Privacy Policy
Effective date: 2026-07-25
Data controller: ozpr s.r.o., IČO 08002461, registered seat Malířská 377/11, Bubeneč, 170 00 Praha 7, Czech Republic (Commercial Register of the Municipal Court in Prague, file no. C 311037). Reach us at support@sojka.email.
What we store, and why
- Account — your Apple user identifier and, if you shared it at sign-in, your email address. Needed to operate your account (legal basis: contract).
- Monitored domains — the domain names you add, their DNS observations, blocklist status, and health history. This is the product (contract).
- DMARC aggregate reports — standardized XML reports that mail receivers (Google, Microsoft, and others) send for your domains once you point your DMARC record at Sojka. They contain sending-server IP addresses and message counts — not message content, subjects, or recipient addresses (contract).
- Test-email checks — if you use the guided source check, the message you send to your one-time check address is analyzed for authentication results and then retained for at most 30 days before automatic deletion (contract).
- Push tokens — your device's APNs token, to deliver notifications you enabled (contract).
- Public checker log — for every free check, including repeat views of a stored result: the domain checked, the visitor's IP address, the result, and the time. Kept for rate limiting, result caching, and understanding how the checker is used (legitimate interest). Not linked to any account.
- Checker email addresses — if you give an email address to raise your free-check allowance, we store that address, the exact consent wording you agreed to, the time, and the IP address you agreed from (consent). Your later checks are linked to that address. Nothing has been sent to these addresses to date; anything sent will be about Sojka only, and every such email carries a one-click unsubscribe link. You can withdraw consent from that link at any time — the address stops being mailed while the record of what you agreed to, and when, is kept as the evidence that the consent existed. To have the address deleted rather than unsubscribed, write to support@sojka.email — we delete it and unlink it from the check log.
What we don't do
- No advertising, no sale of data, no sharing with data brokers.
- No third-party analytics or tracking scripts — on this website or in the app.
- No cookies on the public website beyond what forms require: a CSRF token, and a session cookie that remembers your raised check allowance if you gave an email address.
Where data lives
Data is processed on infrastructure in the European Union: a Hetzner server in Germany, and
Amazon Web Services in the eu-central-1 (Frankfurt) region for inbound mail
handling and storage. Apple processes sign-in and subscription data under Apple's own privacy
terms.
Retention and deletion
Deleting your account in the app removes your account, your domains, and the monitoring data derived from them — signals, sources, rollups, health history, DNS observations, blocklist records, source checks, share links, push tokens and API tokens — along with the parsed DMARC report data for those domains. Any pending sign-in codes for your addresses go with it, and your Sign in with Apple token is revoked at the same time.
Some things deliberately outlive that deletion. It is fairer to name them than to imply otherwise:
- Security audit entries — the record that an account existed and was deleted, carrying internal identifiers only, no name or address. A trail that the act of deletion could erase would not be a trail.
- Payment records — subscription events Apple reported, kept as accounting evidence (legal obligation). They carry Apple's own transaction identifiers; the link to your account is removed.
- Archived report emails — the raw DMARC aggregate reports that mail receivers sent us. These are the recovery source of truth for everything parsed from them, so they are retained rather than expired. They contain sending-server IP addresses and message counts, never message content.
- Public-checker logs and checker email addresses — not account data; see above for how to have an address deleted.
Test emails sent to a one-time check address are deleted from storage within 30 days, whether or not you delete your account. Public-checker log rows are kept for rate limiting and abuse prevention and are not currently expired — we would rather say that than publish a schedule we do not run. Database backups roll over on their own cycle, never longer than 30 days, so data removed from the live service can persist in a backup until that window passes; backups deliberately exclude account records, sign-in identities and the audit trail.
Your rights
Under the GDPR you can request access, correction, export, or erasure of your data, and you can object to legitimate-interest processing. Write to us via the support page. You may also lodge a complaint with your supervisory authority.
See also the terms of service, which cover the subscription and the iOS app.