Privacy Policy
Last updated: 2026-08-31
Who we are
What we collect
- Your Google account email address and profile basics (returned by Google’s OpenID Connect userinfo endpoint when you sign in).
- A Google OAuth refresh token scoped strictly to
gmail.send. We use this only to send email on your behalf when you explicitly click Send. We request no other Gmail permission. - CSVs you upload: recipient email addresses and any additional columns you choose to use as merge tags. These are stored in our database so you can re-send or track status.
- Email campaigns you create: project name, subject, body, and per-recipient send status.
What we don’t do
- We don’t read, list, or search the Gmail you connect. We hold only
gmail.sendpermission, which cannot read your mailbox at all. - We don’t request
gmail.readonly,gmail.metadata,gmail.modify, or full mailbox access. - We don’t share your data with any third party for marketing or advertising.
- We don’t use your data to train any machine-learning model.
- We don’t sell your data.
How your Google data is used
gmail.send is used solely to deliver email you have composed and approved, to the recipients in the CSV you uploaded.
Mailroom’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to any other party except as necessary to provide this service, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security purposes, or where required by law.
How your data is protected
- All traffic is served over HTTPS (TLS 1.2+), and HSTS is enforced.
- Data is stored in Supabase (PostgreSQL), encrypted at rest by the provider.
- Your Google refresh token is held in a column that is readable only by the server. Database-level privileges on that column are revoked from the public and signed-in browser roles, so it cannot be read from the browser even with a valid session.
- Row-level security is enabled on every table, scoping each query to the signed-in user. Cross-account access is rejected at the database, not merely hidden in the interface.
- Access to the production database is limited to the operator, using credentials held server-side only and never shipped to the browser.
- Administrative access requires an explicit role grant tied to a named Google account. There is no shared administrative password.
Who else processes your data
- Google — sends your email, from your own account.
- Supabase — database hosting (all stored data).
- Vercel — application hosting; processes request metadata such as IP address and page URLs.
- PostHog (EU region) — product analytics. Receives your account email address and the pages and actions you take inside the app. It never receives your recipient lists or email content.
- Stripe — payment processing for Pro subscriptions. Receives your email address and billing details. Mailroom never sees or stores your card number.
- Slack — operational alerts to the operator only. Receives your account email address when you sign up, subscribe, or submit feedback. It never receives your recipient lists or email content.
None of these providers receives the contents of your Gmail mailbox, because Mailroom never has access to it.
Retention and deletion
- Campaigns, recipients and send history are kept until you delete them. Deleting a project immediately and permanently removes its recipients and send history.
- Your Google refresh token is deleted as soon as you disconnect that Gmail account in Mailroom, or revoke access at myaccount.google.com/permissions.
- Your account and all associated data are deleted within 30 days of a deletion request. Email aneeka32@gmail.com from the address you signed up with, and it will be actioned within 30 days.
- Analytics events are retained by PostHog for up to 12 months and then deleted automatically.
- Billing records are retained by Stripe for as long as legally required for tax and accounting purposes.
- Nothing is retained after account deletion except records we are legally required to keep.
Acceptable use: recipient consent is required
Users of Mailroom are prohibited from sending email to any contact who has not consented to receive sales or marketing communications from them. Mailroom may only be used to email people who have opted in, or who have a prior business relationship with the sender that makes the message expected: customers, subscribers, event attendees, or known contacts.
Sending to purchased, rented or scraped lists is prohibited. So is any other form of unsolicited commercial email. This is a breach of these terms and of Google’s Gmail API policies, and results in the account being closed.
This is enforced, not merely stated. Before any campaign can be sent or scheduled, the sender must confirm that every recipient on that list consented. The confirmation is recorded per campaign with a timestamp, and the server refuses to send without it.
Mailroom offers no email warm-up, sender rotation, deliverability-evasion or contact-scraping feature, and there are no plans to add any.