Pigeon Atlas

Privacy Policy

Last updated September 09, 2026

Pigeon Atlas is operated by Golux Group, Timocka 11, Belgrade-Zemun, 11080, Serbia. This describes what we hold, why, for how long, and who else can see it. Where it is vague, assume the narrower reading and write to support@pigeonatlas.com.

Two different roles

For your own account — your name, your email address, your billing — we decide what is held and why, and we are the controller.

For the mail you send, we are a processor. Your recipients are your contacts, not ours: we hold their addresses and messages because you asked us to deliver them, we act on your instructions, and we never market to them or use their addresses for anything but delivering what you sent. Whether you had the right to mail them in the first place is your responsibility, and the Acceptable Use Policy sets out what we require of you there.

What we hold

Your account

Name, email address, a hash of your password, and your account's plan. Never the password itself.

Sessions

The IP address and browser user agent of each sign-in, so you can see where your account is signed in and we can rate limit attacks on it.

Messages you send

Sender, recipient, subject, the message body, and the delivery outcome. The body is the part with the shortest life — see below.

Delivery events

Deliveries, bounces, complaints and, if you switch tracking on, opens and clicks with the recipient's IP address and user agent. Tracking is off unless you enable it per domain.

Suppressions

Addresses that bounced or complained on your account, so we do not send to them again.

Billing

Your Stripe customer and subscription identifiers. Card details go to Stripe directly and never reach us.

How long we keep it

Message bodies are deleted after 30 days. What survives is the delivery record — who it went to, when, and what happened to it — because "did this send?" has to stay answerable long after the message itself is no use to anybody.

Everything else lives as long as your account does. Closing it deletes your domains, keys, messages, contacts and stored bodies. Suppressions are the one exception we would argue for keeping: an address that filed a spam complaint should not start receiving mail again because an account was recreated.

Where it is held

In the European Union, throughout. The application and database run in Amsterdam, archived message bodies sit in Frankfurt, and mail is sent through Frankfurt. Nothing is stored outside the EU.

Who else touches it

DigitalOcean

Amsterdam and Frankfurt

Runs the servers and the database, and stores archived message bodies.

Amazon Web Services

Frankfurt

Delivers the mail. Messages pass through SES to reach the recipient.

Stripe

EU and United States

Takes payment. They receive your billing details directly; we receive identifiers back.

That is the whole list. We will update this page before adding to it.

Cookies

One, and it holds your session so that you stay signed in. There is no analytics script on this site, no advertising network, and nothing that follows you to another one — which is why you were not asked to dismiss a banner on the way in.

What you can ask for

A copy of what we hold about you, a correction, deletion, or a machine-readable export. Write to support@pigeonatlas.com and we will answer within 30 days. You do not need a reason and it costs nothing.

If you are a recipient rather than a customer, we hold your address because one of our customers sent to it. Write to us and we will tell you which account, and pass the request on — but they, not we, decide whether they had grounds to mail you. You can also unsubscribe from any bulk message directly, which suppresses your address for that account immediately and does not require our involvement.

If you think we have got this wrong, you can complain to your national data protection authority.

Breaches

If data is exposed, we will tell affected customers within 72 hours of finding out, with what happened and what we know at that point rather than waiting until the picture is complete. Security reports are welcome at security@pigeonatlas.com.

Changes

We will email account owners before this page changes in a way that affects them, rather than editing it quietly and relying on the date at the top.