BETA

Privacy Policy

Updated 30 September 2026. Scope: Commonside's public website, account panel, staff administration and mail service, including Roundcube webmail.

We aim to collect only what is needed to operate the service. We do not sell personal data or use it for advertising. This policy describes current behavior, not a promise of anonymity, zero logging or end-to-end encryption.

Information we process

Cookies and website requests

The website, panels and Roundcube use session cookies for login, form protection and service operation. Roundcube also uses scripts and browser preferences needed for webmail. Custom public pages do not use advertising or analytics trackers. Pages load their own styles and images, so they are not limited to a single document request.

Hosting, DNS, network and reverse-proxy providers, including Cloudflare on routes using it, can process connection metadata. A proxy terminating HTTPS can also process traffic passing through it. This is not a claim that every service connection is direct or invisible to providers.

Who can access information

Commonside volunteers use staff permissions to review requests and handle service issues. Private reviewer notes are kept in the admin database rather than copied into public request records. Authorized staff can access service mailboxes for their role. Privileged server operators have technical access to stored messages and server-held encryption keys; the service is not designed to make mail unreadable to its operators.

Your messages are transmitted to recipient mail systems. Those systems and the people you send to have their own retention and privacy practices. Information may also need to be disclosed when required by applicable law or to address security and abuse incidents. We do not promise that information is never shared under any circumstances.

Request receipts and registration links

A Request ID grants access to its receipt and visible discussion. Anyone with the receipt link may read that discussion or submit a follow-up. Keep it private and do not put secrets in comments. Staff can hide a public receipt. Hidden pages are not available through the public receipt route, but staff records can remain.

Registration links are secret, single-use and expire after 5 days. Session and registration tokens are stored as hashes. Recovery-code hashes are stored; a newly issued recovery code is displayed for you to save. The initial code also passes through a temporary session flash message until displayed.

Protection and its limits

Website and mail-client access use TLS. Standard mail delivery to other providers is not guaranteed to use encryption on every hop. Stored mailbox messages use Dovecot mail-crypt with server-held global keys. This is server-side message encryption, not end-to-end encryption or a claim that all disks, databases, logs and backups are encrypted.

Application, admin and mail records use separate databases and restricted service roles. Staff authentication requires a password and TOTP. These controls reduce risk but cannot guarantee that unauthorized access will never occur.

Retention and deletion

Operational data is retained for service delivery, security, support and abuse handling. We have not established a single verified deletion schedule for all request records, tickets, sessions, audit records and system logs. We do not promise automatic removal after a fixed period.

The panel's Purge data action removes live mailbox messages and aliases while keeping your account. Closing an account disables access and retains data. The panel-account removal action removes the panel record and associated panel sessions; it is not a complete deletion of the separate live mailstore. Contact Commonside volunteers for coordinated mailbox/account deletion. Username changes are temporarily unavailable.

Deleting a request does not delete an existing account. Audit records, deletion tombstones and historical backups can remain. Copies already sent to recipients cannot be removed by Commonside. No deletion action guarantees immediate erasure from every system or backup.

Backups

Local nightly database dumps use restricted file permissions. The backup job removes date-named database backup directories older than its 14-day retention threshold; manual configuration snapshots can remain longer. Database restore tests have passed, but complete off-host mailbox/key backups and a full service restore have not yet been verified. Keep your own copies of important mail.

Questions and privacy requests

Contact support@commonside.org to ask about your data, corrections, access or deletion. We may need to verify your authority before acting. Do not include account secrets.

Policy updates

The website contact form is coming soon and is not currently available. The current policy and update date are published here. Check this page for changes. We do not describe a notification mechanism as guaranteed when it has not been implemented.