Skip to content
Mailicity
Sign in Request access
Mailicity / How we treat your privacy / Privacy Policy

Legal · Australian Privacy Principles

Mailicity Privacy Policy

Effective date: 9 June 2026 · Last updated: 9 June 2026

This is the formal, legally binding policy. For a plain-English explanation of how we treat your privacy, see How we treat your privacy.

1. Who we are and what this policy covers

Mailicity is a product of Syriant Pty Ltd (ABN 52 881 624 363), a company registered in Queensland, Australia (“Mailicity”, “we”, “us”, “our”). Our registered address is Level 13, 50 Cavill Ave, Surfers Paradise QLD 4217.

Mailicity is an email service that connects to a person's existing email account and shows them a calm, curated inbox on a tablet, while a family member or carer manages who can reach them. This policy explains what personal information we collect, why, how long we keep it, who we share it with, and the choices you have.

We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Mailicity is offered to Australian residents only; we do not offer the service to residents of the European Union or European Economic Area.

2. The two people this policy is about

Mailicity involves two distinct roles, and we treat their information differently.

The account holder is the family member or carer who sets up and manages the account. They create a login, connect the protected person's mailbox, choose who is allowed to reach them, and review anything from someone new. This policy refers to this person as “you”.

The protected person is the older or vulnerable adult whose inbox Mailicity looks after. They do not have a login. Their tablet is paired once and then simply works. We refer to this person as “the person you look after”. Information about them is described in §3.2 and §3.3, and §9 sets out the basis on which an account holder may act for them.

3. What we collect, and why

3.1 Information about you, the account holder

When you create and use an account, we collect:

  • Your name, email address, and (if you provide it) phone number.
  • A securely hashed version of your password. We never store your password itself.
  • If you choose to sign in with Google, the account identifier Google provides. We do not receive your Google password.
  • Records of the actions you take in the app, such as approving a sender or changing a setting, kept in an audit log so that families who share an account can see who did what.
  • Basic technical information when you use the admin app, such as device and browser details and your IP address, used for security and to keep the service working.

We use this to give you an account, let you manage the service, keep the account secure, and contact you about the service.

3.2 Information about the person you look after

To set the service up, you give us:

  • Their name or how you refer to them, and optionally their date of birth.
  • The contacts you approve for them: each contact's name, email address, relationship, and optionally a photo you upload.
  • Any private notes you add for your own reference, which are never shown on the person's tablet.

3.3 Their email account and its contents

With your authorisation, we connect to the person's existing email account (for example Gmail, iCloud, Outlook, or another IMAP provider) using the credentials you supply. We store those credentials in encrypted form so we can keep the connection working. We do not store your or their provider password in readable form.

Once connected, in order to show a curated inbox and let you review senders, we handle the email in their mailbox. Specifically:

  • We read and keep limited details about each message: who it is from, who it is to, the subject, the date, whether it has attachments, and a short preview of the text (about the first 500 characters).
  • When a message is opened, we fetch its full text from their real mailbox and keep a temporary copy so it loads quickly.
  • For attachments, we keep only their details (file name, type, and size). We fetch the file itself from their mailbox when it is needed (sometimes shortly after a message arrives, so it is ready to open) and may keep a cached copy so it opens quickly.

How long each of these is kept is set out in §5.

We do not read any of this content for advertising, we do not sell it, and we do not use it to train any model or product.

4. How we use information

We use the information above to:

  • Provide the service: connect the mailbox, show a curated inbox, let you approve or hold senders, and let the person read and reply.
  • Keep the account secure and detect misuse.
  • Let multiple family members share an account, with an audit log of who did what.
  • Send you service messages by email, such as a notification that something is waiting for your review, an account or security alert, or a message about a problem with the mailbox connection.
  • Meet our legal obligations.

We do not use it for advertising, we do not sell personal information, and we do not use the contents of anyone's mail to train models.

5. What we keep, and for how long

We keep only what we need, for as long as we need it.

  • Account information (your name, email, login) is kept while your account is open.
  • Mailbox connection credentials are kept, encrypted, while the mailbox is connected, and are deleted when you disconnect it or close the account.
  • Message details (sender, recipients, subject, date, attachment flag, and the short preview) are kept for as long as the account is open, so we can show the inbox list.
  • Full message text that we fetch when a message is opened is kept as a temporary copy for up to 7 days, then deleted automatically.
  • Attachments: we keep only their details (file name, type, and size). The file itself is fetched from the real mailbox and may be cached so it opens quickly; any cached copy is deleted when the account is closed.
  • Audit records are kept for up to 12 months, then deleted automatically. Moderation records (what was approved or held, and why) are kept for the life of the account.

When you close an account, we permanently delete the personal information we hold within 30 days, except anything we are required by law to keep for longer, which we will hold only as long as that law requires.

6. Who we share information with

We do not sell personal information and we do not share it for anyone else's marketing.

We use a small number of trusted service providers to run Mailicity. They may handle personal information only to provide their service to us, under contract.

  • Amazon Web Services: region us-west-2 (United States). Used for (a) sending service emails to you via Amazon SES, including handling delivery failures, and (b) Amazon S3 storage of cached message images and cached attachment files, kept so the inbox loads quickly.
  • Railway: application and database hosting, region US West (United States).
  • Sentry: error monitoring, configured not to capture message content, credentials, or other sensitive data.
  • PostHog: privacy-friendly product analytics (United States), used only with your consent to understand how the product is used. Configured with no session recording and, in the admin app, no automatic capture of on-screen content.
  • Google: only if you choose to sign in with Google.

We may also disclose information if required by law, to protect the safety of a person, or in connection with a sale or restructure of the business, in which case this policy continues to apply.

7. Where information is stored

Some of our service providers store information in the United States (see §6). When personal information is handled overseas, we take reasonable steps to see that it is protected in line with Australian privacy law. Mailicity is offered to Australian residents only.

8. How we protect information

We take security seriously, because the whole point of Mailicity is to be the safe option.

  • Mailbox credentials are encrypted at rest.
  • Account passwords are stored only as secure hashes, never in readable form.
  • Access to systems is limited and logged.
  • We design the product so message content is not kept longer than needed and is never used for advertising or training.

No service can promise perfect security, but we work to protect information using measures appropriate to how sensitive it is.

9. The person you look after, and your authority to act

Mailicity is set up by an account holder on behalf of another adult. When you set up an account and connect someone's mailbox, you confirm that you are entitled to do so, for example because you are helping a family member with their agreement, or because you act for them under a power of attorney, guardianship, or similar arrangement.

The person you look after keeps their dignity and their own email address. They can read and reply to the people you have approved. We collect information about them only to provide the service to them and to you.

10. Your privacy rights

Under the Australian Privacy Principles you can:

  • Ask what personal information we hold about you and request a copy.
  • Ask us to correct information that is wrong or out of date.
  • Ask us to delete information, subject to any legal requirement to keep it.
  • Make a complaint (see §14).

To make a request, contact us at privacy@mailicity.com. We will respond within a reasonable time and within any period the law requires.

11. Children

Mailicity is not directed at children and is not intended for anyone under 18 to set up or use. We do not knowingly collect information from children.

12. Service and marketing messages

We will send you messages needed to run the service, such as review notifications, security alerts, and account messages.

If we ever send you marketing messages, we will do so in line with the Spam Act 2003 (Cth): we will identify ourselves, only send them where we are permitted to, and include a working way to unsubscribe. You can opt out of marketing at any time without affecting the service messages you need.

13. Cookies and analytics

We use a privacy-friendly product analytics tool, PostHog, on our website and admin app to understand how Mailicity is used so we can improve it. Analytics only begin once you accept them on the consent banner. Until then nothing is collected and no analytics cookies are set. You can decline, and we'll respect that.

We've configured analytics conservatively: no session recording, and in the admin app no automatic capture of on-screen content, so the personal information shown there (contacts, message details) is not sent to analytics. We do not sell analytics data, use it for advertising, or use it to train models. PostHog stores this data in the United States (see §6 and §7).

Apart from analytics, the admin app uses only the cookies and stored tokens essential to keep you signed in securely. Our website also loads web fonts from Google Fonts, which means your browser makes a request to Google to fetch those fonts.

14. Complaints and contact

If you have a question or a concern about how we handle personal information, contact us first at privacy@mailicity.com and we will work to put it right.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

15. Changes to this policy

If we change this policy, we will update the date at the top and, where the change is significant, let account holders know. Continuing to use Mailicity after a change means the updated policy applies.

Mailicity

built with care, in someone's spare room

© 2026 mailicity.com by Syriant

Mailicity uses a few cookies to keep the site working and to understand how it's used. We don't use them for advertising, and we never sell your data. You can read more in our privacy policy.