What is in our logs, and what is not

What the server of this website records, which logs the mail service keeps, how long they stay and what never goes into them.

A log records what a server has done. It helps to find faults and detect attacks, and at the same time it is a collection of data about you. This post states what is written into logs at privymail.eu, how long it stays and what is never in them.

Logs grow by themselves

When in doubt, software logs too much. Default settings record who requested which page and when. Error messages contain whatever was being processed at the time. And what has once been stored stays where it is if nobody has built in deletion. For a mail service such records are sensitive even without message bodies: who wrote to whom and when says a great deal.

Our principle is the same as everywhere: data we do not hold can be neither lost nor handed over by us. For logs that means: write little, keep it briefly, delete automatically.

This website: no access log, no statistics

The website is static and contains no JavaScript, cookies, tracking or advertising. When a page is requested, the server processes your IP address and the HTTP request to deliver it. It keeps no access log of this: access logging is not enabled in Caddy, the web server. There are no statistics either, not even aggregated ones.

No server runs entirely without logs. System and security logs are kept for server operations; they may, for example, include IP addresses from failed administrator sign-ins. The system journal, the log of the operating system, is limited to seven days.

The mail service: little goes in, and it does not stay long

RecordPurposeRetention
Login logs with IP addresssecurity and abuse prevention7 days at most
SMTP logs without contentdelivery and troubleshooting14 days at most
Abuse casesspam and fraud prevention90 days at most

A log without content is not empty. A login log names the account, the event and the IP address. An SMTP log, the record of mail transport, holds what has to be traceable for delivery and troubleshooting: connection data, that is, who delivered to whom and when, and what the other server replied. That is personal data too, hence the retention periods. Five rules come on top:

  • Content stays out. Logs contain neither message bodies nor subject lines.
  • Secrets stay out. Sign-in logs name the account and the event, but never password material, session identifiers or codes. An automated test searches the log output of a complete sequence for them.
  • Sessions without origin. For a session, the account database stores neither IP address nor browser identifier nor device characteristics, and it keeps no sign-in history. Times of use are recorded there only as a date, failed attempts not at all: the service counts them only in memory. The IP address of a sign-in is in the login log and disappears with its retention period.
  • Deletion is a program, not an intention. Deletion runs are automatic and tested: a test shows that data is gone once its period has expired. The deletion runs themselves log only counts.
  • One log is thorough: the one about us. Access to the systems of the mail service is recorded in audit logs. The four-eyes principle applies to key access, write access to databases, requests from authorities and manual deletions.

What it costs

  • Short periods cost answers. After 14 days the log can no longer show why a message did not arrive. After 7 days it can no longer show which address a sign-in came from. Anyone who asks late gets no answer from the log.
  • Late discoveries stay darker. If an attack is noticed only after weeks, the records from the time before are missing.
  • Troubleshooting without content is harder. A log that does not know the message body shows that something went wrong, but not always why.

What it does not solve

  • The server sees more than it writes down. No content in logs does not mean the server processes no content. In Compatible, the default mode, it processes plain text while you are signed in, and during delivery. The Security page describes this.
  • Connection data is still data. Within the retention period, an SMTP log shows who wrote to whom. The period limits that; it does not remove it.
  • Others keep logs too. Network operators, your correspondent's mail server and your own mail app keep records of their own. Our rules do not apply there.

Further reading