Legal

Privacy Policy

You are trusting us with your company's mail. This page says exactly what we hold, what we never look at, where it physically sits, and how you get it all back. No clause here is written to be skipped.

Effective 16 August 2026 Last updated 17 September 2026 Questions support@mailora.io

01 Who we are

Mailora is the email service. HostGet is the company behind it. If you have a privacy question, one address reaches a human.

Mailora is a business email service operated by HostGet, of Tower of Aakash, Level 18, 54 Gulshan Avenue, Dhaka 1212, Bangladesh ("Mailora", "we", "us").

This policy covers mailora.io, the Mailora webmail application, the administrator portals, and mail delivered through our servers. It applies to two different kinds of people, and the difference matters:

  • Our customers — the organisation that buys mailboxes. They decide who gets an account and what the settings are.
  • Mailbox users — the people inside that organisation who send and receive mail.

For mail content, the customer organisation is the data controller and we are the processor: we act on their instructions. For billing and account records, we are the controller.

If you use a Mailora mailbox at work

Your employer controls the account. They can reset your password, suspend the mailbox, and — depending on their own policy — access its contents. Requests to delete or export your mailbox should go to your administrator first, not to us.

02 What we collect

Account details, billing records, a log of admin actions, and counts of AI usage. Not the text of your messages.

WhatExamplesWhy
Account Mailbox address, display name, domain, role, password hash To run the mailbox and sign you in
Billing Organisation, plan, mailbox count, invoices, payment status To charge the correct amount and meet tax obligations
Administrator log Who did what and when — actor, action, target, timestamp So an organisation can see who created, suspended or deleted an account
AI usage counters Mailbox address, which feature, timestamp To enforce plan quotas and bill accurately
Mail delivery logs Sender, recipient, size, time, delivery result Required to deliver mail, fight spam and diagnose failures
Signup source The utm_source, utm_medium, utm_campaign, utm_content and utm_term tags of the link you arrived through, if it had any, and the page you landed on To know which campaigns bring new customers. Nothing else from the link is kept.
Mail content Messages, attachments, drafts, contacts, folders Stored so you can read it — see section 3

What the AI counter actually stores

One row per AI action, holding the mailbox address, the feature name, and the time. There is no column for message text, subject lines, or recipients — so message content cannot appear in it, by construction rather than by promise.

03 Your mail content

We store your mail because that is the product. We do not read it, scan it for advertising, or sell it. Nobody sells ads on Mailora — there are no ads.

We commit to the following, and each is a limit on us, not an aspiration:

  • No advertising. Mailora has no advertising business. Your mail is not profiled, segmented, or used to target anything.
  • No sale. We do not sell, rent or trade mail content or personal data. There is no exception for "partners".
  • No routine human access. Our staff do not read customer mail as part of normal operations.

Our staff may access a mailbox in only three situations:

  • You or your administrator explicitly ask us to, in order to fix a problem;
  • It is strictly necessary to restore a failing service — for example recovering a corrupted mailbox from backup;
  • We are legally compelled (see section 7).

Automated systems do process mail in transit — spam and phishing filtering cannot work otherwise. That processing is automatic, is not retained beyond what the filter needs, and produces no profile of you.

04 AI features

AI only runs when someone presses the button. The text of that one message goes to a specialist AI provider, gets used to answer, and is not used to train anything. Your admin can switch AI off for the whole organisation.

Mailora's AI features — compose, reply, summarise, triage and the assistant — are invoked, not ambient. Nothing is analysed in the background; nothing runs across your mailbox on a schedule.

When a user triggers an AI action:

  • The relevant text — usually the message being worked on, plus any instruction typed — is sent over an encrypted connection to a specialist third-party AI provider.
  • The provider returns a result, which is shown to the user.
  • We record that an AI action happened, for quota and billing. We do not store the text sent or the text returned.

Our agreements with AI providers require that content sent through the API is not used to train their models and is retained only briefly, for abuse monitoring, before deletion.

Turning AI off

An administrator can disable AI for an entire organisation from the admin portal. With AI disabled, no message content leaves our servers for AI processing at all. Organisations under confidentiality or regulatory constraints should use this switch.

We will name our current AI sub-processor, and any change to it, on request to support@mailora.io. Where a customer requires advance notice of sub-processor changes in writing, we will agree that in the contract.

05 Where your data lives

Your mail sits on our own servers in Bangladesh — not on Google's or Microsoft's. Only AI requests leave the country: when someone uses an AI feature, and the automatic phishing check on messages opened in the webmail.

Mail, mailboxes, backups and account records are stored on servers we operate in a data centre in Gazipur, Dhaka Division, Bangladesh. This is deliberate: it is the difference between renting space in someone else's platform and running the mail ourselves.

Data leaves that infrastructure in only two circumstances:

  • Mail delivery. Sending mail necessarily transmits it to the recipient's provider, wherever they are. That is how email works, and it is outside our control once handed over.
  • AI requests. Content sent for an AI action is processed by a provider that may operate outside Bangladesh, typically in the United States. See section 4, including how to disable this entirely.

Encrypted offsite backup copies may be stored with a cloud storage provider outside Bangladesh. Those copies are encrypted before they leave our servers with a key that the storage provider does not hold, so the provider cannot read them.

06 Cookies & local storage

This website sets no cookies unless you accept advertising cookies. It keeps your signup progress and the campaign link you came from in your own browser. The apps store one sign-in token, which expires after 12 hours.

The mailora.io website

Runs no analytics and loads no fonts or images from any third party. Our web server keeps standard access logs (IP address, page, time, user agent) for security and troubleshooting. In your browser, the site keeps:

  • Signup progressmailora_signup in local storage: a reference to the signup you started and its private key, so you can close the page while your domain’s DNS updates and come back to the same step.
  • Campaign tags — if you arrived through a link with utm_ tags, those five tags and the page you landed on (never anything else from the link) are kept in this tab’s session storage (mailora_utm_last, mailora_utm_first) and saved with your signup if you sign up. If you have accepted advertising cookies, the first such link is remembered in local storage for up to 30 days; declining or withdrawing removes it.
  • Your advertising choicemailora_ad_consent (granted or denied), once you have made one. It stays until you change it or clear this site’s data in your browser.
  • Conversions already reportedmailora_meta_sent: the random reference numbers of the signup milestones this browser has already reported, so the same signup is never counted twice. Only written after you accept.
  • Payment returnmailora_signup_flags in session storage, for a moment after the payment page sends you back, so this page knows whether to wait for the payment confirmation.

Advertising measurement (Meta Pixel)

Why: to know which of our advertisements lead to real signups, so we spend on the ones that work. Legal basis: your consent. When the measurement is switched on, the home page, our guides and the signup page show a short notice with two equal buttons, Accept and Decline. Until you choose, nothing is loaded from Meta.

To learn which of our ads bring people to Mailora, the home page, our guides and the signup page can use Meta Pixel. It stays off until you accept advertising cookies, and declining changes nothing about signing up. Only after you accept does the site load Meta’s script, which sets the _fbp cookie (and _fbc when you came from a Facebook ad) and tells Meta: that a page was viewed, that you looked at our prices, that you started a signup, that the account was created (your free month started, or your paid mailboxes were set up), that a checkout started (with its amount and currency), and that a payment was confirmed (with its amount and currency). Each signup milestone carries a random reference number so it is counted once; the number reveals nothing about you. Automatic collection of page buttons and form fields (“automatic advanced matching”) is switched off.

The _fbp and _fbc cookies are Meta’s and expire on the schedule Meta sets. What Meta does with the events it receives is governed by Meta’s own terms and privacy policy.

We never send Meta your name, email address, phone number, company, domain, anything you type into a form, or anything from any mailbox, and the webmail, admin and renewal pages never load it. If we also report those same events from our server, Meta receives your IP address, your browser’s user agent and the Meta browser identifiers above — again only if you accepted. We keep those identifiers with the signup for at most 30 days, then delete them. You can change your choice at any time with Ad cookie settings at the bottom of the home page, our guides and the signup page; withdrawing stops further measurement and removes the Meta cookies from this site.

The webmail and admin applications

After you sign in, the application stores a single session token in your browser's local storage under the key hostget_token. It exists so you are not asked for your password on every action, and it expires 12 hours after sign-in. Signing out removes it immediately. It is not a tracking identifier and is never shared.

07 Who else touches it

A short list: an AI provider when AI is used, a payment processor when you pay, an encrypted backup store, the data centre, and Meta — only if you accept advertising cookies on this website. Plus the law, if it compels us — and we will tell you unless we are forbidden to.

CategoryWhat they receiveWhen
AI providerThe text of the message being acted onWhen a user triggers an AI feature, and when a message is opened in the webmail (automatic phishing check)
Payment processorBilling contact and amountWhen you pay. We do not store full card numbers.
Offsite backup storageEncrypted archives only, unreadable to themNightly
Meta (advertising measurement)The events listed in section 6 — never names, email addresses, form contents or mailOnly if you accept advertising cookies on this website
Data centre operatorPhysical custody of the serversContinuously. No access to accounts.

Legal requests

We disclose data to authorities only where we are legally required to. Where we are permitted to tell you, we will, so that you have the opportunity to challenge it. We do not give any government direct or unsupervised access to our systems, and there is no mechanism in our infrastructure that would allow it.

If the business changes hands

If Mailora is acquired or merged, data may transfer to the acquirer, who would be bound by this policy until you are given notice of any change. You would be told before any such transfer takes effect.

08 How long we keep it

Mail stays until you delete it. Delete it and it is gone within 30 days, backups included. Invoices we must keep for tax law.

DataKept for
Mail in an active mailboxUntil you or your administrator delete it
Deleted mailRemoved from live systems on deletion; purged from backups within 30 days
Mailbox after the account is closed30 days, then permanently deleted — this is your window to export
An unpaid free month after it endsMailbox and mail kept 30 days; we email you 3 days before they are permanently deleted
A signup that was never finished (no account created, nothing paid)90 days, then deleted
Mail delivery logs90 days
Administrator action log2,000 most recent entries per system
AI usage countersCurrent and previous billing period
Meta browser identifiers, IP address and user agent kept with a signup (only if you accepted advertising cookies and we report from our server)30 days at most
Campaign tags in your browserThis tab only; up to 30 days for the first link if you accepted advertising cookies
Invoices and payment recordsAs required by tax law, typically 6 years

The 30-day window is real

After an account closes, we hold the mailbox for 30 days so you can still get your mail out. After that it is deleted from live systems and from backups, and we cannot recover it — not for a fee, not on appeal. Export before you close.

09 Security

Encrypted in transit, isolated between organisations, backed up nightly to a second location, and monitored around the clock. If a breach affects you, we tell you.

  • In transit. All web and mail connections use TLS. Mail to other providers is delivered over TLS wherever the receiving server supports it.
  • Authentication. Passwords are stored hashed, never in plain text. Sessions are signed and time-limited.
  • Isolation. Each organisation's data is scoped to its own domain; administrators can reach their own organisation and no other. This is enforced on the server, not in the interface.
  • Sender authentication. We publish SPF, DKIM and DMARC records so recipients can verify that mail claiming to be from your domain really is.
  • Backups. Nightly, replicated to a second machine, and copied offsite in encrypted form.
  • Monitoring. Automated checks run every five minutes across services, ports, certificates, disk and backup freshness, and alert a human on failure.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will notify affected customers without undue delay, telling you what happened, what data was involved and what we did about it.

10 Your rights

Get a copy, fix mistakes, delete it, or take it elsewhere. Mail is portable by design — standard protocols, no lock-in.

You can ask us to:

  • Access — give you a copy of the personal data we hold about you.
  • Correct — fix anything inaccurate.
  • Delete — erase your data, subject to records we must keep by law.
  • Export — supply your data in a portable format.
  • Restrict or object — limit how we process it.

If you use a mailbox provided by your employer, send these requests to your administrator, who controls the account. We will help them fulfil it. Where we are the controller — billing and account records — write to support@mailora.io. We respond within 30 days and do not charge for reasonable requests.

Portability is built in, not a favour

Mailora speaks standard IMAP, so any mail client can download a complete copy of a mailbox at any time, without asking us. Leaving is a technical operation you can perform yourself.

Customers in the EEA or UK may have additional rights under the GDPR, including the right to complain to a supervisory authority. We will enter into a data processing agreement with any customer who needs one — ask us.

11 Children

Mailora is a business service and is not directed at children. We do not knowingly create accounts for anyone under 16. If we learn that we hold a child's personal data without a proper basis, we will delete it.

12 Changes to this policy

If we change this policy we will update the date at the top. For changes that materially reduce your privacy — a new category of data, a new sub-processor handling mail content, a longer retention period — we will notify account administrators by email at least 30 days before the change takes effect, so you have time to object or leave.

13 Contact

Privacy questions, data requests and complaints:

  • Email — support@mailora.io
  • Post — Tower of Aakash, Level 18, 54 Gulshan Avenue, Dhaka 1212, Bangladesh

If you are not satisfied with our response, you may escalate to the relevant data protection authority in your country.