Your own domain
Run mail on yourname@yourcompany.com with full DNS control: SPF, DKIM, DMARC, custom MX records, unlimited aliases, catch-all forwarding, automatic TLS.
Private email, engineered
Encrypted, filtered, and hosted entirely on servers in the EU, fully GDPR-compliant. Built for people who don't want their inbox anywhere else.
Before it reaches you
No third parties
Data residency
What's inside
Run mail on yourname@yourcompany.com with full DNS control: SPF, DKIM, DMARC, custom MX records, unlimited aliases, catch-all forwarding, automatic TLS.
Full protocol support: IMAP, POP3, SMTP, MAPI/EWS for Outlook, and Exchange ActiveSync for iOS and Android. Use whatever mail app you already trust.
Shared calendars with CalDAV sync, contacts with CardDAV sync, task lists and notes. All built into the same account, no extra app required.
Incoming mail is scanned line by line for spam, viruses, and phishing before it lands in your inbox. Nothing is kept afterward.
Admin dashboard, role-based permissions, shared address books, distribution lists, and centralized control for whole organizations.
Encrypted transport with TLS 1.3, redundant infrastructure across multiple locations, and continuous monitoring keep mail flowing.
Always on
Continuously monitored
One account
Ready when you are
Contact
General questions, feedback, or anything else. We read every message ourselves.
Received
Thanks for reaching out. We reply to genuine messages as soon as we can.
Whitelist
This form is for whitelist requests. Every request is reviewed by hand. It is not a general inbox.
Received
We review whitelist applications by hand. If the sending domain is RFC-compliant, you will hear from us.
Webmail
Verified straight into SmarterMail. No second login screen.
Verified
Redirecting to your inbox.
Imprint
Last updated: August 2026
intelligent piXel GmbH
Enzianstraße 4a
82319 Starnberg, Germany
Managing Director: George A. Rauscher
Authorized Officer: Dr. Maria-Louise Morgott
VAT ID: DE291416044
Commercial Register: HRB 207679, Munich District Court
This website uses self-hosted Lucide icons served from our own infrastructure. This avoids requests to third parties and supports privacy-conscious delivery. Lucide is credited to the Lucide project and its contributors.
Privacy
Last updated: August 16, 2026
This policy describes how we handle personal data when operating the email service at mail.vipmail.app. The website vipmail.app is covered by a separate policy published there.
intelligent piXel GmbH
Enzianstraße 4a
82319 Starnberg, Germany
Managing Director: George A. Rauscher
Authorized Officer: Dr. Maria-Louise Morgott
Commercial Register: HRB 207679, Munich District Court
VAT ID: DE291416044
Email: my@intelligent-pixel.com
For privacy inquiries and unblock requests: postmaster@vipmail.app
As a processor under Art. 28 GDPR we act on behalf of our customers with regard to the contents of their mailboxes. The mailbox holder decides on the purpose and the means of that processing. A data processing agreement is in place with our business customers.
As a controller in our own right we act on everything that protects the service and keeps it running: defending against attacks, filtering unwanted and harmful messages, and the logging that requires. The legal basis is Art. 6(1)(f) GDPR, supported by Art. 32 GDPR.
This policy also applies to people who simply send us a message without being customers.
For our customers, we collect data directly from the person concerned, as part of the contractual relationship and through their use of the service.
For people who send us a message without being customers, we do not receive the data from them directly. It comes from the message itself and from the technical delivery process. Under Art. 14 GDPR we therefore set out the source and the categories here:
| Category | Source |
|---|---|
| IP address of the connecting system | technical connection setup |
| Sender and recipient address | SMTP transaction |
| Subject line, message identifier, timestamps | message headers |
| Delivery chain and technical headers | message headers |
| Results of authentication checks | our own checks against public DNS records |
| Reputation data on the IP address | queries to public directories |
| Message content | the message itself |
Message content is processed by automated systems only, and solely for delivery, storage in the mailbox, and defense against malware, fraud, and unsolicited advertising.
In addition, every sign-in to a mailbox gives us the IP address, the time, the protocol used, and the account being accessed.
| Purpose | Legal basis |
|---|---|
| Delivering, storing, and providing access to messages | Art. 6(1)(b) GDPR |
| Filtering spam, malware, and phishing | Art. 6(1)(f) GDPR |
| Defending the infrastructure against attacks | Art. 6(1)(f) and Art. 32 GDPR |
| Logging for troubleshooting and evidence | Art. 6(1)(f) GDPR |
| Handling inquiries and unblock requests | Art. 6(1)(b) and 6(1)(f) GDPR |
Our legitimate interests under Art. 6(1)(f) GDPR are these: keeping the service available and intact, protecting our customers from fraud, malware, and identity theft, protecting mailboxes from unauthorized access, and meeting our obligation under Art. 32 GDPR to maintain an appropriate level of security. We have weighed these interests against those of the people concerned. Processing is limited to what defense requires. Nothing is analyzed for any other purpose, and no profiles are built.
Processing the data described above is a technical precondition for delivering email at all. It does not arise from any legal obligation on the sender, nor from a contract with them. It follows from how email works. Without this data, a message can be neither received nor checked nor delivered.
You are under no obligation to provide us with data. If you do not send a message to an address we host and do not use a mailbox, we process nothing about you.
As an email service provider we are bound by the confidentiality of communications under § 3 TDDDG. We honor that obligation.
No person reads message content. Incoming messages are checked for malware, fraud, and unsolicited advertising by automated systems only, and only to the extent required to run the service and keep our systems secure. Our staff are formally bound to maintain the confidentiality of communications.
The service runs on dedicated hardware rented from
Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany
All mailbox contents, logs, and backups are processed and stored exclusively in data centers within the European Union. No data is transferred to a third country. A data processing agreement under Art. 28 GDPR is in place. Hetzner has no access to mailbox contents. Its role is limited to providing the infrastructure.
Every incoming message goes through several independent checks. The purpose is defense. We build no profiles of senders or recipients, and content is not analyzed for any other purpose.
These checks never leave our server.
To assess the connecting IP address and any links contained in a message, we query public reputation directories. All that gets transmitted is the address or domain name being checked, in the form of a DNS query. No message content is transmitted.
Depending on the outcome, a message is delivered, moved to the junk folder, or refused. Messages that fail several independent checks at once are not delivered.
Senders whose domain passed SPF or DKIM authentication receive an automatic notice in that case, stating a reference number and which checks were flagged. Senders who could not be authenticated receive no notice. That keeps us from sending messages to people whose address was forged by somebody else.
Under Art. 13(2)(f) and Art. 22 GDPR we want to be explicit about this: the decision on whether a message gets delivered is made automatically.
The logic behind it. Every message goes through several independent checks. Each check that is flagged raises a numeric score. Once that score reaches a set threshold, the message is not delivered. A single flagged check is not enough. Several have to fail at the same time. We review the threshold regularly against the mail traffic we actually receive.
What it means for you. If a message is not delivered, it does not reach the recipient. The sender is informed, provided their domain passed authentication.
Your rights under Art. 22(3) GDPR. You have the right to obtain human intervention, to express your point of view, and to contest the decision. Use the form on vipmail.app, or simply write to postmaster@vipmail.app. Please quote the reference number from our notice if you received one. Every contested decision is reviewed by a person, not by a machine.
Messages held back on suspicion of fraud are kept for seven days, so that such a review is genuinely possible and a wrong decision can be corrected.
This service is under constant automated attack. On an ordinary day we record several thousand failed sign-in attempts from several hundred different IP addresses.
Here is what we block:
For this we process the IP address, the time, the protocol used, and the account being addressed. Addresses that stand out are blocked in stages, ranging from one month upward depending on severity. Blocks are reviewed regularly and lifted once the reason is gone. A block can cover an entire network range where attacks repeatedly come from it. Before applying one, we check automatically whether legitimate sign-ins have ever come from that range.
A block only affects the sign-in interfaces. Receiving email and access to webmail remain available in every case. A blocked address can still deliver messages to our customers.
We do this to keep the service running and to protect our customers. It is a security measure under Art. 32 GDPR.
If your IP address has been blocked, or your messages are not getting through, you can ask us to review it. There is a form on vipmail.app for exactly that. A plain message to postmaster@vipmail.app works just as well.
What we need from you: the IP address or sender address concerned, the reference number from our notice if you have one, and a short description of the situation.
About the form. It runs on our own server and is secured to the same standard as the rest of our infrastructure. It uses no third party services, no external scripts, and no tracking. Submissions go directly and encrypted to a mailbox operated by Proton AG in Switzerland. The European Commission has recognized Switzerland as providing an adequate level of data protection.
We process what you send us together with the log entries for that case. Legal basis: Art. 6(1)(f) GDPR. Every request is reviewed by a person, and we tell you the outcome. We delete the details six months after the case is closed.
There is no automatic right to have a block lifted. We lift one when the review shows that the reason is gone, or that the block reaches further than it needs to.
The server is built to stay up. Storage sits behind multiple redundant RAID arrays, so losing individual drives interrupts nothing and costs no data.
Mail is backed up every hour, so that even a serious failure puts as little of it at risk as possible. We keep three independent sets of backups on separate systems. For security reasons we do not say where they are or how they are structured.
Backups are overwritten once their retention period is up. If you delete a message from your mailbox, it may still exist in a backup until then. Backups serve only to restore the service as a whole. We do not use them to look up individual messages.
| Type of data | Period |
|---|---|
| Mailbox contents | until deleted by the mailbox holder |
| Delivery and connection logs | 14 days |
| Security logs from attack defense | 60 days |
| Copies of flagged messages, for review | 7 days |
| IP block lists | graded by severity, up to ten years |
| Unblock requests | six months after the case is closed |
The long period for block lists is necessary because the same network ranges get used for attacks over years, and a short one would make the protection worthless. What we store is the IP address, the reason, and the time of the block. Nothing else about the person.
We do not pass personal data to third parties for their own purposes. Nothing is sold, rented, used for advertising, or used to build profiles.
The following are involved as processors or recipients for the purposes described above:
| Category | Purpose | Location |
|---|---|---|
| Data center operator | providing the infrastructure | based in Germany, processing within the EU |
| Provider of the mailbox receiving form submissions | receiving unblock requests | Switzerland |
| Operators of public reputation directories | IP address and domain lookups | various |
On request we will name the specific recipients.
We disclose data to public authorities only where the law requires it. We examine every such request for its lawfulness and limit disclosure to what the law demands.
You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you that is based on Art. 6(1)(f) GDPR.
If you object, we will stop processing the data in question, unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing serves to establish, exercise, or defend legal claims.
Send your objection informally to postmaster@vipmail.app.
You have the right to access the data we hold about you (Art. 15 GDPR), to have inaccurate data corrected (Art. 16), to have it erased (Art. 17), to have processing restricted (Art. 18), and to receive your data in a portable format (Art. 20).
Send your request to postmaster@vipmail.app or my@intelligent-pixel.com.
One practical note on access requests: delivery and connection logs are deleted automatically after 14 days. An access request can therefore only cover data still held when we receive it.
If you are a customer of one of our business clients and your request concerns the contents of a mailbox, please contact that mailbox holder. For those contents we act as a processor and may not respond without their instruction.
You have the right to lodge a complaint with a supervisory authority. The one responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht
Promenade 18
91522 Ansbach, Germany
We update this policy when our technical procedures or the legal requirements change. The version published on vipmail.app is the one that applies. We notify our customers separately of any substantial change.