Skip to main content
Onyx Mail
  • About
  • Security
  • Verify
  • Contact

Privacy Policy

Effective: July 20, 2026

Version 3.0

Registry

  1. Scope
  2. Data processed
  3. Uses of data
  4. Cookies and client storage
  5. Third parties and external resources
  6. Tor access
  7. Contact communications
  8. Retention and deletion
  9. Legal requests
  10. Security and limitations
  11. Requests concerning personal data
  12. Policy changes
  13. Contact

1. Scope

This Privacy Policy applies to Onyx Mail, reached through onyxmail.net and its published Tor v3 address. It covers the informational pages, public verification artifacts, the warrant canary, the PGP keys, and the contact information published by Onyx Mail.

Onyx Mail does not operate user accounts or mailboxes, so it processes no mailbox content, message body, or account profile. This Policy describes the data practices of the material Onyx Mail publishes and serves.

2. Data processed

2.1 Request records

The application processes technical request data required to receive and respond to HTTP requests. Depending on the network path and proxy configuration, this can include a request identifier, route, method, status code, timing category, user-agent category, proxy trace identifier, and network address used for rate limiting or operational security.

The structured application logger is designed not to record request bodies, full URLs, cookies, referrers, or raw user-agent strings in its standard access event. Upstream infrastructure may process additional connection data required to deliver the request.

2.2 Public artifact requests

Requests for a PGP key, warrant canary, Tor address, sitemap, or other public artifact are ordinary HTTP requests and are subject to the same operational processing.

2.3 Information not requested by Onyx Mail

Onyx Mail presents no account-registration form, payment form, mailbox interface, or message-submission form. It does not ask for a legal name, postal address, payment credential, contact list, or mailbox content.

3. Uses of data

Operational request data may be used to:

  • Deliver the requested page or artifact.
  • Apply request-rate controls and reject abusive traffic.
  • Diagnose faults and measure application health.
  • Investigate security events affecting the site or signing artifacts.
  • Comply with an applicable legal obligation.

Onyx Mail does not use request data to build advertising profiles or behavioral marketing segments.

4. Cookies and client storage

The pages do not require an account session, analytics cookie, advertising cookie, or local-storage profile. The current client script implements navigation, copy feedback, disclosures, canary status refresh, and optional motion.

A browser, network intermediary, or added feature may introduce storage outside the scope of this statement. Material changes will require an update to this Policy.

5. Third parties and external resources

Onyx Mail loads its stylesheet, script, fonts, and images from the same origin. It does not load an analytics library, advertising pixel, externally hosted font, or third-party runtime script.

A User who follows an external link leaves Onyx Mail and becomes subject to the destination's terms and privacy practices. Public verification commands can also contact key servers or other endpoints selected by the User.

6. Tor access

Onyx Mail runs a Tor v3 service. The address is included in server-rendered HTML so it remains available when JavaScript is disabled.

Tor changes the network path and can reduce information exposed to the clearnet origin. It does not guarantee anonymity against every adversary, a compromised endpoint, browser misconfiguration, correlation attack, or information voluntarily disclosed by the User.

7. Contact communications

The Contact page publishes an email address. Sending email is a separate action performed through the sender's mail provider, network, and software. The message, sender address, headers, and attachments may be processed and retained by those systems and by the receiving mail system.

Users should not send passwords, private keys, recovery secrets, or unnecessary personal data. PGP may protect message content when correctly configured. It does not conceal all mail metadata.

8. Retention and deletion

Application-log retention is controlled by deployment configuration. The current logging package defines a 14-day default for its retention setting. Upstream proxy, operating-system, security, or mail logs may have separate controls.

Onyx Mail does not state a universal retention period for every infrastructure layer because those layers are not represented by one application setting. A data request should identify the relevant communication, approximate time, and request identifier when available.

9. Legal requests

Onyx Mail may disclose data that it possesses when required by applicable law. Onyx Mail is built to minimize the categories of data it solicits. Minimization does not prevent disclosure of data that exists.

The warrant canary is a separate, periodic signed statement. Its current claims are contained only in the signed text. This Policy does not expand those claims.

10. Security and limitations

Onyx Mail applies controls documented in the Verification Registry, including a restrictive Content Security Policy, same-origin runtime assets, security response headers, a Tor endpoint, and PGP-signed transparency artifacts.

No site, transport, or cryptographic control eliminates all risk. Onyx Mail cannot protect a compromised client device, malicious extension, endpoint malware, social engineering, or every future cryptanalytic development.

11. Requests concerning personal data

A person may contact Onyx Mail to request information about personal data associated with a specific communication or request identifier. Onyx Mail may require sufficient information to identify the record and to prevent unauthorized disclosure.

Applicable law determines whether access, correction, deletion, restriction, or objection rights apply. Onyx Mail does not promise a right that applicable law does not provide.

12. Policy changes

Onyx Mail may revise this Policy when the site, logging posture, network path, or legal obligations change. The effective date and version identify the published revision.

13. Contact

Privacy questions and data requests may be sent through the contact address published by Onyx Mail. Include only the information necessary to identify and evaluate the request.

Contact Onyx Mail.

Document state

Version3.0
Effective2026-07-20
ScopeONYX MAIL
Onyx Mail

Verifiable privacy infrastructure. Inspect every claim.

Established 2022

Organization

  • About Onyx Mail
  • Security Overview
  • Privacy Policy
  • Site Terms
  • Contact

Verification

  • Verification Registry
  • Canary Signing Key
  • Contact Public Key

Security Status

  • Warrant Canary , status: Current
  • Tor Access

© 2026 Onyx Mail. All rights reserved.