Legal

Privacy Policy

Last updated August 11, 2026

kontacts.dev is an email product. That means we store the contents of your email, and this page explains exactly what happens to it. Everything here describes what the system actually does today. Where we do not do something well, we say so rather than describing what we intend to build.

1. Who we are

kontacts.dev is operated by an independent developer established in the European Union. We are publishing the operator's full legal identity here shortly; until then, you can reach us about anything on this page at privacy@kontacts.dev, and we will answer with it if you ask.

2. What we collect, and why we are allowed to

Your mail. Every message sent to or from your gitmail address is stored in our database in full — the sender, the recipient, the subject line, and the complete body in both plain text and HTML. We store it so that the product can show it to you. We do not read it, scan it, or build a profile from it. Legal basis: performance of our contract with you, Art. 6(1)(b) GDPR.

Your account. You sign in either with GitHub or with a sign-in link we email you. If you use GitHub, we receive and store your GitHub identity and the email address on that account; if you use the emailed link, we store the email address you gave us. Either way we also store the gitmail address you send from and the display name you set. Art. 6(1)(b).

A GitHub access token. If you sign in with GitHub, we also store the access token GitHub issues for your account, and the refresh token that goes with it if GitHub issues one. This is a live credential: it lets our server ask GitHub things as you. We use it for one thing — asking GitHub which installations of our GitHub App you administer, so that you can link one to your organisation here. It is never sent to your browser, and deleting your account deletes it in the same request. Art. 6(1)(b).

Your domains. If you connect a domain of your own, we store the domain name, its verification status, the identifier our email provider assigns to it, and the addresses you create on it. Art. 6(1)(b).

A send counter. One number per account per day, counting messages sent, so we can enforce the daily sending limit and make spam through gitmail expensive. Legitimate interest in preventing abuse, Art. 6(1)(f).

Server logs. Our hosting provider records requests to the site — including IP addresses — so we can debug failures and spot abuse. Art. 6(1)(f).

Page views. See section 6.

3. Your mail can end up in a GitHub issue

This is how the product works, and it is the part most likely to surprise you.

If you link a GitHub repository to a project, mail arriving at that project's address is posted into that repository as a GitHub issue: the sender's address and the full message body become the issue body, and the subject line becomes the issue title.

Emails sent to this project's address will be published as public GitHub issues — including the sender's address and the full message body. Anyone can read them. Do not link a public repository to an address that receives private correspondence. This is a deliberate feature, not a leak — but you should choose it knowingly.

4. Where your data goes

We use four providers. Our three processors — Supabase, Vercel and Resend — each publish a data processing agreement that incorporates the EU Standard Contractual Clauses for transfers outside the EEA. GitHub is different: it is not our processor. If you sign in with GitHub you are using your own GitHub account, and issues are created in a repository you own, so GitHub handles that data as an independent controller under its own privacy statement, not under instructions from us.

ProviderWhat it doesEntityWhere it processes
SupabaseDatabase and sign-inSupabase Pte. Ltd., SingaporeOur database is hosted in Frankfurt, Germany (AWS eu-central-1)
VercelWebsite hosting and page-view analyticsVercel Inc., USAOur server code runs in Washington, D.C., USA (iad1)
ResendSending and receiving emailPlus Five Five, Inc. (Resend), USAIncoming mail is received in Ireland (AWS eu-west-1); Resend's API is US-based
GitHubGitHub sign-in, and issue creation described aboveGitHub, Inc., USAUSA (independent controller, not our processor)

In plain terms: your mail is stored in Germany, but it passes through the United States on the way in and on the way out. Our application code runs on servers in Washington, D.C., and our email provider is a US company. We are not going to describe ourselves as an EU-hosted service on that basis. Moving hosting into the EU is on our roadmap, and this page will change when it happens — not before.

We do not use your data for anything outside this list, and we do not add a provider without updating this page.

5. AI

We do not train AI models on your mail. We do not send your mail to any AI service. This is a standing commitment, not a current-configuration statement.

What we cannot promise on someone else's behalf: our providers publish their own subprocessor lists, and Resend's includes AI vendors for parts of its own product. We have no way to audit that beyond what they publish, so we would rather you learn it here than find it there. Their list is at resend.com/legal/subprocessors.

6. Page views, and why there is no cookie banner

We use Vercel Web Analytics to count visits to kontacts.dev. For each page view it records the time, the page and referring page, filtered query parameters, a coarse location derived from your IP address (country, region, city), and your operating system, browser and device type.

It sets no cookies and stores nothing on your device. Visitors are identified by a hash computed from the request, which Vercel discards after 24 hours; it cannot follow you to other websites. Because nothing is written to or read from your device for analytics, no consent banner is required — and that is the only reason you are not seeing one, not an oversight.

The one cookie we do set is the session cookie that keeps you signed in. It is strictly necessary for the service to function.

Legal basis for analytics: legitimate interest in understanding whether the site works, Art. 6(1)(f).

7. How long we keep it

We run no automatic deletion of any kind. There is no expiry job and no retention timer. Your mail, your account and your domain records stay until they are deleted by request. We are not printing a retention schedule we do not enforce.

You delete your account yourself. It is in Settings in the dashboard, behind a typed confirmation, and it takes effect in that request — not within thirty days, and without asking us. It removes your sign-in, the GitHub access token described in section 2, your stored mail both sent and received, your sending address and your send counter, and any org that is yours alone together with its projects, domains and domain records. Orgs you share with other people survive: you are removed from them, and if you were their only owner someone else is made owner so the org is not left stranded.

We keep one record of the deletion itself — the account id and the time, nothing about your mail — so that we can evidence it if you or a regulator ask.

If you would rather we did it, or you cannot sign in, email privacy@kontacts.dev and a person will erase the account by hand within 30 days, the maximum the GDPR allows us (Art. 12(3)).

Our database provider takes its own backups. A record you have deleted can survive in those backups until they roll over.

8. Your rights

You have the right to access your data, correct it, have it erased, take it elsewhere in a portable form, restrict how we use it, and object to processing we base on legitimate interest.

Erasure you can exercise yourself, immediately, from Settings — see section 7. For any of the others, email privacy@kontacts.dev. We answer within 30 days. We will not make you use a form, and we will not route your request through a public issue tracker.

You can also complain to the data protection authority in the country where you live or work. In France that is the CNIL (cnil.fr).

9. Security, stated honestly

  • Traffic to kontacts.dev and between us and our providers is encrypted in transit with TLS.
  • Our database provider encrypts its disks and its backups at rest with AES-256, with the keys held in FIPS 140-2 hardware security modules.
  • Your mail bodies are stored as ordinary database columns. The disk underneath is encrypted; the message is not encrypted with a key only you hold. kontacts.dev is not end-to-end encrypted and we are not going to imply that it is. Anyone with our database credentials could read your mail, so the honest security statement is that we keep those credentials tightly held and access to production limited to the person operating the service.

10. Age

kontacts.dev is not intended for anyone under 16, and we ask that you do not use it if you are.

11. Changes to this page

When this changes, we change the date at the top of it. There is no separate archive; the current version is the one that applies.