Privacy Policy
Last updated: 8/31/2026
1. Introduction
Welcome to smtp-sync. We operate as a "Stateful Proxy" utility designed to bridge your
legacy email accounts (POP3/IMAP) securely to your Gmail "Command Center". This Privacy
Policy outlines how we handle your data, with a strong commitment to a Zero-Trust security
model.
2. Data Collection & Authorization
To provide our services, we collect and securely store the following information:
- Google OAuth 2.0 Tokens: We store refresh tokens used exclusively to
authorize the
users.messages.import API. These tokens allow us to push emails to your Gmail inbox and are managed via Google's secure
OAuth 2.0 flow. - Mailbox Credentials: The usernames and passwords for your source POP3/IMAP
servers. These are required to establish the synchronization connection.
3. Data Protection Mechanisms
We take the security of your sensitive data seriously and implement the following protection
mechanisms:
- Encryption at Rest: All sensitive credentials, including your legacy
mailbox passwords and Google OAuth tokens, are encrypted at rest using industry-standard AES-256 encryption.
- Encryption in Transit: All data transfers between our servers, your
legacy email providers, and Google APIs are conducted over secure TLS (Transport Layer Security) encrypted connections.
- Data Isolation and Access: Operational credentials are isolated from the analytics
system and are available only to the synchronization processes that require them. Authorized
personnel may access the separate analytics system through Metabase to measure registration,
onboarding, mailbox connection, and service access activity, and to investigate service reliability
or security issues.
4. Zero-Trust Data Processing
Our architecture is built on a "No-Storage" binary streaming model. We
believe that your email content is your own.
- No Content Persistence: Email bodies, attachments, and content are never persisted to our disks or databases.
- In-Memory Streaming: Our high-concurrency workers stream data directly from
your source server to the Gmail API using temporary in-memory buffers that are cleared immediately
after the transfer.
5. Data Retention & Deletion
We adhere to strict data retention policies to ensure you have full control over your
information:
- Retention Period: We retain your mailbox credentials and sync metadata only
for as long as your synchronization task remains active in our system.
- User-Initiated Deletion: You can delete mailbox connections through the
dashboard. The dashboard does not currently provide account deletion. To request account
or analytics data erasure, email hello@mailtogmail.com.
- Operational Data Wiping: Upon deletion of a mailbox connection, its operational
credentials and active synchronization state, including encrypted passwords and OAuth tokens,
are immediately and permanently removed from our active operational databases. The analytics
records described below remain unless a verified erasure request applies.
- Google User Data: If you revoke access via your Google Security settings or
delete a mailbox connection, the associated Google OAuth tokens and operational mailbox connection
metadata are removed from our active operational databases. Historical service analytics remain
under the retention and erasure terms below.
- Service Analytics: We retain account email addresses, registration timestamps,
session creation timestamps, IP addresses, and browser User Agent strings in our PostgreSQL
analytics database without an automatic expiration period. This historical data is used to measure
registration, onboarding, mailbox connection, and service access activity, and may remain after
an operational account is deleted unless a verified erasure request applies.
- Erasure Requests: Before acting on an account or analytics erasure request,
we verify the requester's identity to protect users from unauthorized deletion. After verification,
we delete or irreversibly anonymize the requester's email address, IP addresses, browser User
Agent strings, and other user-linked analytics. We may retain information when required by law
or needed to establish, exercise, or defend legal claims. Deleted data may also remain temporarily
in secured backups until those backups expire or are overwritten, and will not be restored to
active use.
- Temporary Event Queue: Cloudflare D1 keeps acknowledged copies of session creation
events until they are older than 30 days, when they become eligible for cleanup. They may remain
longer if synchronization or cleanup is delayed or not running. Events that have not been successfully
transferred to PostgreSQL are not automatically deleted. For a verified erasure request, event
rows may be irreversibly anonymized in place rather than deleted when retaining their numeric
sequence is required to keep the synchronization log complete.
6. Glass Box Audit (Metadata Logging)
To ensure high reliability and to give you full transparency into the health of your sync
connections, we maintain a "Glass Box Audit" trail.
- What is Logged: We log only sync metadata, which includes timestamps, sender
domains, delivery status, and message sizes.
- Analytics Metadata: Operational logs do not contain email content or authentication
secrets. The separate analytics database stores the account and session metadata described in
Section 5, including email address, IP address, and User Agent.
- Operational Logs: The dashboard lets you view operational synchronization history
for your own mailbox connections. It does not expose every metadata or analytics record associated
with your account.
- Internal Analytics: The separate account and session analytics described in
Section 5 are available only to authorized personnel through Metabase for the stated analytics,
reliability, and security purposes.
7. Third-Party Services
We utilize trusted third-party infrastructure to deliver our service:
- Google Cloud (Gmail API): For delivering synchronized mail.
- Mailjet: For sending system notifications and error alerts.
- Stripe: For secure billing and subscription management.
- Neon.com: For metadata ingestion and dashboard visualization.
- Fly.io & Cloudflare: For dedicated hardware and network security.
8. Google API Disclosure
Our use and transfer to any other app of information received from Google APIs will adhere
to Google API Services User Data Policy, including the Limited Use requirements.
We do not use your Gmail data (including message content and metadata) to serve
advertisements or for any marketing purposes.
Important: We do not use, sell, or transfer your Gmail data for the purpose of
training or improving generalized Artificial Intelligence (AI) or Machine Learning (ML) models.