This server records opens, clicks and button taps on email for the person who sent or received that email, using Envelope. It exists so they can see how they themselves read mail, and whether mail they sent was opened. Nothing here is sold or shared.
For each open, click or tap: an opaque stream id, a hash of the link token, the time, the kind of event, and a coarse client class (browser, Apple Mail privacy proxy, Google image proxy, known security scanner, bot, or unknown).
No IP address, no full user-agent string, no destination URL, no subject line, no email address. Link destinations travel inside the link itself, in the clear, so you can always see where a link goes before you follow it. Link tokens are signed by the owner's install; this server holds only the keys that check signatures, never the keys that make them.
Events wait here until the owner's install collects them: 7 days after collection, or 90 days if never collected, they are deleted. Each install may record at most 330 events per day. Past that, events are dropped. Links and images keep working.
Apple Mail loads images through a privacy proxy, so an "open" from Apple Mail usually does not mean a person read the message. Envelope labels those as proxy loads.
Tracked mail carries an X-Envelope-Tracking header naming this server. To ask the sender to stop tracking mail to you, open https://cairn.u1f4e7.com/optout/<token> using the token from any image or link in that message.