← Back to Plexus Mail

Privacy Policy

Effective 11 September 2026

Plexus Mail is designed so readable mail, private messaging keys, contacts, drafts, and mailbox history stay in the encrypted local vault on your device. The Plexus service transports encrypted packages and cannot ordinarily read their contents.

Information Plexus processes

  • Your public handle, PeerID, public messaging keys, passkey public-key records, linked-device labels, recovery-code hashes, sessions, and blocked-sender choices.
  • A coarse signup country, when Cloudflare supplies one, plus limited security and rate-limit events used to prevent abuse.
  • Encrypted message packages, routing identifiers, timestamps, and delivery receipts needed to deliver mail across the primary and secondary Plexus relays.
  • A web-push endpoint and its associated subscription keys only when you enable notifications. Notifications are generic and do not contain mail content.

Mail content and safety reports

Mail content is encrypted on the sender’s device separately for each recipient device. Relay servers store ciphertext, not readable messages. If you deliberately report a message, Plexus sends the reported subject and message excerpt, reason, sender, and reporter identity to the private operations dashboard so the report can be reviewed.

Storage and retention

Queued encrypted packages are removed after confirmed delivery or expire after 30 days. Delivery receipts and relay-send events are retained for up to 30 days. Expired sessions and temporary authentication challenges are removed automatically. Accounts inactive for 365 days are removed with their public keys and queued packages; retired handles are kept so they cannot be reassigned. Safety reports are retained as an abuse-review record unless removed by the operator.

Encrypted server backups are kept on separate owner-controlled infrastructure for up to 30 days. The backup decryption key is kept offline.

Service providers

Cloudflare provides public routing and network protection and may supply the coarse signup-country header. Browser push services deliver generic notification signals when notifications are enabled. Discord and Healthchecks.io receive operational uptime and backup-status alerts only—not message content, handles, contacts, or mailbox data.

Your choices

You can disable notifications, remove linked devices, block or unblock senders, delete local messages, and export or restore an encrypted local backup from Plexus. Account recovery revokes old passkeys and devices. Locking Plexus ends the current session on that device.

Security and contact

Plexus uses transport encryption, per-device end-to-end message encryption, passwordless passkeys, restricted server access, and encrypted backups. No system can promise absolute security. For privacy questions, support, or a data request, email [email protected].