Privacy Policy

Last updated July 24, 2026

The short version: we don't want your personal information, so we don't ask for it. No phone number, no name, no backup email, no tracking, no ads, and we never scan or sell your mail.

Who we are

NeonMail (“we”, “us”) operates the email service at neonmail.io and the NeonMail Android app. You can reach us at support@neonmail.io.

What we collect

To give you a working mailbox, we store only:

  • Your username — the local part of your @neonmail.io address.
  • A password hash — your password is salted and hashed (scrypt); we never store the password itself.
  • A recovery-phrase hash — only a one-way hash of your 12-word phrase, so we can verify recovery but can never reproduce the phrase.
  • Your mail — the messages you send and receive, so we can show them to you.
  • Basic security metadata — the IP address and browser user-agent of sign-ins and account actions, kept to detect abuse.

We do not ask for your phone number, real name, physical address, date of birth, or a backup email, and we do not require email verification.

What we don't do

  • No advertising, and no sharing or selling of your data to anyone.
  • No third-party trackers, analytics beacons, or advertising SDKs.
  • No scanning of your mail to build a profile of you.
  • No cross-site tracking or data brokering.

How your mail is sent and received

Mail between @neonmail.io users is delivered internally. Mail to and from the wider internet passes through our email infrastructure and a third-party sending relay (SMTP2GO) purely to hand messages to other providers such as Gmail or Outlook. Those providers, and your recipients, receive the mail you choose to send them. Mail travels over encrypted connections (TLS) wherever the other side supports it.

Cookies

We use a single, strictly-necessary cookie to keep you signed in (an encrypted session token). We do not use advertising or analytics cookies.

Data retention & deletion

We keep your account and mail until you ask us to delete them. To delete your account and all associated mail, email support@neonmail.io from your NeonMail address, or use the in-app account controls where available. Deletion is permanent and removes your messages, your account record, and your security metadata.

Your responsibility for the recovery phrase

Your 12-word recovery phrase is the only way to restore access if you forget your password. Because we store only a hash of it, we cannot recover your account for you if you lose it. Keep it offline and private — anyone who has it can reset your password.

Children

NeonMail is not directed to children under 13 (or the minimum age of digital consent in your country), and we do not knowingly create accounts for them.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.

Contact

Questions about privacy? Email support@neonmail.io.