Privacy Policy

Last updated: September 2026

1. What EmailRefresh does

EmailRefresh connects to your Gmail, Microsoft (Outlook), or Yahoo Mail account to help you scan, sort, and clean up your inbox — categorizing mail, archiving or deleting on your instruction or by rules you set, and (optionally) using AI to summarize and categorize messages.

2. Information we collect

  • Account information — your name and email address, provided by Google, Microsoft, or Yahoo when you connect a mailbox.
  • Authorization credentials — an OAuth access/refresh token (Google, Microsoft) or an app-specific password (Yahoo), used solely to access your mailbox on your behalf. These are encrypted (AES-256-GCM) before being stored and are never visible to us in plain text.
  • Email metadata and content — sender, subject, timestamps, and message snippets, read from your mailbox to build the inbox view, sender summaries, and AI categorization. We do not permanently store full email bodies; they are fetched live from your provider each time you view them.
  • Your settings — automation rules, VIP-shielded senders, digest preferences, and similar configuration you create in the app.
  • Usage and activity records — a log of actions the app takes on your mailbox (archived, deleted, marked read) so you can review or restore them, and lightweight usage counters for plan limits and support.
  • Support requests — anything you submit through the in-app support form.

3. How we use AI categorization

To categorize a message (e.g. Work, Finance, Newsletter), we send the sender's domain, the subject line, and a short preview of the message to Google's Gemini API for classification. We do not send full email bodies or attachments. A sender's category is cached for up to 30 days so the same sender isn't re-classified on every message; this cache is not tied to any one user's identity.

4. Who we share data with

We don't sell your data. Data is shared only as needed to run the service:

  • Google, Microsoft, and Yahoo — to authenticate you and access your mailbox.
  • Google Gemini — to categorize and summarize messages, as described above.
  • Our infrastructure providers (hosting, database, and background job processing) — to run the application. They process data on our behalf and don't use it for their own purposes.

5. Data retention

We retain your account data and settings for as long as your account is connected. If you disconnect a mailbox, its stored access credentials are deleted. You can also revoke EmailRefresh's access at any time directly from your Google, Microsoft, or Yahoo account security settings — this immediately invalidates our access even if you don't remove the connection in EmailRefresh first. We do not use private email content for advertising purposes. Email data is accessed solely to provide the functionality you request, and EmailRefresh does not sell user email data.

6. Security

All connections to EmailRefresh use TLS encryption in transit. Access tokens and app passwords are encrypted at rest (AES-256-GCM) before being stored. Access to the underlying database and infrastructure is restricted to the engineering team operating the service.

7. Your choices

  • Disconnect any mailbox at any time from Connected Accounts in the app.
  • Turn off AI categorization, automation rules, or digest emails at any time.
  • Request deletion of your account and associated data by contacting us (see below).

8. Changes to this Privacy Policy

We will update this Privacy Policy periodically as the product develops. Changes become effective when posted on this page, with an updated revision date above.

We may use trusted third-party vendors for:

  • Hosting our domain and infrastructure.
  • Authentication, via the Google, Microsoft, and Yahoo APIs.
  • Analytics.
  • Payment processing, for subscribed users (once billing is active).

9. Contact

Questions about this policy or your data can be sent through the in-app Support form under Settings, or to info@emailrefresh.com.