Privacy Policy

Last updated: 2026-08-18

Controller and contact

Northwire is the controller of personal data processed through this service.

Privacy contact: misfin://privacy@northwire.xyz

Scope

Northwire is a hosted Misfin mailbox service. It is currently in a testing period. Public signup, customer-managed domains, analytics, support email, and payments are not active processing activities unless this policy is updated.

Data we process

Depending on your use of Northwire, we process account and mailbox details, mailbox addresses, account and mailbox identifiers, settings, timestamps, password verifiers, client-certificate data, certificate trust and block data, messages, drafts, sender and recipient addresses, message metadata, delivery status, domain and alias data, security events, aggregate security metrics, and non-identifying serving-process liveness records.

We receive data from account holders and from other Misfin servers. When you send a message, we send its message and routing data to the recipient's Misfin server. A person whose data appears only in a message may not have an account with Northwire.

Northwire does not use advertising cookies or analytics. Release builds do not retain application access logs. Network providers may still process connection data necessary to operate their networks.

Purposes and legal bases

We use data to create and operate accounts and mailboxes, authenticate users, store and deliver messages, provide export and deletion features, and respond to support requests. The legal basis is performance of a contract with the account holder under GDPR Article 6(1)(b).

We use limited security and technical data to prevent abuse, protect the service, investigate incidents, and maintain its confidentiality, integrity, and availability. The legal basis is Northwire's legitimate interests under GDPR Article 6(1)(f). We use data minimisation, encryption, and short retention periods to balance those interests against your rights.

We may also process data when needed to comply with a legal obligation or for legal claims. If a future optional feature relies on consent, it will ask for consent separately and explain how to withdraw it.

Recipients and transfers

The recipient's Misfin server receives message and routing data when you send a message. That server is independently responsible for its processing and may be in any country chosen by the recipient.

Northwire operates from Taiwan. Cloudflare provides DNS services for Northwire. Depending on the deployed configuration, it may process DNS or connection data. Before launch, Northwire will confirm the enabled Cloudflare services, processing terms, locations, and transfer safeguards here.

Northwire does not sell personal data or disclose it to advertisers.

Retention

Account, mailbox, message, draft, alias, and trust data are kept until you delete them or delete your account, unless a longer period is required by law or necessary for legal claims.

Messages in Trash are permanently deleted after 30 days. You can permanently delete them sooner.

Signup, signin, password-change, and account-deletion confirmation state expires after 30 minutes. Domain-enrolment state expires after 24 hours. Security events and aggregate security metrics expire after 30 days. Non-identifying serving-process liveness records expire after 180 days.

Encrypted backups are retained for 30 days. Data deleted from the live service may remain in a historic backup until that backup expires, for up to 30 more days.

Before public launch, Northwire will document retention periods for provider and infrastructure logs.

Security

Northwire encrypts stored message content and much of its stored metadata, uses keyed indexes for address lookup, and rotates encryption-key material. This is not end-to-end encryption: Northwire can process message plaintext where needed to operate the service. Use end-to-end encryption, such as GPG, if needed.

Northwire maintains procedures to investigate personal-data breaches and will notify the competent authority and affected people when required by law.

Your rights

Subject to GDPR conditions and exemptions, you can ask for access, rectification, erasure, restriction, portability, or to object to processing based on legitimate interests. You can export account data and delete your account from the service settings.

For other requests, use the privacy contact above. We may ask for information needed to verify your identity. You may complain to the data-protection authority in your EEA country of residence, place of work, or alleged breach.

Automated decisions and children

Northwire does not make solely automated decisions with legal or similarly significant effects. The service is not directed to children. Do not use it if you are below the minimum age required by applicable law or cannot validly enter the service agreement.

Changes

We will publish material changes before they take effect where practicable.





This page is rendered from Gemini Gemtext to HTML. We recommened to get a proper Gemini client for the best experience.