Privacy policy
Last updated 24 September 2026
Waribox gives a team one shared email address. Mail sent to it is delivered to each member’s own inbox, and replies go back out through the shared address. This page explains what that involves for your data. We keep as little as the service needs to work.
What we never store
We do not store the content of any email: no bodies, no subjects, no attachments. Each message is read in memory only to deliver it, then discarded. It passes through Amazon SES on its way to its recipients.
What we store, and for how long
- Your account: your email address and team name, kept until you ask us to delete the account.
- Pipes and members: each pipe’s address and name, and the email addresses of the members you add, with whether they have confirmed. Kept until you remove them.
- Conversations: for each conversation, the external addresses taking part and the IDs of messages we sent, so replies reach the right people. Deleted after 90 days without activity.
- Activity log: for each message, the sender’s address, how many people it went to, what happened to it (for example delivered, or refused as too large), and the time. Deleted after 30 days.
- Sign-in and verification links: the link, the address it was sent to, and a one-way hash of the requesting IP address, used only to limit abuse. Deleted shortly after the link expires, within two days.
- Your domains: if you use an address on your own domain, the domain name and the results of our checks of its public DNS records.
Our hosting provider keeps short-lived operational logs of requests. Our own log lines contain counts and statuses, never message content.
Who receives your mail
Mail to a pipe goes only to that pipe’s members who have confirmed their address. Replies go only to the people already in that conversation. We never add you to a mailing list, never send marketing, and never sell or share addresses.
Members receive nothing until they click the confirmation link we send them. The pipe’s owner can remove a member at any time, and that member then receives nothing further from that pipe.
Services we use
- Cloudflare runs the service, receives mail for mail.waribox.app, stores the data above, and provides the bot check on the sign-in page (Turnstile).
- Amazon Web Services (SES) sends the email: deliveries to members, replies, and sign-in links. It keeps its own delivery records and a list of addresses that bounced or complained, so they are not mailed again.
Data is processed in the United States and on Cloudflare’s global network. An optional automatic urgency tag would send a message’s subject and opening text to an outside service; it is turned off, and we will update this page before we ever turn it on.
Cookies
We set one cookie, to keep you signed in for up to 30 days. It is not used for tracking. The sign-in page loads Cloudflare Turnstile to tell people from bots. We use no analytics and no advertising trackers.
Your choices
You can remove pipes, members and domains yourself at any time. To get a copy of your data, correct it, or delete your account, write to privacy@waribox.app. We reply within 30 days.
Changes and contact
If we change this policy we will update this page and its date, and tell account owners by email about anything significant. Questions go to privacy@waribox.app.