Privacy policy
What Mail Pounder stores,
and for how long.
Effective August 1, 2026
Data we collect
Mail Pounder stores the identity email and display name used to set up Mail Pounder, the profile details of Google accounts you link, and encrypted Google OAuth access and refresh tokens. It never receives or stores your Google password.
Diagnostic logging is optional and disabled by default. If you enable it, Mail Pounder records OAuth flow stages and MCP tool-call events. OAuth diagnostics include stage names, a one-way flow identifier, callback origin and path, client type, timestamps, and success or error status; authorization codes, state values, PKCE material, and tokens are not stored in these logs. Tool logs may contain the Mail Pounder user email, linked Google account identifier, OAuth client identifier, tool name, timestamp, duration, success or failure status, tool arguments, a size-limited result excerpt, and an error message.
The public homepage shows only the aggregate number of Mail Pounder users with at least one linked Google account. It does not expose names, email addresses, account counts by user, or activity.
How we use it
Account and token data is used to operate Drive, Docs, Sheets, Slides, and Gmail tools for the signed-in user. When you enable operational logs, they are used to diagnose failed calls, investigate reliability problems, and improve the service. We do not sell this data or use it for advertising.
Isolation and security
Every MCP OAuth grant is bound to one Mail Pounder identity and snapshots only the Google accounts listed when you approve it. Accounts linked later are not added to an existing grant automatically. Google tokens are encrypted at rest, MCP access tokens are stored as hashes, and credential-like fields are redacted from optional operational logs.
When you request a Drive export or Gmail attachment, Mail Pounder temporarily stores the encrypted-in-transit file bytes in private object storage solely to create an unguessable download link. The link expires after 15 minutes, is served with private no-store headers, and expired objects are deleted automatically. File bytes and download URLs are not retained in diagnostic logs.
Retention and deletion
When enabled, operational logs expire seven days after creation and are automatically purged during normal server operation. Turning logging off immediately deletes your existing operational and OAuth diagnostic logs. Removing a linked Google account deletes its encrypted tokens, active MCP grants that use it, pending grants, and associated operational logs.
Access and contact
Operational logs are available only to an explicitly configured Mail Pounder administrator. To ask about your data or request deletion, contact maxweinbach5@gmail.com.