Home · Pricing · Writing desk · Terms · Privacy · Cookies · Acceptable use · Sign in · Take up the pen
Privacy Policy
What Pennapost collects and why. EU-only storage in Florence and Frankfurt, no ads, no selling data, spy pixels removed and your signature stored encrypted.
Updated 1 September 2026
1. Who looks after your data
Pennapost S.r.l., Via de’ Tornabuoni 9, 50123 Firenze, Italy (P.IVA 07123450481) is the controller of the personal data described in this policy. It applies to pennapost.com, the Pennapost apps and every @pennapost.com address.
You can reach our privacy team at privacy@pennapost.com and our Data Protection Officer at dpo@pennapost.com.
2. The short version
We collect what we need to run your mailbox, and nothing more. No ads, no selling data, no tracking, and no profiles built from your mail.
Your mail is stored in Florence and Frankfurt, encrypted in transit and at rest. You can see, export or delete your data at any time.
3. What you give us
Account details: your name, your Pennapost address, a recovery email address, your password (stored only as a salted hash) and any passkeys you register.
Your signature image and letterhead choices. Your signature is stored encrypted and only added to messages you send.
Billing details on paid plans: your name, billing address, VAT number if you add one, and the plan you chose. Card details go directly to our payment processor; we see only the card type, last four digits and expiry date.
4. Your mail and contacts
We store the messages, attachments, drafts and contacts in your account, including mail you import from Gmail, Outlook or iCloud at your request.
We process this content only to provide the Service to you: to deliver, receive, store, search and back up your mail, and to filter spam and malware. Our staff do not read your mail, except where you ask us to for support or where the law requires it.
5. What we collect automatically
Delivery metadata needed to route mail, such as sender and recipient addresses, timestamps, message size and the servers a message passed through.
Security logs, such as sign-in times, IP addresses, device and browser type, used to protect your account and detect abuse. We do not use analytics or advertising trackers on pennapost.com or in our apps.
6. Seals and suspicious mail
To check the seal on incoming mail, we read the message headers and the cryptographic signature attached to them. The check uses headers only, never the content of your mail.
When we remove spy pixels from incoming mail, it happens on our servers before the message reaches you, so the sender learns nothing about when, where or whether you opened it.
7. Why we use your data, and our legal basis
To provide the Service you signed up for, including storing and delivering your mail, adding your signature and seals, and processing payments: performance of our contract with you (Article 6(1)(b) GDPR).
To keep Pennapost secure, prevent spam, fraud and abuse, and check seals on incoming mail: our legitimate interest in running a safe service (Article 6(1)(f) GDPR).
To keep invoices and accounting records and to answer lawful requests from authorities: our legal obligations (Article 6(1)(c) GDPR). We send product news only if you opt in, and you can withdraw that consent at any time (Article 6(1)(a) GDPR).
8. What we never do
We never show ads, sell or rent your personal data, or share it with advertisers or data brokers. We never use your mail for advertising or profiling.
Under the California Consumer Privacy Act, we do not “sell” or “share” personal information, and we do not use sensitive personal information beyond what is needed to provide the Service.
9. Who we share data with
We use a small number of carefully chosen processors, bound by data processing agreements: our data centre operators in Florence and Frankfurt, our payment processor, and the service that sends account emails such as password reset codes.
Mail you send naturally goes to its recipients and their providers. We may also disclose data where required by a valid legal order from an Italian or EU authority, and we will tell you unless the law forbids it. If Pennapost is ever merged or sold, your data would move only under this policy, and we would tell you first.
10. Where your data lives
Your mail and account data are stored in Florence, Italy and Frankfurt, Germany, encrypted at rest and in transit.
Our payment processor may process billing data outside the European Economic Area. Where it does, the transfer is protected by an adequacy decision or the European Commission’s Standard Contractual Clauses.
11. How long we keep it
Your mail and contacts stay until you delete them or close your account. Deleted messages remain in Trash for 30 days, then are removed; backups roll over within a further 30 days.
Security logs are kept for 90 days. Invoices and billing records are kept for 10 years, as Italian tax law requires. When you close your account, everything else is deleted within 30 days.
12. How we protect it
Encryption in transit and at rest, encrypted storage of signatures, strict access controls, two-person approval for access to production systems, and regular independent security reviews.
If a breach ever puts your data at risk, we will notify the Garante within 72 hours and tell you without undue delay, as the GDPR requires.
13. Your rights
You have the right to access, correct, export and delete your personal data, to restrict or object to how we use it, and to withdraw any consent you have given. Most of this can be done directly in Settings → Privacy.
For anything else, write to privacy@pennapost.com. We reply within one month. California residents have equivalent rights to know, delete and correct, and we will never treat you differently for using them.
You can also complain to the Garante per la protezione dei dati personali (garanteprivacy.it), or to the data protection authority where you live.
14. Children
Pennapost is not intended for anyone under 14. If we learn that a child under 14 has created an account without the consent of a parent or guardian, we will close it and delete the data. Parents can contact privacy@pennapost.com.
15. Changes to this policy
We will update this policy when our practices or the law change. If a change is material, we will email you at least 30 days before it takes effect. The date at the top always shows the current version.
Pennapost S.r.l. · Via de’ Tornabuoni 9, 50123 Firenze, Italy · help@pennapost.com