Inovamail Legal
Cookie Policy
Inovamail is privacy-first: we use the minimum cookies and local storage needed to run the Service securely, we block external images by default to limit tracking, and we do not use third-party advertising cookies or cross-site ad tracking. This summary is for convenience and does not replace the full text below.
1. What cookies and local storage are
This Cookie Policy explains how Inovamail (the "Service") uses cookies and similar technologies when you visit our website at [WEBSITE URL], use our web application, or otherwise interact with the Service. It should be read together with our Privacy Policy, which describes how we handle personal data more generally, and forms part of the terms incorporated into our Terms of Service.
A cookie is a small text file that a website asks your browser to store on your device. When you return, your browser sends the cookie back, which lets the site recognise your session or remember a setting. Cookies may be "first-party" (set by Inovamail) or "third-party" (set by another domain), and may be "session" cookies (deleted when you close your browser) or "persistent" cookies (kept for a defined period or until you delete them).
We also use related technologies that are not, strictly speaking, cookies but serve similar functions. These include local storage and session storage (key-value data your browser holds for the web application), IndexedDB and similar in-browser databases (used, for example, to cache data or hold encryption material locally so the Service can operate), and pixels, tags, or software development kits ("SDKs") where used. In this Policy, "Cookies" refers to all of these technologies unless we say otherwise.
Because Inovamail is an encrypted email service, some in-browser storage is essential to security. For example, cryptographic keys and session material may be held in your browser's local storage so that end-to-end-encrypted content can be decrypted on your device and never in a form we can read.
2. Our privacy-first approach
Consistent with the privacy-first design of Inovamail, we take a deliberately minimal approach to Cookies:
- Minimal use. We use Cookies only where they are necessary to deliver, secure, and improve the Service, and we prefer first-party, essential technologies over optional ones.
- No third-party advertising. We do not use Cookies to build advertising profiles, to serve behavioural or targeted advertising, or to sell or "share" personal information for cross-context behavioural advertising within the meaning of applicable privacy laws.
- No cross-site ad tracking. We do not participate in advertising networks or data brokerages that track you across unrelated websites.
- External images blocked by default. The Service blocks external image loading in messages by default, which prevents many common email-tracking pixels from reporting when or where you open a message.
- Privacy-respecting analytics only. Where we measure how the Service is used, we aim to use privacy-respecting, aggregated analytics and, where practical, techniques that do not rely on cross-site identifiers.
This approach means that, in many configurations, the only Cookies in use are strictly necessary ones that do not require consent under applicable law.
3. Categories of cookies we use
We group the technologies we may use into the categories below. The table lists representative entries; the specific names, purposes, and durations in effect at any time are the ones actually deployed in the Service and disclosed through our cookie settings tool where one is provided. Durations are approximate and may be shorter where a session ends earlier or you clear your browser storage.
3.1 Strictly necessary
Required for the Service to function and to keep it secure. These cannot be switched off through our tools without breaking core functionality, and in most jurisdictions they do not require consent.
| Name | Purpose | Duration | Type |
|---|---|---|---|
| [COOKIE NAME] | Maintains your session and load-balancing / routing so requests reach the correct server. | [DURATION] | First-party · Session |
| [COOKIE NAME] | Protects against cross-site request forgery (CSRF) and other request-integrity attacks. | [DURATION] | First-party · Session |
| [COOKIE NAME] | Stores your current cookie choices so we can honour them. | [DURATION] | First-party · Persistent |
3.2 Authentication and security
Used to sign you in, keep you signed in, remember trusted devices, support two-factor authentication, and hold the local material needed to operate encryption on your device.
| Name | Purpose | Duration | Type |
|---|---|---|---|
| [COOKIE NAME] | Keeps you authenticated between requests after sign-in. | [DURATION] | First-party · Session or Persistent |
| [COOKIE NAME] | Remembers a trusted device or a completed two-factor step to reduce repeated challenges. | [DURATION] | First-party · Persistent |
| [COOKIE NAME] (local storage / IndexedDB) | Holds encrypted key material and cached data on your device so end-to-end-encrypted content can be decrypted locally. | [DURATION] | First-party · Local storage |
3.3 Functional and preferences
Remember choices you make to give you a better experience, such as language, theme, and interface settings. Disabling these may cause the Service to forget your preferences.
| Name | Purpose | Duration | Type |
|---|---|---|---|
| [COOKIE NAME] | Stores interface preferences such as language, locale, or theme (for example, light or dark mode). | [DURATION] | First-party · Persistent |
| [COOKIE NAME] | Remembers layout, list, or view settings within the application. | [DURATION] | First-party · Persistent |
3.4 Analytics
Help us understand how the Service is used so we can maintain and improve it. Where used, we aim to keep analytics privacy-respecting and, where practical, aggregated. These are optional and, where required by law, are set only with your consent.
| Name | Purpose | Duration | Type |
|---|---|---|---|
| [COOKIE NAME] | Measures aggregate usage, such as which features are used and whether pages load correctly. | [DURATION] | First-party · Persistent |
| [COOKIE NAME] | Distinguishes sessions for performance and error monitoring in aggregate. | [DURATION] | First-party · Persistent |
4. Third-party cookies
We keep third-party Cookies to a minimum. We do not use third-party advertising cookies, and we do not permit advertising networks to track you across other websites through the Service.
A limited number of third parties may set Cookies or receive technical data where they provide infrastructure or functionality that the Service relies on — for example, security and anti-abuse protection (such as challenge or CAPTCHA mechanisms used to protect sign-in and to challenge unknown senders), content delivery, payment processing at checkout, or privacy-respecting analytics. Where any such analytics are used, we select providers and settings intended to respect user privacy, and we do not use them to build advertising profiles. The current list of providers that process personal data on our behalf is described in our Subprocessors page and Privacy Policy.
Third-party Cookies are governed by the relevant third party's own privacy and cookie notices, which we encourage you to review.
5. Managing and disabling cookies
You have several ways to control Cookies:
- Our cookie settings. Where a cookie settings tool or banner is provided, you can use it to accept or reject non-essential Cookies and to change your choice at any time.
- Browser controls. Most browsers let you view, block, or delete Cookies and clear local storage through their settings or privacy menus. You can usually set your browser to warn you before accepting Cookies, or to refuse them.
- Device and profile settings. You can clear stored site data for the Service, which removes Cookies and local storage associated with it.
Disabling essential Cookies will break the Service. Strictly necessary and authentication or security technologies are required to sign in, maintain your session, and operate encryption on your device. If you block or delete them, you may be unable to log in, stay logged in, decrypt your content, or use core features. Clearing local storage may also remove locally cached data. This does not affect the availability of your account itself, but it may require you to sign in and re-establish local state again.
Disabling functional or analytics technologies is safe and will, at most, cause the Service to forget your preferences or reduce our ability to measure and improve it.
6. Do Not Track and Global Privacy Control
Some browsers offer a "Do Not Track" ("DNT") signal. Because there is no common industry standard for how DNT signals should be interpreted, and because we do not engage in cross-site behavioural advertising in any event, the Service does not respond to DNT signals in a distinct way.
Where required by applicable law, we treat a recognised Global Privacy Control ("GPC") or comparable opt-out preference signal sent by your browser or a browser extension as a valid request to opt out of any "sale" or "sharing" of personal information for cross-context behavioural advertising, to the extent such processing occurs. As described above, Inovamail does not sell or share personal information for advertising in the ordinary course. For more on your privacy choices and rights, see our Privacy Policy.
7. Consent
We do not require consent for strictly necessary Cookies, which are essential to provide a service you have requested. For non-essential Cookies — such as functional and analytics technologies — we obtain consent where applicable law requires it.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with equivalent requirements, we will ask for your consent before setting non-essential Cookies (for example, through a cookie banner or settings tool), you may decline or accept by category, and you may withdraw your consent at any time by changing your cookie settings or your browser controls. Where consent is not legally required, we rely on our legitimate interests in operating and securing the Service, subject to any applicable opt-out.
Withdrawing consent does not affect the lawfulness of any processing carried out before you withdrew it.
8. Changes and how to contact us
We may update this Cookie Policy from time to time to reflect changes in the technologies we use or in applicable law. When we do, we will revise the "Last updated" date above and, where the change is material, we may provide additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy, except where your consent is separately required.
If you have questions about this Cookie Policy or our use of Cookies, contact us at [PRIVACY EMAIL]. For broader questions about how we handle personal data, please see our Privacy Policy.