MailHub privacy policy
Effective 26 September 2026.
MailHub is a personal tool. It is built and used by one person, Mohammed Afzal Imam, for his
own email accounts. It is not offered to the public, and no one else can sign in to it.
What MailHub accesses
When I connect one of my own Gmail accounts, MailHub asks Google for read-only access to
that mailbox (the gmail.readonly permission). It cannot send, change or delete email. Outlook
accounts, when connected, get the equivalent read-only permission from Microsoft.
What MailHub stores
- Message details only: sender, recipients, subject, a short preview, dates, and folder and label names, plus the category and priority MailHub assigns.
- Never the message body or attachments. They are fetched from Google or Microsoft only when I open a message, shown, and not saved.
- The access token that lets MailHub read the mailbox, stored encrypted.
Where it is stored and who can see it
- On a private server I operate, in Germany. Only I can sign in, protected by a second login in front of the app and by passkeys in the app itself.
- Nightly backups are encrypted before they leave the server and are kept for 7 days.
- No one else reads the data. It is not sold, shared, used for advertising, or used to train AI or machine-learning models.
Google API Services User Data Policy
MailHub's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Keeping and deleting data
- Disconnecting an account in MailHub revokes its access token at Google or Microsoft and deletes all stored details for that account.
- Automatic deletion of message details older than 365 days is planned; until it is in place, details are kept while the account stays connected.
- Access can also be removed at any time from the Google account at myaccount.google.com/permissions.
Contact
Changes
If this policy changes, the new version is published on this page with a new effective date.