Usually retained for a short operational period to help prevent duplicate API operations.
- Support Ticket Attachments: Generally removed after the applicable support and security retention period; certain records may be retained longer for disputes, abuse prevention, or legal obligations.
Your Rights
- Access: Request a copy of your data via Support.
- Deletion: Delete your account or submit an applicable request to remove covered personal data, subject to operational backups and records TrekMail or its providers may retain for security, tax, accounting, dispute, legal, or other permitted purposes.
- Portability: Export your emails via IMAP and download Drive files through available product interfaces while the account remains active and accessible.
White Label Lite and data-processor relationships
If you serve mailboxes to your own customers via White Label Lite, the relationship looks like this for data-protection purposes:
- Your end customer or user may be a data subject.
- You (the TrekMail account holder running the branded service) generally determine the purposes and means of processing your customers' mailbox content and may act as a controller under applicable data-protection law.
- TrekMail generally acts as your processor or sub-processor for that Customer Content, while acting as an independent controller for account administration, billing, security, legal compliance, and similar purposes described in the Privacy Policy.
You remain responsible for the notices, instructions, permissions, contracts, and responses required for your relationship with end users. TrekMail's contractual data-processing terms are included in the Privacy Policy; TrekMail does not promise a separate signed DPA through this article.
Related articles
Jump to nearby guides that continue the workflow.