NatterBy Masons Mail

Privacy

Updated 3 October 2026

Here is how Masons Mail and public Natter use information, and the choices you have. Mailbox and Natter features are described separately below.

Masons Mail is operated by Craig Mason in Sweden. Craig Mason is the controller responsible for the personal information covered by this notice. For privacy questions or requests, email craig@masonsmail.com.

This notice covers the Masons Mail website, personal mailbox and account service, and the public Natter app and its personal services at natterapp.com. Our Imprint identifies the operator. The private Idelego Natter app, separate guest-meeting services and separately governed business API services are outside its scope.

Masons Mail account information includes your mailbox address, account identifier, password hash, account status, plan and storage usage. We use it to create your mailbox, recognise your sign-in and manage the service. An address and password are necessary to create and access an account.

A recovery email is optional. If supplied, we store it and its verification status and send verification and password-reset messages. You can use your mailbox before following the verification link. Password resets to that address become available after verification.

Display name, full name and country or region are optional profile details. You can edit or clear them in your account. Leaving them blank does not prevent ordinary mailbox use.

Mail and calendar features process message contents, attachments, event details and delivery information, such as addresses and timestamps. This includes information from you and from people who write to you or invite you to events.

Security and operational information includes IP addresses, request times, account activity and security events. We use it to protect accounts, prevent abuse and investigate faults. At Masons Mail signup, or a later successful sign-in if no estimate is saved, we also estimate your city and country from the connection IP using a local reference database. We save the approximate region and its date for account geography statistics; we do not send the IP to the database provider or collect GPS for this purpose. An estimate may be wrong, particularly on mobile networks or VPNs. It is not your confirmed home address. Support enquiries contain the information you choose to send us. Please do not send us your password.

When you use an available billing feature, we process the customer, subscription, payment-status and invoice references needed for it. Payment details entered on Stripe's pages are handled by Stripe.

We do not sell your mailbox data, build advertising profiles from it or insert advertising into your inbox. Recovery, security and other account notices are service communications. Advertising sent by someone else to your email address is outside our control.

We process information needed to provide the mailbox, account and public Natter features you request to perform our agreement with you. Optional recovery, profile, sharing and backup information is used when you choose those features. Where processing relies on consent, you can withdraw it; device permission controls also let you stop access to features such as contacts or location.

Security, abuse prevention and fault investigation serve our legitimate interests in keeping the service reliable and protecting its users. You can object to processing based on legitimate interests by contacting us. We also process information when necessary to meet an applicable legal obligation, including responding to a valid legal order.

Idelego supplies hosting and mail infrastructure used to run Masons Mail and hosts the public Natter backend. The mail infrastructure processes mailbox messages and calendar data; the account and Natter infrastructure processes the records needed for those services. Public Natter has its own app identity and service configuration, separate from the private Idelego Natter app.

Mailgun delivers Masons Mail account notification emails. It receives the destination address, notification content and delivery information for those messages. See Mailgun's privacy information.

Cloudflare Turnstile helps protect Masons Mail signup against bots. It processes technical signals, including IP address and browser connection information. Cloudflare processes these signals to provide protection and also uses them in its own role improving bot detection. See Cloudflare's Turnstile notice.

Stripe provides payment and billing-management features when you use them. It receives the information needed for the relevant customer or payment transaction. See Stripe's privacy policy.

Sending mail or sharing an invitation passes the content and necessary delivery information to the recipients and their providers. We may also disclose information when required by applicable law or a valid legal order.

The operator is based in Sweden. This is not a promise that all processing takes place in Sweden or the EU/EEA: external providers operate internationally, and messages travel to the recipients you choose.

The full details of hosting and backup locations, provider regions and international-transfer arrangements are still being confirmed. This notice does not yet provide a complete account of those arrangements. Contact craig@masonsmail.com with questions about where your information is processed.

Our website connections use HTTPS, and the mailbox account system stores password hashes. These protections do not make ordinary email end-to-end encrypted. Mail systems and their authorised operators can have technical access to stored messages; the providers used by your recipients also receive the mail you send them.

Automated security checks can prevent a signup or restrict activity. If you believe a check has stopped you incorrectly, contact us for help. Please keep your password and devices secure.

The Masons Mail account site uses a necessary sign-in cookie called mm_session. The server session expires after 30 minutes of inactivity or 12 hours in total, whichever comes first. Signing out revokes it. Session expiry does not mean every associated operational record is erased at the same moment.

We use the preferred languages sent by your browser to choose a supported website language, otherwise English. You can choose another language using the language menu. That choice is carried in the page address as you move between our pages; it is not saved in a language cookie or browser storage. Choosing “Use browser language” removes it from the page address. We do not look up your IP address or location to choose a language.

The company website and account application do not include advertising or audience-analytics trackers. Protected Masons Mail signup loads Cloudflare's Turnstile code. Separate webmail, meeting and payment applications may use their own cookies and browser storage. For information about Cloudflare and Stripe, see their provider notices above.

Masons Mail account and mailbox information is held while your account is open to provide the service. You can request deletion from account security. The confirmation shows when deletion is due and how to cancel the request during the cancellation period.

After that period, the deletion process removes the mailbox, clears direct account profile information and cancels active storage subscriptions. A failed deletion operation can take longer while it is retried.

Some account-linked mailbox records, usage history, security and financial records remain after that process. Closing an account does not immediately erase every provider copy or backup. Messages you have sent may remain with their recipients.

Retention periods for the remaining operational records, support correspondence and backups are still being confirmed. A complete schedule is not yet available in this notice. You can contact us to ask what information remains about your account and to request erasure where applicable.

Masons Mail account settings let you change your profile and recovery email, download your account records and request deletion. The account download does not include all message contents and attachments. Keep copies of mail you need through your mail app before closing the mailbox.

Under applicable data-protection law, you may request access, correction, erasure, restriction or portability of your information, and object to processing based on legitimate interests. These rights have conditions and exceptions. Where processing relies on consent, you can withdraw that consent.

Send requests to craig@masonsmail.com. We may need reasonable evidence of your identity. GDPR normally requires a response within one month; if a permitted extension is needed, we must explain it within that first month.

You can complain to Sweden's data-protection authority, Integritetsskyddsmyndigheten (IMY), or another competent supervisory authority, including where you live or work in the EU/EEA.

We date changes to this notice and will communicate material changes as required by law. For questions about your information, contact craig@masonsmail.com. Our Terms explain the arrangements for using Masons Mail and public Natter.

Natter uses your phone number for verification and account discovery. It processes account and device identifiers, public encryption keys, device credentials, push registrations, profile details and discovery choices. Number records use keyed hashes and, where needed, encrypted copies; this protects stored values but does not make them anonymous. Verification also processes request addresses, country, app/device information, outcomes and provider delivery references. Security checks may ask Google Play Integrity or Apple App Attest to confirm information about the app instance.

Personal relay messages and attachments are encrypted on devices. The server temporarily holds encrypted deliveries and media and processes the account, device, membership, block and audience relationships needed to route and authorise them. Received chat history is held on devices. Encryption does not hide every connection or routing detail from the service, and recipients can retain or share what they receive.

Personal group calls encrypt media between participating devices. Call infrastructure processes connection, participant and call-state information. These protections do not mean every business conversation, guest meeting, support enquiry or external service has the same encryption. A report or support message contains the information you choose to submit. When your phone creates a link preview, it contacts the linked website, which can receive ordinary connection information such as your IP address.

Depending on the verification method available and selected, Natter uses Telnyx for SMS or Meta's WhatsApp Business service. The provider and relevant communications networks process your number, verification message and delivery information. For an incoming method, Natter matches the message you choose to send and the sender information supplied by the provider to your verification attempt. These messages use the selected provider, separately from your encrypted Natter conversations. Carrier charges may apply to an SMS you send.

Contacts access is optional and controlled by your phone's permissions. Discovery uses phone-number information to find permitted matches; names and personal contact customisations are used on your device. Feed and Atlas location sharing use your audience choices. Location updates are encrypted for the chosen recipients; the backend also processes sharing relationships and delivery information. Turning sharing off does not erase copies a recipient has already kept. Apple or Google maps process the information needed to display their maps under their own services.

Google Firebase Cloud Messaging and Apple Push Notifications process device tokens and delivery information to alert or wake the app. Natter stores the device registrations needed for this. Personal relay chat bodies are not sent as ordinary push-notification text; notification content displayed by your device depends on the app and your privacy settings.

Chat backup is optional. On Android, Google Drive backup requests only permission to create, read, update and delete Natter's own files in your hidden Drive application-data folder (the drive.appdata scope). It does not request access to your general Drive files, Gmail or Google Contacts for this feature. Your phone uses a short-lived access token to communicate directly with Drive. This integration does not send that token, a Google identity token or a server authorisation code to Natter's servers.

On iPhone, the corresponding backup uses Natter's container in your own iCloud account. Backup contents are encrypted on your device before upload. They can include chat history, chat and app settings, contact customisations and media when you enable it. Restoring needs the password or recovery key you choose; losing it may make the backup unrecoverable. These chat backups are stored in your cloud account, not on Natter's servers. Google or Apple stores the encrypted files and processes the cloud-account and technical information needed to provide its service.

Natter uses this cloud access to create, restore and manage your backups. Turning backup off stops future backups on that device, forgets its local backup key, and requests removal of the relevant cloud files and withdrawal of Drive access. Provider or connection failures can leave files or permissions behind. You can also manage remaining app data and access with your cloud provider. Deleting your Natter account does not guarantee deletion of cloud backups or other copies you have saved.

Deleting your Natter account revokes the account and its devices, removes its profile and relevant account relationships and registrations, and starts clearing app data on the requesting phone. Copies saved to a gallery, cloud backups and copies already received by other people may remain. Closing a Masons Mail mailbox does not close a separate Natter account. If you cannot use account deletion in the app, contact us for help; we need to establish ownership before acting.

Undelivered encrypted relay envelopes expire within 30 days, and acknowledged deliveries are removed from the delivery queue. Temporary media can be removed earlier under storage limits. Registration attempts and consumer verification-send records are scheduled for removal after 30 days. Ended direct relay call records are scheduled for removal after 24 hours. These are operational cleanup rules, not a promise that every log, provider copy or backup disappears at the same time.

Revoked account/device identifiers and some security or relationship records can remain. Bindings between a deleted account and its phone-number hash become eligible for removal after 90 days unless another person's block still refers to them. Keeping those blocks protects that person's choice. Retired Atlas device-sharing rows are scheduled for removal after seven days; other sharing records have their own expiry or remain while needed for an active sharing relationship. The outstanding retention and processing-location details described above also apply to public Natter.