← Back to ecosmail.fr Version francaise

Privacy Policy

Last updated: April 6, 2026

1. Data Controller

TOUT CREER — contact@ecosmail.fr
EcosMail is operated by TOUT CREER, registered in France.

2. Data We Collect

DataPurposeLegal BasisRetention
Phone numberAuthentication (OTP / EcoAuth)Contract performanceAccount lifetime
Email addressEmail serviceContract performanceAccount lifetime
Email contentDisplay and storageContract performanceAccount lifetime
Imported contactsAddress bookConsentAccount lifetime
Payment dataBillingContract performance5 years (legal obligation)
AI analysisEmail classification, briefingConsent30 days

3. Data We Do NOT Collect

EcosMail never collects:

4. Encryption

Your emails are protected by multiple layers of encryption:

An X25519/Ed25519 keypair is generated per user in anticipation of E2E deployment. Until client-side E2E is enabled, email and message content remains technically accessible to service operators for processing purposes (see Section 2).

5. Sub-Processors

ServiceProviderLocationData Processed
DatabaseSupabaseEU (Frankfurt)Metadata, email index
PaymentMollie B.V.Netherlands (EU)Payment transactions
AI AnalysisAnthropicUSAEmail content (for classification)
SMS OTPTwilioUSAPhone numbers
Email hostingIONOSGermany (EU)Email server

For sub-processors outside the EU (Anthropic, Twilio), data transfers are covered by Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework.

6. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights:

To exercise your rights: admin@ecosmail.fr
We will respond within 30 days as required by GDPR Article 12.

7. Security

We implement technical and organizational measures to protect your data:

8. Cookies

EcosMail uses no tracking, advertising, or analytics cookies. We only use a session token (localStorage) to maintain your login. No third-party trackers are present on our website or application.

9. Children's Privacy

EcosMail is not intended for children under 16. We do not knowingly collect data from minors. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Data Breach Notification

In the event of a personal data breach, we will:

11. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top indicates the latest revision. For significant changes, we will notify users by email.

12. Contact

For any privacy-related questions:
admin@ecosmail.fr

For security issues:
security@ecosmail.fr

French Data Protection Authority:
CNIL — Commission Nationale de l'Informatique et des Libertes