Privacy Policy

Effective date: 2026-07-25

Data controller: ozpr s.r.o., IČO 08002461, registered seat Malířská 377/11, Bubeneč, 170 00 Praha 7, Czech Republic (Commercial Register of the Municipal Court in Prague, file no. C 311037). Reach us at support@sojka.email.

What we store, and why

What we don't do

Where data lives

Data is processed on infrastructure in the European Union: a Hetzner server in Germany, and Amazon Web Services in the eu-central-1 (Frankfurt) region for inbound mail handling and storage. Apple processes sign-in and subscription data under Apple's own privacy terms.

Retention and deletion

Deleting your account in the app removes your account, your domains, and the monitoring data derived from them — signals, sources, rollups, health history, DNS observations, blocklist records, source checks, share links, push tokens and API tokens — along with the parsed DMARC report data for those domains. Any pending sign-in codes for your addresses go with it, and your Sign in with Apple token is revoked at the same time.

Some things deliberately outlive that deletion. It is fairer to name them than to imply otherwise:

Test emails sent to a one-time check address are deleted from storage within 30 days, whether or not you delete your account. Public-checker log rows are kept for rate limiting and abuse prevention and are not currently expired — we would rather say that than publish a schedule we do not run. Database backups roll over on their own cycle, never longer than 30 days, so data removed from the live service can persist in a backup until that window passes; backups deliberately exclude account records, sign-in identities and the audit trail.

Your rights

Under the GDPR you can request access, correction, export, or erasure of your data, and you can object to legitimate-interest processing. Write to us via the support page. You may also lodge a complaint with your supervisory authority.

See also the terms of service, which cover the subscription and the iOS app.