Legal
Privacy Policy
Last updated 24 August 2026.
We sell email hosting. We do not read your mail, scan it for advertising, build a profile of you, sell anything about you, or train anything on any of it. The site pages you are reading now use Google Analytics so we can tell whether anyone is finding us. The product itself does not. Once you sign in there is no analytics, no tracking and exactly one cookie: the one that keeps you signed in.
Who we are
FranklyMail is a product of Naylalabs, based in Türkiye. There is no separate FranklyMail company — the contract is with Naylalabs.
Registered address: Harran Üniversitesi Şanlıurfa Teknokent, Ulubağ Mahallesi, Recep Tayyip Erdoğan Bulvarı No 287A, İç Kapı No: 315, Haliliye, Şanlıurfa, Türkiye.
For anything on this page, including a request to see or delete your data, write to hello@franklymail.com. A person reads it.
We are the data controller for your account, and we are the host of the mail in your mailboxes. Mail you receive is written by other people and we do not control what they put in it; we store and deliver it for you.
What we store
Your account, so the service can exist:
- Your email address, and a hash of your password — never the password itself.
- Account status and plan.
- One row per sign-in session, each with the IP address and browser user-agent it was created from, so the session list in your settings can show you what is signed in and let you revoke it.
- If you turn on two-factor authentication: an encrypted TOTP secret and hashed backup codes. App passwords are stored as hashes only.
Your mail setup, because that is the product:
- The domains you add, and the result of each DNS check we run against them — the MX, SPF, DKIM and DMARC values we expect, what we observed, and when.
- Your mailboxes and aliases: addresses, display names, quotas, forwarding targets.
- The mail itself — messages, attachments, folders — stored on our mail servers for as long as you keep it there.
- Mail server logs: connections, deliveries and rejections. These contain IP addresses and envelope addresses, and they are what makes it possible to answer "why did that message not arrive" and to stop abuse.
- Storage and message counters, so your usage meter and your bill are real numbers.
Counters are all the panel normally sees of a mailbox — how much and how many, never what is in them. There is one exception, and it exists because you asked for it: when you export a mailbox, the panel reads that mailbox's messages, because it cannot build the file you are downloading out of anything else. Those bytes go straight through to your browser as the archive is assembled — none of it is written to disk on our side, no copy is kept when the download ends, and the request is written to your audit log like every other action on your account. Nothing else in the product reads the contents of your mail.
Your billing record, which is mostly a mirror of someone else's:
- Subscription status, renewal date, and invoice records for display in the panel.
- No card details, ever. Payment is taken by Creem, our merchant of record — see who else touches your data. Card numbers never reach our servers.
And an audit log: every state-changing action on your account, with a timestamp and who did it. It exists so that a security question has an answer.
Cookies and local storage
One cookie, __Host-fm_session. It holds a session token, is HTTP-only and Secure, is sent same-site, and lasts 90 days from your last visit with a hard stop at one year. It is strictly necessary — without it you cannot stay signed in — which is why there is no cookie banner asking you to consent to things we do not do.
Your browser also keeps a fm-theme value in local storage so the panel opens in the light or dark theme you chose. It never leaves your browser.
In the panel and in webmail: no advertising cookies, no third-party cookies, no analytics, no session recording, no fingerprinting. Nothing about a signed-in customer is measured or sent anywhere.
The marketing pages are the exception, and it is worth being exact about where the line is. Everything outside the product — the home page, the comparison and guide pages, this policy, and the signup and setup screens — loads Google Analytics, which sets its own cookies and tells Google that a browser visited a page. It is there to answer one question: how many people arrive, and where they stop.
Two limits on it, both of which are enforced in the code rather than promised here. The address is trimmed before it is sent — Google receives the path and never the query string, so the domain identifier that appears in a setup URL does not leave with it. And the events carry no personal data: they record that an account was created, an address was verified or a checkout was opened, never whose. Nothing that identifies you is ever a parameter.
The panel and webmail carry none of it. Once you are signed in and using the product, nothing is measured — the boundary is which part of the site loads the analytics at all, not a setting someone could flip.
Who else touches your data
Four companies, each named with what it does for us. No one else receives your data, and we do not sell or rent it to anyone.
- Cloudflare — serves this site and the control panel, and carries the connection from them to our database and mail servers.
- Creem — our merchant of record. Creem takes the payment, holds the card details, and issues your invoice. It receives your email address and what you bought.
- Hetzner — the servers our mail system and database run on.
- Google Fonts — serves the two typefaces this site uses, which means your browser requests them from Google and Google sees that request. Worth saying out loud rather than hiding in a footnote.
We also disclose data when the law requires it. If we ever receive such a demand we will tell you, unless we are forbidden from doing so.
Your rights
You can ask us to show you what we hold, correct it, export it, or delete it, and you can object to how we use it. Email hello@franklymail.com from your account address and we will answer within 30 days. We do not charge for it and we will not put you through a retention conversation first.
Two of those are things you can already do without asking us. Your mail is reachable over IMAP, so your archive was always portable — any mail client can copy it out whole. And the session list in your settings lets you revoke access to any device.
If you are in the EU or UK and think we have handled your data badly, you can complain to your local data protection authority. We would rather you told us first, but it is your right either way.
How long we keep it
While your account is active: for as long as you keep it. Nothing expires quietly behind your back.
- A failed renewal starts a 14-day window. Mail keeps flowing during it and nothing is deleted. Your billing screen shows the exact dates for your account.
- After that the account is suspended — mail stops, and the data stays. It remains for 60 more days, after which we may delete it. We will not delete a suspended account's mail without telling you first, and the schedule gives you at least 30 days' notice.
- If you cancel, the same clock applies from the end of the period you paid for. Ask us and we will delete it sooner.
Sessions expire on their own. Audit log entries and mail server logs are kept for security and delivery troubleshooting, and are not used for anything else.
Backups have their own clock, and it is shorter. Your mail and the account database are backed up every night and copied to storage in a different company's data centre in the EU. Those copies are deleted automatically after 30 days. So when you delete something, or close your account, a copy can survive in a backup for up to a month after it is gone from the live system — that is true of every hosting provider that takes backups at all, and we would rather write it down than let you assume otherwise.
Backups exist so that a broken server does not cost you your mail. They are not browsable, nothing routine is ever restored from them, and a request to delete your data removes it from the live system immediately and lets the backup copies age out on that 30-day clock.
Security
Passwords are hashed, TOTP secrets are encrypted, app passwords are stored only as hashes, and sessions are held server-side so that revoking one actually revokes it. Our database is not reachable from the internet, and the mail server's admin interface is not exposed to it either — the panel reaches both through a private tunnel.
What we will not tell you is that this makes us unbreakable. If we ever have a breach that affects you, we will email you about it, and we will say what happened rather than what our lawyers would prefer.
Children
The service is sold to adults and is not directed at children. We do not knowingly create accounts for anyone under 16.
Changes to this policy
When this page changes, the date at the top changes with it. If a change materially affects what we do with your data, we will email you rather than quietly re-dating the page.
Questions: hello@franklymail.com. See also our Terms of Service and Refund Policy.