Skip to content
EMAPKA beta

Transparency

A privacy promise is only worth what the person making it is willing to say about their own weak points. Here are ours.

What we cannot do, even if asked#

What we can see#

What the server stores, and for how long#

WhatHow longNote
A sealed parcel waiting for its addresseeUntil it is collectedDeleted the moment the addressee confirms receipt
A parcel that nobody collected14 days by defaultThen deleted automatically
A file in transitUntil collected, within a fixed storage quotaEncrypted; the server cannot open it
Access records of the web serverA short periodOrdinary operational records

Where it runs#

Development, hosting and distribution are inside the European Union. The server used for the beta stands in Helsinki, Finland.

Known weak points#

These are true today. They are written here so that nobody has to discover them the hard way.

Reporting a vulnerability#

If you have found a weakness, write to security@emapka.app and tell us what you found. Give us time to fix it before making it public. We will not take legal action against anyone who reports a problem in good faith and does not damage other people's data while doing so.

Page updated: