Privacy policy
DRAFT — pending legal review. This text was written by the engineering team to describe the service honestly and will be replaced by a reviewed version before the public launch. It does not yet name the legal entity, the data-protection contact or the supervisory authority.
Last updated: 8 September 2026 (draft).
What MailBridge is
MailBridge imports mail from POP3 and IMAP mailboxes that you own into your Gmail account. To do that it needs a small amount of data about you and about each source mailbox. This page lists all of it.
Use of Google user data (Limited Use disclosure)
MailBridge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail access only to add messages you have chosen to import. We do not read your Gmail, do not store message content, do not use it for advertising or analytics, and do not allow humans to access it except for security investigation or with your consent.
Concretely, MailBridge requests two Gmail permissions: gmail.insert, used solely to add each original message to your mailbox through Gmail's import operation, and gmail.labels, used to create the label that marks imported mail. It never requests permission to read, search, modify, send or delete existing Gmail data, and the service has no code path that could do so. Signing in uses a separate, standard Google sign-in grant (your Google account id, e-mail address and display name).
What we store
- Your account: Google account id, e-mail address, display name, sign-in times, the status of the Gmail connection (connected, disconnected, revoked), the date and scopes of the Gmail grant, and an encrypted Gmail refresh token.
- Each source you add: label, protocol, host name, port, TLS mode, user name, an encrypted copy of the password, your settings (polling interval, spam handling, delete-from-source consent and grace period), state, counters and the last error category.
- Import bookkeeping: for every message seen at a source, an identifier of that message (the POP3 UIDL or IMAP UID, not the message itself), its size, the import state and, after a successful import, the Gmail message id. This is what prevents duplicates.
- Job history: when each sync ran, how long it took, how many messages were imported, skipped or failed, and error categories.
- Sessions: a hashed session identifier, creation and expiry times.
- Operational logs (90 days): request identifiers, timings, error categories, pseudonymous references, and the IP address each request came from — used to apply rate limits and to investigate abuse. Log lines never contain passwords, tokens, message content, or a host name together with a user name; e-mail addresses are masked automatically.
What we never store
- Message content. Each message exists only in the memory of one short-lived process while it is copied from the source to Gmail, and is discarded as soon as Gmail has accepted it. There is no spool, no cache and no backup of mail.
- Plaintext passwords or tokens. Secrets are encrypted with a hardware-backed key before they are written; only the component that performs a sync can decrypt them, for that sync only.
- Anything from your Gmail account other than the ids of the messages and labels MailBridge itself created there.
How your data is used
Only to provide the service: to connect to the source mailbox you configured, to add mail to your Gmail account, to show you the state of the import, and to detect abuse or security problems. There is no advertising, no profiling and no sale or sharing of data.
Delete-from-source
MailBridge can delete messages from a POP3 source after they have been imported, but only if you switch this on for that source and confirm an explicit consent text. It is off by default, is never applied to IMAP sources, is never applied during the first verification pass, and is only applied to a message once Gmail has confirmed the import with a message id. You can switch it off at any time. Messages already deleted from the source cannot be restored by MailBridge; they remain in your Gmail account.
Where data is processed
On Amazon Web Services in the European Union (Ireland region). Google is contacted only to sign you in and to add messages to your Gmail account. Your source mailbox provider is contacted only with the credentials you supplied. No other third party receives your data.
Retention and deletion
- Your account, sources, bookkeeping, job history and sessions exist until you delete them. Removing a source deletes its bookkeeping and history; deleting your account deletes everything listed above.
- Deleting your account first destroys the encrypted secrets, then revokes the Gmail grant at Google (if Google is reachable), then removes every remaining record. You receive an anonymous receipt (kept 30 days) that shows the progress and completion of the deletion. Mail already imported into Gmail stays in Gmail, under your control.
- The private alpha runs without database backups: point-in-time recovery is switched off, so no copy of your data survives a deletion in a backup. When backups are switched on for the production service they will be kept for 35 days for disaster recovery only, not used for anything else and not accessible to the application.
- Operational logs are kept for 90 days; audit records of key usage are kept as required by our infrastructure provider's audit trail.
Your rights
You can export the data MailBridge holds about you as a JSON document from the Account page — your account, your sources and their settings, your recent sync history and per-source message counts — and you can delete your account there without contacting anyone. If you are in the EU/EEA or the UK you also have the rights to access, rectify, restrict and object under the GDPR; the contact details for exercising them will be added when the legal review is complete.
Cookies
MailBridge uses two cookies, both essential: a session cookie after you sign in, and a short-lived cookie that protects the sign-in flow against forgery. No tracking or analytics cookies are used.
Changes
This draft will change during the legal review. Material changes after launch will be announced in the app before they take effect.