# recvmail policy

recvmail sells short-lived, receive-only email inboxes to AI agents, paid for one
call at a time. This page is the whole of our policy: for the services our addresses
are given to, for our customers, and for anyone asking what we keep.

## For services that receive our addresses

### What recvmail is

- **We mint every address:** 20 random characters at recvmail.net. Nobody can choose
  one, so no `support@`, `billing@` or lookalike address of ours exists.
- **Inboxes are short-lived.** An inbox lives 75 minutes unless its buyer pays to
  extend it, and most are gone within hours. Mail is deleted soon after it is read,
  and all of it when the inbox ends.
- **An address is never reissued.** Once an inbox ends, mail to its address is
  refused for good, so nobody can later receive another holder's password resets.
- **recvmail sends no mail.** recvmail.net publishes a DMARC `reject` policy, so a
  message claiming to be from it is forged.

### Blocking us is fine

Our addresses are on recvmail.net and its subdomains, and always will be: we never
add or rotate domains to get around a blocklist. If your service doesn't want
throwaway addresses, block the domain and its subdomains, or opt out (next), which
also tells our customers before they pay.

### Opting your domain out

A domain's owner can have all mail from that domain refused for every recvmail
address. We don't ask why. We only check that the request comes from whoever
controls the domain's DNS:

1. Publish a TXT record at `_recvmail.<your domain>` with the value `opt-out`.
2. Then write to abuse@admin.recvmail.net naming the domain. Publish first: a
   resolver that looked the name up before the record existed can keep its "no such
   name" answer for as long as your zone's negative-caching TTL (the SOA minimum).

We look the record up ourselves and reply once the opt-out is in place. From then on:

- mail whose `From:` domain is yours, or a subdomain of it, is refused when it is
  sent, authenticated or not, with `sender domain opted out`;
- an agent that tells us it expects mail from your domain is refused before it pays.

The record covers the domain it sits under and that domain's subdomains, never a
parent: `_recvmail.mail.example.com` opts out `mail.example.com` only. You can
delegate the name with a CNAME, as with `_dmarc`. To withdraw, delete the record and
write again; we remove the opt-out once the record is gone. We don't publish the list
of domains that have opted out.

### Reporting abuse

Write to abuse@admin.recvmail.net. Mail to abuse@ or postmaster@ at recvmail.net
itself bounces with a pointer there. Name the addresses of ours involved and when,
and send the evidence: the offending message as an attachment with its full headers,
a lure with our address in its `Reply-To:`, or an RFC 5965 report. Reports are by
mail only, and we answer from a person's own address, since recvmail.net sends none.

- **A report that names an address, with evidence, cancels that inbox.** Everything
  it holds is deleted at once, and its buyer is told it was cancelled for abuse. Until
  the end of the time that was paid for, mail to it bounces with
  `address disabled for abuse; reports: abuse@admin.recvmail.net`, so someone
  replying to a lure learns why.
- **Most inboxes have ended by the time a report arrives.** A report is still worth
  sending: it shows us the pattern, such as one buyer holding many inboxes that hear
  from you, and we look into the buyer's other inboxes too.
- **If your service is being farmed, you see the farm better than we do.** Name
  every address you know, or opt out.

We act on the evidence you send, never by reading our customers' mail.

### What we tell you, and what we don't

We tell you whether an address was ours and what we did about it. We never tell you
who paid for it or what else they hold; we act on that ourselves.

## Acceptable use

recvmail is for an agent that needs to receive mail as part of its task. These uses
are not acceptable, whoever pays and however few inboxes they take:

- **Getting around a limit a service sets per person:** accounts, trials, sign-up
  credits, votes, purchases, tickets. One timed-entry ticket to a national park for
  the person you act for is fine; every ticket for a day is not. What counts is what
  the service means to give each person once, not what its sign-up form allows.
- **Collecting mail by deception:** an inbox as the `Reply-To:` of a phishing
  message, or a drop for stolen credentials or data.
- Anything unlawful, reading inboxes you didn't buy, and ignoring `429`: a caller
  that keeps going may be blocked before it reaches the API.

An inbox used this way is cancelled, without refund and without appeal, and its
calls answer `410 inbox_cancelled`. We may refuse future service to whoever paid for
it.

We never cancel an inbox for how much mail it receives or how long it is kept. Heavy
use we didn't expect is not abuse.

## What we see and keep

### Your mail

We don't read it. The operator of the service has the access any host has, and
never uses it to look at mail. A message is deleted 5 minutes after you download it,
1 hour after a poll first lists it if you never do, and in any case about 20 minutes
after the inbox ends. We keep no copy and no backup: deleted is deleted.

### What we look at

- **Routinely, aggregates:** counts, sizes and timings, by sender domain and by
  paying wallet, to see that the service works and how it is used. No addresses.
- **On a case,** opened by a report or by a pattern in those aggregates, one inbox's
  metadata: its lifetime and counts, its sender allowlist and rejections, and for
  each message the envelope sender, the `From:` address, size, time and
  authentication result. Every such look is recorded before anything is shown.
- **Never subjects or content,** on a case or otherwise. For the mail this service
  exists for, the subject is often the secret ("482913 is your code").

### What we keep, and for how long

Each period is the most we keep it. We may shorten one, and we lengthen one only by
changing this page first.

| What | Kept at most |
|---|---|
| Message content | 5 minutes after download, 1 hour after a poll first lists it, or until about 20 minutes after the inbox ends |
| An inbox's record: its id, lifetime, quota, counts, and a keyed hash of the wallet that paid | 13 months after the inbox ends |
| What each wallet paid for each inbox: how many calls, their sum, the first and last | 13 months after the inbox ends |
| Each payment's own record, with its transaction | 1 day, then added into the line above; one that never completed, 13 months after the payment |
| An abuse case: each look and cancel, who took it and why, and the inbox's record | 3 years after the inbox ends or the case's last action, whichever is later |
| A domain's opt-out, and how it was verified | until withdrawn |
| Reports mailed to us | until handled, 30 days at most |
| Error logs, which can name a delivery's sender and recipient | 7 days |
| Sampled request traces: ids, a delivery's sender and recipient, an API caller's approximate location, network and user agent | 7 days |
| Usage metrics: inbox ids, counts, sizes, timings, sender domains; no sender addresses | 3 months |
| The delivery log of the provider that receives our mail: sender, recipient, subject, result | 31 days, kept by the provider; we can't shorten it, and don't use it to look at mail |

Payments settle on a public blockchain, where the transaction and the paying wallet
are public and permanent, outside anything we can delete.

This list is everything we keep. If a legal obligation requires us to preserve a
particular record, we keep that record until the obligation ends; content, once
deleted, cannot be recovered.

## Terms

These terms apply to every paid call. Making one accepts them, for you and for
whoever you act for.

- **What you buy.** A paid call buys what its route says and nothing else: provision
  buys an inbox for 75 minutes with a 100 MiB quota, and extend adds 75 more
  minutes. The price is in the payment challenge before you pay, and nothing is
  charged afterwards. There is no account and no subscription.
- **Payments are final.** They are not refunded: not for an inbox that received
  nothing, one cancelled under the acceptable-use rules, or one a site wouldn't take. A
  retry with the same `Idempotency-Key` is never charged twice.
- **As is.** We work to deliver every message, but we don't promise that any message
  arrives, that any site accepts our addresses, or that the service is available at
  a given time. Don't use an inbox for an account you will need to recover by email.
- **Liability.** As far as the law allows, our liability for anything to do with an
  inbox is limited to what was paid for it.
- **Cancellation.** We cancel an inbox only for use against the acceptable-use rules.
- **Changes.** We may change these terms and our prices. A change applies to calls
  paid after it is published here, never to one already paid.

## Security

Report a vulnerability to security@admin.recvmail.net (also in
`/.well-known/security.txt`). Test against inboxes you bought, never anyone else's.
