Privacy Policy
Effective date: August 18, 2026 · Applies to SOFX.NET and related SOFX services.
01Scope of This Policy
This Privacy Policy describes how SOFX, Inc. ("SOFX," "we," "us") collects, uses, and protects information in connection with SOFX.NET — our private email and communication platform — including webmail at mail.sofx.net, member messaging, file storage, conferencing, and this website (together, the "Services"). By using the Services, you agree to this Policy and to our Terms of Service. If you do not agree, do not use the Services.
02Our Privacy Principles
SOFX.NET exists because most email is paid for with your data. Ours is not. The Services are funded by membership fees — not advertising — and are operated on infrastructure we directly control, by our own team.
- You are the customer, not the product. We sell memberships, never data.
- Minimum necessary collection. We collect only what operating a reliable, secure mail service requires.
- Humans, not algorithms. No behavioral profiling, no advertising analytics, no AI systems reading your mail.
03Information We Collect
Information you provide
- Account and application information: name, contact email, phone number, desired username, and the information you submit during our manual membership review.
- Payment information: processed by our payment processor (Stripe). We do not store full card numbers on our systems.
- Your communications with us: support requests, contact-form submissions, and correspondence with our team.
- Your content: the email, files, calendar entries, and other material you store or transmit through the Services. This content is yours; we handle it only to deliver the Services.
Information collected automatically
- Operational logs: connection metadata (such as IP address, timestamps, and protocol information) generated in the ordinary course of running mail infrastructure — used for delivery, security, and abuse prevention.
- Essential technical data: the minimum required for the website and webmail to function. We do not deploy advertising cookies or third-party tracking pixels.
04How We Use Information
- To provide, maintain, and secure the Services — delivering your mail, syncing your devices, and protecting the network.
- To verify membership applications and maintain a network of real people.
- To process billing and renewals through our payment processor.
- To respond when you contact us for support.
- To detect and prevent spam, malware, fraud, and abuse of the network. Automated filtering for malware and spam signatures is the only automated processing applied to message traffic — it exists to protect you and is never used for advertising, profiling, or AI training.
- To comply with legal obligations.
05Cookies
We use cookies sparingly, and only in the strictly-necessary category:
- Session and authentication cookies — so you can sign in to webmail and stay signed in securely.
- Security cookies — to protect against cross-site request forgery and session hijacking.
- Preference cookies — to remember basic settings you choose within the Services.
We do not use advertising cookies, third-party analytics cookies, cross-site tracking cookies, or tracking pixels — on the website or inside the mail service. Because we use only strictly-necessary cookies, there is no cookie-consent wall to click through. You can clear or block cookies in your browser settings; blocking essential cookies will prevent webmail sign-in from working.
06What We Never Do
- We never sell, rent, or trade your personal information.
- We never scan your communications for advertising.
- We never use your content to train artificial-intelligence models, nor permit others to.
- We never place third-party advertising or tracking technologies in the Services.
- We never build behavioral profiles of members.
07Sharing & Disclosure
We share information only in these limited circumstances:
- Service providers: a small number of vendors strictly necessary to operate (for example, payment processing and datacenter services), bound to use information only on our behalf.
- Legal process: where required by valid subpoena, court order, or other lawful process. We review every demand, comply only to the extent legally required, and — unless legally prohibited — notify the affected member.
- Protection of the network: where necessary to enforce our Terms, or to protect the rights, safety, or property of SOFX, our members, or the public.
- Business transfers: if SOFX is involved in a merger, acquisition, or asset sale, information may transfer to the successor, which remains bound by this Policy's commitments.
08Security
The Services run on U.S.-based servers administered by our own personnel, hosted on infrastructure from a major U.S. cloud provider. The provider supplies hardware and datacenter facilities; only SOFX personnel manage the systems and hold access to member data. Access to the Services is encrypted in transit (TLS/SSL). Administrative access is restricted, logged, and limited to personnel who need it. No system is perfectly secure, and we cannot guarantee absolute protection — but unlike ad-funded providers, our business model never puts your data at cross-purposes with your interests. You are responsible for safeguarding your login credentials.
09Data Retention
- Your content is retained while your account is active. When your account closes, content is deleted from active systems within a commercially reasonable period, subject to backup cycles and legal holds.
- Operational logs are retained only as long as needed for security and delivery purposes, then deleted or anonymized.
- Billing records are retained as required by tax and accounting law.
10Your Rights & Choices
Regardless of where you live, we extend the same core rights to every member:
- Access & portability — request a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete information (much of this you can do directly in account settings).
- Deletion — request deletion of personal data, subject to legal retention requirements.
- Objection — object to processing that is not required to deliver the Services.
To exercise any of these rights, email privacy@sofx.net. We will respond within the timeframe required by applicable law (and aim to be faster). We do not discriminate against anyone who exercises privacy rights.
11U.S. State Privacy Rights
If you reside in a state with a comprehensive privacy law — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others — you may have specific statutory rights, including the rights to know, access, correct, delete, and obtain a portable copy of your personal information, and the right to opt out of the sale or sharing of personal information and of targeted advertising.
- We do not sell personal information, and we have not done so in the preceding 12 months.
- We do not share personal information for cross-context behavioral advertising, and we do not engage in targeted advertising.
- We do not use or disclose sensitive personal information except to provide the Services you request.
- Because of the above, there is no sale, sharing, or targeted advertising to opt out of — and no "Do Not Sell or Share" link is required. That is by design.
- Universal opt-out signals: since we do not track or sell, signals such as Global Privacy Control require no action from us — but we honor their intent by default.
To exercise any state-law right, email privacy@sofx.net. You may use an authorized agent where the law provides for one; we will verify the request as the law requires. If we ever decline a request, we will explain why, and you may appeal by replying to our decision.
12International Users & GDPR
SOFX.NET is built for a U.S. audience. The Services are operated from the United States, hosted on U.S. servers, and directed to U.S. members. We do not target or market the Services to the European Union, the European Economic Area, or the United Kingdom.
That said, we do not geography-lock the Services. If you access them from the EU/EEA, the UK, or another jurisdiction with GDPR-style protections, we will make a good-faith effort to honor the rights those laws provide, including:
- Access, rectification, erasure ("right to be forgotten"), and data portability;
- Restriction of, and objection to, processing;
- The right not to be subject to solely automated decision-making (we do not practice it in any case);
- The right to withdraw consent where processing is based on consent.
Where GDPR concepts apply, the lawful bases for our processing are: performance of a contract (delivering the membership you purchased), legitimate interests (securing and operating the network), and legal obligation. By using the Services from outside the United States, you understand your data is processed and stored in the United States. To exercise these rights, contact privacy@sofx.net; you also retain any right you may have to lodge a complaint with your local supervisory authority.
13Children
The Services are intended for adults and require membership. They are not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
14Changes to This Policy
We may update this Policy from time to time. Material changes will be announced by email or prominently within the Services before they take effect. Your continued use of the Services after the effective date constitutes acceptance. We will never change this Policy to permit the sale of member data or advertising-based processing of member content.
15Contact
SOFX, Inc.
997 Morrison Dr, Charleston, SC 29403
Privacy inquiries: privacy@sofx.net
General: contact@sofx.net