Privacy policy
Version 7 · last updated October 7, 2026
nerdbox is built to keep as little as possible. This page says what is processed, why, for how long, and with whom. The durations are those the service actually applies.
Controller
Robin Meyssonnier EI, Prades-le-Lez (Hérault, France), SIREN 828 494 062. Contact for anything about your data: [email protected].
Data processed and how long it is kept
The table below lists every piece of data, from the moment it arrives until it is deleted. People who write to a nerdbox address are concerned too: what they send is processed as described here.
| Data | Purpose | Kept | Where |
|---|---|---|---|
| Account at Auth0: email, password (hashed, at Auth0 only), name and picture of a Google or GitHub account, verification status, sign-in dates, IP address of the last sign-in | Signing you in | As long as the account exists | Okta (Auth0), European region |
| Account at nerdbox: Auth0 identifier, email, verification status, dates of creation, last activity, email verification, first address and first code received, first use of the extension and of notifications, version and date of the accepted terms, chosen language, whether the newsletter was offered | Tying your addresses to you | As long as the account exists | Our server, France |
| Your addresses: address, label you gave it, creation and expiry dates | Receiving mail | 24 hours, 7 days at most if you extend it, then deleted 1 hour after expiry; at once if you delete it | Our server, France |
| Mail received: full content, attachments | Showing you your mail | Until the address expires, then deleted 1 hour later at most; at once if you delete it | Our server, France |
| Notification subscriptions of your devices: the address of the browser’s push service for the device, its encryption keys, the “Hide the content” setting, the date | Notifying you of new mail on the devices you chose | Until you turn notifications off on the device or sign out of it, or the push service ends the subscription | Our server, France |
| Chrome extension, in your browser: the key that keeps it signed in, and the last code or link received by each address | Staying signed in, showing the code in the extension | Until the browser is closed or you sign out of the extension | Your browser |
| Share links of your addresses: creation and expiry dates, and a fingerprint (SHA-256) of the link’s key; never the key itself | Letting the people you choose read an address | Until the link expires or you revoke it, and at the latest until the address expires | Our server, France |
| Mail details: sender, recipients, subject, first 200 characters of the text, size, names of the attachments, and the verification code or confirmation link found in it | The list of your mail, and the code ready to copy | Until the address expires, then deleted 1 hour later at most; at once if you delete it | Our server, France |
| Identification data: for each action on an address (creation, extension, label, share created or revoked, deletion of an address or a mail), its nature, its date, the address created, the account’s identifier and the connection’s IP address; for each mail received, its internal identifier, its receiving address (internal identifier) and its date, without sender, IP address nor content; for the account, its Auth0 identifier and the email addresses it has had | Legal obligation of hosting providers (décret n° 2021-1362); disclosed only to the authorities that request it | 1 year from each action; for the account, until it is closed, then 1 year for the identifier and 5 years for the email addresses. Not erased by deleting an address or the account | Our server, France, in a separate database, never shown by the service |
| Database backups: the account data, mail details, reports and identification data above, as they were at backup time | Recovering from an incident | 30 days at most (the 10 latest) | Our server, France |
| Server logs: IP address, requested page, date; addresses at reception and expiry. Never the content of mail. | Security, troubleshooting | 30 days at most | Our server, France |
| Reception queue: recipient address, size and identifiers of each mail received | Passing each mail on for processing | Deleted once processed and 24 hours old; those of mail that failed processing, after 8 days | Our server, France |
| Reception records: sender, recipient, subject of each mail | Mail reception (Cloudflare Email Routing) | 31 days | Cloudflare |
| Relay logs: recipient, size, accepted or refused | Mail reception | 3 days | Cloudflare |
| Account emails sent for Auth0 (email verification, new password): your email, the message and its sending log; their opening and the clicks on their links, measured by Brevo (a tracking image, and links that go through Brevo before their destination) | Sending you your account’s emails, and knowing whether they arrive and are opened (deliverability) | 30 days | Brevo, France and Belgium |
| Consents to nerdbox’s emails: email, list, state (asked, confirmed, withdrawn), dates, and for each change the source, the version and language of the text shown and the IP address of the request | Sending these emails only to those who asked, and proving it (consent) | 3 years after the last contact or the withdrawal; 30 days for a request never confirmed; deleted with the account | Our server, France |
| At Brevo, for those who subscribed: email, language, lists, the facts of use listed under “nerdbox’s emails”, the emails sent, their opening and the clicks on their links | Sending nerdbox’s emails, and knowing which are read (consent) | Until you unsubscribe, then the proof, 3 years at most; erased when the account is deleted | Brevo, France and Belgium |
| Messages waiting for n8n or Auth0: the events of nerdbox’s emails above, the abuse reports, the identifier of a deleted account | Passing them on without losing any, even when n8n or Auth0 is unavailable | Until delivered, then 7 days | Our server, France |
| Sign-in logs | Security of sign-in | 1 day | Okta (Auth0) |
| Reports: reported address, kind, explanation, your name and email if you give them. Your IP address is not kept. | Handling the report (DSA) | Until the decision, then 1 year | Our server, France |
| Moderation decisions: measure, ground, facts, address and account concerned, reports answered, date; blocked addresses | Stating and keeping each decision, showing it to the account concerned and to the author of the report (Digital Services Act, arts. 16 and 17) | As long as the measure lasts, then 1 year (1 year from the decision when it imposes nothing); a blocked address, as long as the block | Our server, France |
| Rate counters: account identifier; IP address on the report form and on the newsletter form | Preventing abuse | One hour at most; a day for the data export | Our server, France |
Purposes and legal bases
- Contract (GDPR art. 6(1)(b)): your account, your addresses and the mail they receive, the acceptance of the terms.
- Legitimate interest (art. 6(1)(f)): the security of the service (logs, rate limits), backups, and the processing of the mail’s senders, needed to show you what they sent.
- Consent (art. 6(1)(a)): nerdbox’s emails (news, tips, the developer offer’s waiting list), only if you asked for them; you can withdraw it at any time.
- Legal obligation (art. 6(1)(c)): handling reports and moderation decisions (Digital Services Act, arts. 16 and 17), keeping the identification data the law requires of hosting providers (French LCEN, art. 6, and décret n° 2021-1362), and answering requests from authorities.
There is no advertising, no audience measurement on the site and no automated decision. Only if you subscribe to nerdbox’s emails, a few facts about your use of the service, listed below, choose which emails you get.
Recipients and processors
Your data is read by no one but you, the people to whom you give a share link of an address (that address’s mail only), and, when needed for the service or a report, the publisher. The identification data is disclosed only to the judicial or administrative authorities that lawfully request it; no screen of the service shows it, not even to the publisher. It is never sold. Only if you subscribe to nerdbox’s emails does the data listed under “nerdbox’s emails” go to Brevo, which sends them; n8n, the publisher’s own automation tool on the same server, passes it on. These providers process it on our behalf:
| Provider | Role | Location | Safeguards |
|---|---|---|---|
| Hostinger International Ltd 61 Lordou Vironos str., 6023 Larnaca, Cyprus Privacy policy · Data processing agreement | Hosting of the server: all the data above stored by nerdbox | Server in France; company in Cyprus (EU) | Data processing agreement |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, USA Privacy policy · Data processing agreement | Reception of mail, tunnel, protection and delivery of the site | United States, worldwide network | Data Privacy Framework; standard contractual clauses; data processing agreement |
| Okta, Inc. (Auth0) 100 First Street, San Francisco, CA 94105, USA Privacy policy · Data processing agreement | Accounts and sign-in (Auth0) | Auth0 European region; company in the United States | Data Privacy Framework. [TO COMPLETE: Okta data processing agreement, not in force on the Free plan] |
| Sendinblue SAS (Brevo) 9-17 rue Salneuve, 75017 Paris, France Privacy policy · Data processing agreement | Sending the account’s emails for Auth0 (verification, new password), and nerdbox’s emails to those who asked for them | France and Belgium; company in France | Data processing agreement (Appendix 3 of its terms) |
nerdbox’s emails
nerdbox sends news and tips by email, and will tell those who asked when the developer offer opens, only to people who asked for it: an unchecked box in your space or after accepting the terms, or the form at the bottom of the pages. A confirmation email comes first: without a click on its link, nothing else is sent. Your consent is recorded with its proof: the version and language of the text you read, the date, where you gave it and the IP address of the request; your withdrawal too.
- What goes to Brevo, which sends these emails: your email address, your language and the lists you chose. For an account, and only once you have confirmed: the day you signed up, how you sign in (email, Google, GitHub), the days of your first address and of your first code received, whether you used the Chrome extension and turned notifications on, and the day of your last visit. Never one of your disposable addresses, nor anything from a mail: no sender, subject, content nor code.
- Opens and clicks of these emails are measured by Brevo (a tracking image, and links that go through Brevo before their destination), to know which emails are read.
- How long: 3 years after your last contact with nerdbox, or after you unsubscribe (the proof of the unsubscription); a request never confirmed, 30 days. Deleting your account erases all of it, here and at Brevo.
- Unsubscribe at any time: the link at the bottom of every email, or the switch in your space. Either way, both sides know.
Notifications
When you turn notifications on for a device, each notification goes through the push service of your browser, which delivers it: Google (Chrome, and Edge on Android), Microsoft (Edge on a computer), Mozilla (Firefox) or Apple (Safari). These companies are not our processors: your browser chose them. The notification is encrypted from our server to your device; the push service sees neither the code, nor the sender, nor the subject, only that a notification of a given size is sent to your device at a given time. Google, Microsoft, Mozilla and Apple may process this in the United States. With “Hide the content”, the notification itself only says “New mail”.
Signing in with Google or GitHub
If you choose to sign in with Google or GitHub, that company confirms who you are and sends Auth0 your email address, whether it has verified it, your name and your profile picture; nerdbox itself receives only your email address and whether it is verified. Google and GitHub are not our processors: you chose them, and their own policies apply, Google’s and GitHub’s. They may process this data in the United States.
The Chrome extension
The extension is optional. It acts only when you ask it to, with its menu on a field, its shortcut or its button: it then reads the field you aimed at and the name of the site, to label the new address with it, and nothing else of the page. It talks to nerdbox and to the sign-in page only, and collects nothing of your browsing: no history. nerdbox counts, in a daily total that says nothing about who, how many addresses are created through it. It keeps two things in the browser’s session storage, which no web page can read and which is emptied when the browser closes: the key that keeps it signed in, and the last code received by each address. Signing out of the extension deletes both and revokes the key.
Transfers outside the European Union
The server is in France. Cloudflare and Okta (Auth0) are American companies: data may be processed in the United States. These transfers rely on the EU-US Data Privacy Framework, in which both companies are certified (adequacy decision of the European Commission of 10 July 2023), and, for Cloudflare, also on the standard contractual clauses of the European Commission included in its data processing agreement. The Auth0 tenant of nerdbox is in Auth0’s European region.
Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format.
You export your data (one JSON file, 3 times a day at most) and delete your account yourself, from your space: “My account”. For anything else, write to [email protected] from the email of your account, or say which account it is about. You get an answer within one month. The identification data, kept under a legal obligation, cannot be erased before it is due, nor is it part of the export.
You can also lodge a complaint with the French data protection authority, the CNIL: cnil.fr/fr/plaintes.
Security
- Every connection is encrypted (HTTPS); the server opens no port to the Internet but its administration access, everything goes through a Cloudflare tunnel.
- nerdbox stores no password: sign-in is handled by Auth0. Your session token stays in your browser’s memory.
- Mail is shown in an isolated frame, without scripts, and remote images are blocked by default: they are often tracking pixels.
- The content of mail is never written to the logs.
Minimum age
The service is for people aged 18 or older.
Changes
This policy follows the service: it changes when the service changes, with a new version and date at the top of the page.