Privacy

Last updated: draft placeholder

This page is maintained by the app owner. Wording will be finalized with counsel before public launch.

Message contents

Message bodies and attachments are stored only for the 24-hour retention window and are readable only through the public inbox URL or a valid BM_ token. Administrators cannot read message contents.

Tokens and secrets

BM_ tokens are shown to the address owner in full, once, and are treated as sensitive credentials thereafter. Tokens are stripped from browser URLs before rendering and redacted from application logs.

Metadata

Aggregate counts (accepted / rejected messages, active inboxes, worker health) are used for service operations and never expose message contents.