CofferBack to home

Last updated 7 September 2026

Privacy Policy

This policy explains what Coffer does with personal data - for the people who sign in and work in a workspace, and for the people whose mail ends up in one. It covers the pages we run ourselves. Coffer is in private preview; every sentence here describes what the product does today, not what it might do later.

Who is responsible

The controller is Marcin Frątczak, ul. Warszawska 40/2A, 40-008 Katowice, Poland. Write to [email protected] about anything in this document.

For the mail synced into a workspace - the messages, the addresses on them, the names of the people who wrote - the workspace owner is the controller and Coffer is their processor. We act on the owner's instructions: sync what they connect, show it to the members they invite, send what they tell us to send.

What we collect from workspace members

Signing in creates an account tied to your Google account or to your e-mail address.

  • your e-mail address and display name, as your sign-in provider gives them to us, and the account identifier it issues
  • the workspace you belong to, your role in it (owner or agent) and the colour and initials shown on your avatar
  • what you do in the inbox: assignments, tags, internal notes, replies you send, conversations you close - each with your name and a time, so the team can see who did what
  • a session cookie so you stay signed in for five days

The legal basis is performance of the contract between us (Art. 6(1)(b) GDPR) - without this there is no account and no workspace.

Access requests and invitations

Asking for access on our site, or signing in before your team has a place, stores your e-mail address, the note you wrote if any, the time and how many times you asked. We keep it so we can write back when there is room, and so the same address does not appear on the list twice.

Inviting someone to a workspace stores their e-mail address, who invited them and when the invitation expires (seven days). The link in the invitation is stored only as a hash - a copy of our database does not contain a usable link.

Both rest on our legitimate interest in running a preview that lets teams in one at a time (Art. 6(1)(f)). An address on the access list receives one confirmation and, when its turn comes, one invitation - nothing else.

Connected mailboxes

A workspace owner connects a mailbox by giving us the address, the server names and the user name and password for reading and, optionally, for sending. The passwords are encrypted at rest with a key that exists only on our servers, never in the database itself, and they are never shown again in the panel - not even to the person who typed them.

From a connected mailbox we sync incoming messages, and the Sent folder if the owner asks for it: the addresses and names on the message, the subject, the date, the text and HTML of the body, and the attachments: their names, types and sizes, and the files themselves. Files are kept in object storage in the European Union, separately from the database, and a file larger than 25 MB is not kept at all - the thread keeps its name, not the file.

We use the credentials for exactly two things: reading new mail into the workspace, and sending the replies a member writes, from that mailbox, with a copy in its Sent folder. Nobody at the operator reads a workspace's mail unless the owner asks for support on a specific conversation, and then only that conversation.

Disconnecting a mailbox deletes its credentials and every message synced from it.

People whose mail is in a workspace

If you wrote to a company that uses ${PRODUCT}, your message and your address are in that company's workspace. The company is the controller for that data; we hold it on their behalf and under their instructions. Questions about a particular message go to the company you wrote to - they can delete it, and we help them do so.

We never contact those people ourselves, never use their addresses for anything of our own, and never train models on anyone's mail.

Cookies and browser storage

  • is_session - your sign-in session, five days. Verified on every request to the panel.
  • is_access - remembers that this browser has the preview password, so you are not asked for it on every page. Set only during the private preview.
  • your e-mail address in the browser's local storage, between asking for a sign-in link and clicking it - the link itself does not carry the address, and finishing the sign-in needs it. Removed once you are in.

All of these are strictly necessary for what they do, so they are set without a consent banner. We set no analytics cookies and no advertising cookies, and we run no ad networks or session-replay tools.

E-mail we send

We send transactional mail only: sign-in links, invitations, the confirmation that you are on the access list, and notices about the service that affect your workspace. Sign-in links are rate-limited per address and per network, so asking repeatedly will not flood an inbox.

This mail goes out through Amazon Simple Email Service from an address on our own domain. We do not send newsletters, and we never e-mail a workspace's contacts on our own behalf.

Replies your team writes to its contacts do not pass through our sender at all. They are sent through the workspace's own mail server, from the workspace's own address, using the credentials the owner gave us for that purpose.

Billing

Billing is not open during the private preview and no payment data is collected. When it opens, this section will name the payment provider and what it receives, and workspace owners will be told by e-mail before anything is charged.

Who else processes the data

We use these providers, and no others:

  • Prisma Data, Inc. - managed Postgres database (EU region)
  • Google Ireland Ltd. - Firebase Authentication, sign-in only
  • Amazon Web Services EMEA SARL - Simple Email Service, transactional mail (eu-central-1)
  • Hetzner Online GmbH - application hosting, Germany
  • Cloudflare, Inc. - DNS and CDN in front of the application

Google may process sign-in data in the United States under the EU-US Data Privacy Framework. Everything else stays in the EU.

How long we keep it

  • synced mail - until the owner disconnects the mailbox, deletes the conversation, or asks us to delete the workspace
  • member accounts and activity - until the workspace is deleted; a member removed from a workspace stays in its history as the name on past actions
  • access requests - until handled, and for twelve months afterwards so a declined address is not re-invited by mistake
  • invitations - seven days, or until accepted or revoked
  • sessions - five days

Deleting a workspace is done by hand on request during the preview, within a few days of your writing to us.

Your rights

You may request access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest.

Write to [email protected]. If you believe we have handled your data badly you can complain to the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.

Security

Traffic runs over TLS. Mailbox passwords are encrypted at rest with a key held outside the database. Invitation links are stored as hashes. Sign-in sessions are httpOnly cookies verified on every request. Every page and every action in the panel checks the session before touching data, and a workspace is addressed from the session, never from the address bar. Service credentials are least-privilege and never committed to source control.

This is a small product run by one person. We do not claim certifications we do not hold.

Changes

If this policy changes materially, workspace owners are notified by e-mail before it takes effect. The date at the top always reflects the current version.

Questions: [email protected]