Sign InGet Started Free →

Privacy Policy

Your privacy is our most important responsibility. This policy is written in plain language — so you understand exactly how we handle and protect your data.

Last updated: January 15, 2026

Core Principles

Our 4 Privacy Commitments

End-to-End Encrypted

All emails are encrypted — unreadable to us and anyone else.

Zero Data Selling

Your data is never sold to anyone. Ever. Thats our guarantee.

India Data Centers

All data stored in secure facilities in Mumbai and Delhi.

Youre in Control

Download or permanently delete your data at any time.

DPDP Act 2023 — Fully Compliant

IvaBuddy is fully compliant with India's Digital Personal Data Protection Act 2023. All your data protection rights are legally safeguarded.

What Information We Collect

Account Information: When you sign up: your name, email address, phone number (optional), and password (stored as a secure hash — never plaintext).
Email Data: Your emails, attachments, contacts, and calendar data — this belongs to you. We only process it to deliver and store your messages.
Usage Data: Login timestamps, IP addresses, device type — collected for security and fraud prevention only.
Domain Information: When you add a custom domain, we store the domain name and DNS verification details.

How We Use Your Data

Email Delivery: We process only whats strictly necessary to send and receive your emails.
Security & Fraud Prevention: Monitoring login attempts, detecting suspicious activity, and protecting your account.
Service Improvement: Only anonymized, aggregated analytics — individual user data is never used for this.
Legal Compliance: If a valid Indian court order requires it, only the minimum required data is shared — and youll be notified.

Third-Party Sharing

Advertisers: NEVER. IvaBuddy is a completely ad-free platform. No advertiser ever receives your data.
Analytics Tools: We use privacy-first, cookieless analytics. No personal data is sent to third-party analytics providers.
Email Infrastructure: Standard industry protocols (SMTP, IMAP) are used for delivery. All communication is encrypted.
Legal Requests: Only valid Indian court orders, with minimum data shared and the user notified.

Your Rights Under DPDP Act 2023

Right to Access: You can request a full copy of all data we hold about you. We respond within 30 days.
Right to Correction: You can request correction of any inaccurate personal data we hold.
Right to Deletion: Delete your account and all your data is permanently purged within 30 days.
Data Portability: Export all your emails in standard formats (MBOX, PST) at any time.
Right to Object: You can opt out of any data processing that is legally optional.

Security Measures

Encryption at Rest: All stored data is protected with AES-256 encryption.
Encryption in Transit: All network communication is secured with TLS 1.3.
Two-Factor Authentication: 2FA is optional but strongly recommended. Enable it via Settings → Security.
Security Audits: We conduct regular independent third-party security audits.
Breach Notification: In the event of any data breach, you will be notified within 72 hours.

Data Retention

Active Accounts: Your data is securely retained for the lifetime of your active account.
Deleted Emails: Emails moved to trash are permanently purged after 30 days.
Account Deletion: After an account deletion request, all data is permanently deleted within 30 days.
Backup Copies: Disaster recovery backups are rotated every 90 days.

Cookies & Tracking

Session Cookies Only: We use cookies exclusively for login sessions and CSRF security. No tracking cookies.
No Cross-Site Tracking: IvaBuddy never tracks you across other websites.
Analytics: Privacy-first, cookieless page analytics only — no personal data is captured.

Data Deletion Request?

Want to permanently delete all your data, or need to reach our Data Protection Officer? Email us directly — we respond within 30 days.

privacy@ivabuddy.com

We will acknowledge your request within 24 hours.