Privacy Policy
Effective April 16, 2026
Atmosphere Mail LLC operates the relay. Here is exactly what we collect, why, and for how long.
The data we hold
- Your DID and registered sending domain(s).
- A salted hash of your API key — the plaintext key is only ever shown once, at enrollment.
- DKIM keypairs issued to your domain. Private keys are stored encrypted at rest and never leave our servers.
- Send logs: per-message sender DID, recipient address, From/To headers, timestamps, delivery status code, and bounce disposition. We do not store message bodies after handoff to the queue.
- Rate-limit counters: short-window send counts per DID used to enforce hourly and daily limits.
- Bounce records: inbound DSN classifications per DID so we can suspend senders with pathological bounce rates.
- Suppression list: recipients who used the one-click unsubscribe header, keyed per sender DID.
- IP addresses of SMTP clients, kept only in transient logs for abuse investigation and rotated out under the retention schedule below.
Data we deliberately avoid
We do not retain full message bodies past delivery. We do not set web tracking cookies, fingerprint browsers, or embed third-party analytics on any of our pages. We do not sell or rent member data to anyone, under any circumstances.
How long we keep it
- Terminal message logs (sent, bounced): 30 days, then purged.
- Rate-limit counters: 48 hours rolling window.
- Suppression entries: for the life of the member record — unsubscribes must persist.
- Member record: indefinitely while active; removed on request.
Who else sees this
Send events and bounce outcomes are evaluated by our internal Trust & Safety rules engine (Osprey) to derive reputation labels (e.g. highly_trusted, auto_suspended). Labels are published via an atproto labeler and are intentionally public — any consumer of the labeler can read them. We do not share message content, recipient lists, or API keys with anyone.
Access, correction, deletion
You can fetch your member status and current labels via the API-key-authenticated /member/status endpoint. To correct or delete your member record, write to postmaster@atmos.email from a mailbox you can prove control of (or sign the request with your DID's signing key). We respond to verified requests within 14 days.
How we protect it
API keys are stored as salted hashes. DKIM private keys are encrypted at rest. Host access is restricted to the LLC's operations team and uses hardware-keyed SSH. If we discover a breach that exposes member data we will notify affected members without undue delay.
Reach us
Atmosphere Mail LLC — postmaster@atmos.email