Legal
Privacy policy
Last updated 30 September 2026. This covers the Woyra platform, the Woyra console, and the Woyra Mail applications for the web and for Android.
Who this is
Woyra is operated by MINAC GROUP LLC. For questions about this policy, or to make any request described below, write to privacy@woyra.com.
Where Woyra Mail is provided to you through your employer or through a partner such as TalariCloud, that organisation decides who has a mailbox and what happens to it. Woyra processes the mail on their instructions. Requests about your own account usually have to go through them, and we will say so rather than act on an instruction we are not entitled to follow.
What Woyra Mail holds, and why
| What | Why | How long |
|---|---|---|
| Your email address and display name | It identifies the mailbox. There is no product without it. | While the mailbox exists |
| Your messages, their attachments and their headers | Storing and delivering mail is the service. | Until you delete them, then 30 days, then erased |
| Delivery and authentication results (SPF, DKIM, DMARC, spam verdicts) | To show you when a message is not from who it claims, and to keep the platform’s sending reputation intact for every customer on it. | 90 days |
| A push notification token, if you allow notifications | So your phone can be told mail arrived. | Until you sign out or revoke it |
| Usage counts: bytes stored, messages sent and received | To bill accurately and enforce a quota. Counts, not contents. | 7 years, because tax authorities ask |
What Woyra does not do
- Your mail is not read to target advertising. Woyra sells email and messaging, not audiences. There is no advertising product for your mail to feed.
- Your mail is not used to train machine learning models, ours or anybody else’s.
- Your mail is not sold, rented or shared with data brokers.
- The apps carry no advertising identifier, no analytics SDK and no third-party tracker. If that ever changes it will change in this policy and in the Google Play data safety declaration in the same release.
Two things the apps do on purpose
Remote images are blocked until you ask for them. An image loaded from someone else’s server tells that server when you opened the message and roughly where you were. In business email that is usually why the image is there. Woyra Mail blocks them and offers a button; whether to load them stays your decision, per message.
A notification never contains your mail. When new mail arrives, your device is told only that the mailbox changed and where to resume from. It then fetches the message itself over its own authenticated connection. This is deliberate: a push payload travels through Google’s infrastructure and is stored in a notification log on the device, and your correspondence should be in neither.
Where your mail is kept
Woyra Mail runs on Amazon Web Services, and the region is fixed per deployment and stated in your agreement. Woyra records the region an account belongs to and refuses cross-region reads.
We are specific about one thing because customers in Ethiopia reasonably ask. Woyra does not currently host data inside Ethiopia. If you have an obligation under Proclamation No. 1321/2024 to keep personal data in the country, Woyra Mail does not meet it today, and we would rather tell you that here than have you discover it later.
Who else touches it
Woyra uses a small number of processors, each for a stated job and none of them permitted to use your data for their own purposes:
- Amazon Web Services — hosting, storage and mail delivery.
- Expo / Google Firebase Cloud Messaging — delivering push notifications. They carry the notice that something changed, never the message.
- Stripe — payment processing. Woyra does not store your card details.
Woyra discloses mail to a government or a court only where legally compelled, and will tell you unless the law forbids it.
How it is protected
- Every connection is encrypted in transit. The apps make no cleartext requests.
- Mail is encrypted at rest with a customer-managed key.
- On Android, your credential is held in the Android Keystore rather than in ordinary app storage, so it is not readable from a device backup.
- Message bodies render with scripting disabled and a strict content security policy, so a message cannot run code, load a tracker or place a fake form over the app.
- Access to production is limited to named staff and is logged.
Deletion, and what “erased” means
A deleted message is recoverable for 30 days and then erased. A closed account is recoverable for 60 days and then erased, the longer window because closure is more often a mistake or a dispute than a decision.
Erasure means the rows are deleted, the stored objects are deleted, and the encryption key material is destroyed where a per-customer key is in use. One honest caveat: point-in-time backups have their own 35-day window, so a message may exist in a backup for a short period after it disappears from your mailbox. It is not readable by anyone without a restore, and it ages out.
Your rights
You can ask for a copy of your data, ask for it corrected, ask for it deleted, or object to how it is handled. Write to privacy@woyra.com. If your mailbox was provided by an employer or a partner, we will pass the request to them and tell you we have, because it is their decision and not ours.
Children
Woyra is sold to businesses and is not directed at children. Woyra does not knowingly collect data from anyone under 16.
Changes
When this policy changes materially, account holders are told by email before it takes effect. The date at the top is the version in force.
Woyra is operated by MINAC GROUP LLC.