Coldfeet
Last updated: 1 January 2026

Privacy policy

This policy explains what Coldfeet does with personal data. Because the platform is self-hosted, the operator of this installation is the controller for mail processed through it, and this policy describes how the software handles that data on their behalf.

What is processed

Mail content and headers, including sender and recipient addresses, subject lines, attachments and authentication results, are processed to determine whether a message is safe to deliver.

Account data — name, email address, role, tenant membership and authentication factors — is processed to provide access to the console.

Technical data such as connecting IP addresses, timestamps and delivery outcomes is processed to operate the mail flow and to investigate abuse.

Why it is processed

To provide the service: filtering, delivering, quarantining and tracing mail, and giving administrators the evidence they need to act on it.

To secure the service: detecting attacks, rate-limiting abuse, and maintaining an audit trail of administrative action.

To meet legal obligations, including responding to lawful requests and retaining records where the law requires it.

How long it is kept

Retention is configured by the operator of this installation. Message bodies, quarantined mail, archived mail and audit records each have their own retention period, and data is deleted automatically once it expires.

Deleting a tenant removes its mail, accounts and configuration. Backups age out on their own schedule, which the operator sets.

Who it is shared with

Mail is transmitted to the destination you configure, and where you have configured a relay provider, to that provider. No message content is sent anywhere else.

Where the operator has enabled external reputation or threat-intelligence lookups, those services receive indicators such as URLs and file hashes rather than message content.

Cookies

The console sets cookies that are strictly necessary to sign you in and to keep that session secure. Without them there is no way to stay signed in, so they are set whether or not you accept anything else.

These public marketing pages set one further cookie, and only after you have answered the notice: a record of that answer, so we can stop asking. It holds nothing but "accepted" or "declined", it is first-party, and it expires after a year.

There are no advertising or cross-site tracking cookies on this site, and no personal data is sold or shared with advertisers. If the operator of this installation later enables usage analytics on the marketing pages, it will only load once you have accepted.

Your rights

Depending on where you are, you may have the right to access, correct, export or delete personal data held about you, and to object to its processing.

Requests should go to the operator of this installation, who controls the data. Export and deletion are available directly in the console for administrators.

Security

Data is encrypted in transit and at rest, access is role-scoped and second-factored, and administrative action is recorded in a tamper-evident audit log. The security page describes this in more detail.