Privacy policy
Last updated: 4 October 2026
This page says what data we handle, what for, who we share it with, and what you can ask of us. It is written to be understood without a lawyer. If something isn't clear, write to legal@duobox.io.
Who handles your data
Duobox is a service of MSN Computing LLC, a United States company, at 1209 Mountain Road Place NE, STE N, Albuquerque, NM 87110, United States. We are the controller of the data: the company that decides what gets handled and what for.
For anything on this page, write to legal@duobox.io. We have not appointed a data protection officer: we are a small company and are not required to have one.
Your mail: what we do with it and what we don't
It's the first thing you want to know, so it goes first.
Duobox sells email on your domain. For you to open a message and read it, we have to store it. That is everything we do with the content of your mail.
What we do
- We store the messages that come in and go out, with their attachments and headers, to show them to you when you open the inbox.
- We deliver them: outgoing mail goes through our sending provider to the recipient.
- We filter them: an automatic filter checks incoming mail to set spam aside. It's a program, not a person.
What we don't do
- We don't read your mail. Nobody at Duobox opens your messages.
- We don't use it for advertising. No ads, no profiles.
- We don't sell it and we don't hand it to anyone who wants data.
- We don't use it to train models, ours or anyone else's.
- We don't mine it for statistics about your business.
If you connect an agent, the agent is yours and it runs on your side. You choose what it can do in each inbox — read, write drafts, or send — and every action is logged. Duobox gives no agent access to your mail unless you connected it.
What data we handle, and where it comes from
Your account
Your name, your email address — which is your inbox address, on your domain — your password, your company's name, and your role inside it: owner, admin or member. The password is stored as a *hash*, a fingerprint that cannot be turned back into the original password. You give us all of this when you create the account.
Your domain
The domain name, and the owner details the registrar — the company that registers domain names — requires in order to register it. You give us these when you buy or connect a domain.
Your mail
The content of the messages that come in and go out, with their attachments and headers. You write them, or the person writing to you does.
Your payment
Payment is handled by Stripe. You give your card details to Stripe, not to us: Duobox does not store card numbers. On our side we keep a Stripe customer identifier and the status of your subscription.
Sending
Outgoing mail goes through Amazon SES, which reports bounces and complaints back to us. We store the addresses that hard-bounced — they don't exist — and the ones that marked a message as unwanted, so we stop writing to them. It is a list of addresses, not of content.
Your session
When you sign in, an HttpOnly session cookie is left in your browser and the matching row in our database. HttpOnly means no script on the page can read it. We keep no tokens in the browser.
The public site
On duobox.io and app.duobox.io we measure visits with Google Analytics. We send the route pattern and not the URL with identifiers: it sees that someone looked at a domain page, not which one. The webmail has no analytics: inside your mail we measure nothing.
The Google connection
Only if you turn it on. It has its own section below.
What we use it for, and on what legal basis
"Legal basis" is the reason the law lets us handle a piece of data. We use four.
| What for | Which data | Legal basis |
|---|---|---|
| Giving you the service: your account, your domain, your inbox, your mail | account, domain, mail, session | The contract with you. Without this there is no product |
| Charging you and running your subscription | payment | The contract |
| Getting the mail delivered: spam filter, bounces and complaints | mail, sending | Legitimate interest — a reason of our own that doesn't harm you: keeping the service working for everyone and not getting blocked for spam |
| Understanding how the public site is used | site | Legitimate interest. We do not show a cookie banner today: you can block measurement cookies in your browser |
| Showing you how your site is doing on Google | Google connection | Your consent: you turn it on and you can disconnect it |
| Meeting legal and accounting obligations | account, payment | Legal obligation |
Governing law: the law of the State of New Mexico, United States.
Who we share it with
With nobody who wants it for themselves. Only with the companies we need for the service to work. The law calls them processors: they handle data on our behalf, following our instructions, and they cannot use it for anything else.
| Who | What for | What they see |
|---|---|---|
| AWS | Servers, database and mail sending (Amazon SES) | What we store, your mail included, on their infrastructure |
| Stripe | Charging | Your payment and billing details |
| Measuring the public site and, if you turn it on, the read-only connection | Visits to the site. Never your mail | |
| The domain registrar | Registering and renewing your domain | The domain name and the owner details |
We don't sell data. We don't hand it over for advertising. If an authority asks for it with a valid order, we give what the law requires and nothing more.
Where it is processed
On AWS infrastructure, region us-east-1 (United States), with a PostgreSQL database. That is where your mail and everything else lives.
Duobox is a United States company and it handles the data in its own country. So the one that travels is your data: if you sign up from Latin America, Europe or anywhere outside the United States, your data leaves your country and is handled in the United States, under the laws there. That is an international transfer, and by using Duobox you accept it.
What that means concretely:
- Your mail, your account and your domain are stored on servers in the United States.
- The authorities that can ask for them with a valid order are United States authorities. We already said what we hand over in that case: what the law requires and nothing more.
- The rights below, you use by writing to us — we are the ones handling the data.
Stripe and Google may also process data outside your country.
How long we keep it
- Your mail: as long as your account exists. It's your archive and we don't delete it on our own.
- Your account and your company: as long as the account exists.
- Your session: the row is deleted when you sign out or when the session expires.
- Bounces and complaints: we keep them as long as they serve to stop us writing again to an address that doesn't exist or doesn't want to hear from us.
- Payments and billing: what accounting law requires.
- If you ask us to delete your data: write to legal@duobox.io and we delete it, except what the law requires us to keep. Today closing an account is not self-service in the app: you ask, and we do it.
Your rights, and how to use them
About your data, you can:
- Know what we hold and ask for a copy.
- Correct what is wrong.
- Delete what we don't have to keep.
- Take it to another service in a readable format. Your mail, on top of that, you download yourself with any mail program over IMAP.
- Object to what we do on legitimate interest, or ask us to restrict it.
- Withdraw a consent you gave, such as the Google connection.
- Complain to the data protection authority that covers you, if you think we got it wrong.
They apply to anyone, wherever they write from. Duobox is a United States company selling to companies in Latin America, Europe and the US, so more than one data protection regime can reach us. We won't ask you to tell us which one you are writing under: you get these rights either way. And if where you live gives you any more, you can use those too.
To use them, write to legal@duobox.io from your account's address. If you can't write from there, tell us how to verify it's you: we don't hand an account's data to someone we cannot identify. We answer on the same channel.
Your contacts' mail. The messages in your inbox are yours: we store them on behalf of your company. If someone who wrote to you wants to know what data of theirs is there, or wants it deleted, your company decides that, not us. If they write to us, we point them to you.
Cookies
There are two kinds and they don't do the same thing.
The one you need to sign in. The session cookie. Without it you can't sign in: the browser would have no way to say it's you on each request. It is HttpOnly, it can't be read from the page, and it is no use for following you across other sites. It can't be turned off: if you block it, the product can't be used.
The ones that measure. Google Analytics leaves cookies on duobox.io and app.duobox.io to count visits and see which pages get used. They are not needed for the product to work. You can block them in your browser or with an extension, and everything else keeps working the same.
There are no measurement cookies in the webmail. Only the session one is there.
The Google connection, if you want it
It's optional and it starts off.
If you turn it on, we ask for read-only permission on your Google Search Console and your Google Analytics, to show you inside Duobox how your site is doing: what people search, how many visits you get, where they come from.
What read-only means, concretely: we read those reports and nothing else. We don't write, we don't change anything and we don't delete anything in your Google account. We don't ask for access to your Gmail, your Drive or your contacts.
Duobox's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In plain words: we use that data to show you how your site is doing inside Duobox, and for nothing else. We do not sell it, we do not use it for advertising, and we do not use it to train models.
You can disconnect it whenever you want, from Duobox or from your Google account's permissions. From that moment we stop asking for that data.
Minors
Duobox is a product for companies. It is not meant for minors and we don't deliberately collect data about them. If we learn that an account belongs to a minor, we close it and delete the data.
Changes
If we change this policy, we publish the new version on this same page, with the new date at the top. When the change touches something important — new data, a new purpose, a new processor — we don't hide it in a line: we say it.
Contact
legal@duobox.io. Write to us in Spanish, English or Portuguese.
Controller: MSN Computing LLC, 1209 Mountain Road Place NE, STE N, Albuquerque, NM 87110, United States. We have not appointed a data protection officer: we are a small company and are not required to have one.
Anything unclear? Write to legal@duobox.io.