Privacy Policy
Last updated October 7, 2026
GmailFlow sends cold email sequences from your own Gmail account. This policy explains what personal data GmailFlow ("we", "us") collects, why we need it, how long we keep it, and what you can do about it.
It covers two groups of people. Customers are the people who sign up and run campaigns, alone or together in teams. Recipients are the people our customers email.
What we collect from customers
Your Google account
You sign in with Google. We store the name and email address on your Google profile, and your Google account ID, which tells us it's you the next time you sign in. We don't store your profile photo, and we never see your Google password.
Teams
Everything in GmailFlow happens in a team. When you sign up, you create a team of your own and choose its plan, or join a team you were invited to, and you can create more teams. A team's owner can invite people by email: we store the address invited and who sent the invitation, and email it a link that works for 7 days. Members of a team see each other's names and email addresses. The owner manages the team: its members, which of them can use each of its mailboxes, its plan and its billing.
Connected Gmail mailboxes
When you connect a mailbox, Google gives us access and refresh tokens that let GmailFlow work with it. We store those tokens encrypted, along with the mailbox address and the sync state we need to keep sending and checking for replies. The mailbox belongs to the team you connected it in, and the team's owner decides which of its members can use it (you can, to begin with). It stays with the team if you leave it.
Campaigns and contacts
We store what a team's members create in GmailFlow: campaigns, sequences, email templates, contact lists, and the contacts they add or import. A contact can hold an email address, a name, a company, a phone number, and any extra columns imported from a CSV file. All of it belongs to the team, whoever created it, and we record which member created each item. Members see the campaigns sent from the mailboxes they can use, and their own campaigns that have no mailbox; the owner sees all of them.
Billing
Each team has its own plan. Stripe processes payments, and we send it the team's name and its owner's email address. We keep the team's Stripe customer ID, its subscription status, its trial end date, and the brand and last four digits of its card. We never see or store a full card number.
Privacy choices
When you change a marketing or analytics preference in Privacy settings, we record the choice, the time, and the IP address and browser user agent you made it from.
Logs and cookies
Our servers log requests, including IP addresses, so we can keep the service running and investigate abuse.
GmailFlow sets a session cookie that keeps you signed in, a "remember me" cookie, a cookie that protects forms against cross-site request forgery, and a cookie that remembers whether you last signed in with Google or a password, so the sign-in page can remind you. We don't use analytics or advertising cookies. Our pages load their fonts and scripts from our own servers. The exception is the page where you confirm a card payment that your bank asks you to authenticate: it loads Stripe's payment script from Stripe, and its other scripts and styles from jsDelivr, so your browser sends your IP address to those services on that page.
Gmail data
GmailFlow asks Google for permission to send email from your mailbox and to read the headers of its messages. That permission doesn't reach what your messages say, so it can't read their content. It uses that access for three things:
- Sending. It sends the emails of the campaigns that use your mailbox from your address, so they show up in your Sent folder like any other email. When Gmail doesn't confirm that an email went out, it reads the Message-ID and subject headers of your recent sent emails to check before it sends again.
- Reply and bounce detection. When a message arrives in your inbox, it reads the headers (sender, recipients, subject, message IDs, and the headers that mark automatic replies and bounces) to tell whether a recipient replied, sent an out-of-office message, or bounced. It doesn't read or store the body of any message in your inbox.
- New mail notifications. It asks Gmail to notify it through Google Cloud Pub/Sub when new mail arrives, so replies stop a sequence within minutes.
For each email GmailFlow sends, we store the Gmail message and thread IDs, the subject, the sender and recipient, and when it went out. For a reply we store its message ID and when it arrived. For a bounce we store the bounce's subject line and the address that failed.
GmailFlow's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That means:
- We use Gmail data only to provide the features described above, all of which you can see in the app.
- We don't sell Gmail data or use it for advertising. We don't transfer it to anyone, except as needed to provide the service, to comply with the law, or as part of a merger or acquisition.
- We don't use Gmail data to train AI or machine learning models.
- Nobody at GmailFlow reads your Gmail data unless you ask us to, it's needed for security (such as investigating abuse), the law requires it, or it has been aggregated and anonymized for internal operations.
You can revoke GmailFlow's access at any time from your Google Account permissions. After that it can no longer send from or read that mailbox.
If you received an email sent with GmailFlow
The email came from one of our customers. That customer decided to contact you, wrote the email, and is responsible for having a lawful reason to email you. We process your data on their behalf.
We hold what the sender gave us, usually your email address and name, and sometimes your company, phone number or other details. We also record:
- When each email was sent to you, and whether you replied or it bounced. We store message IDs, not the content of your reply.
- If the sender turned on open or click tracking, when you opened the email, which links you clicked, your browser's user agent, and a keyed hash of your IP address. We don't store the IP address itself, and we don't look up your location.
- If you unsubscribe, your email address, the reason you gave if any, the time, and the IP address and user agent you unsubscribed from.
Every email carries unsubscribe headers, which most email apps show as an Unsubscribe button, and many senders also put an unsubscribe link in the email. Unsubscribing stops all further email from the sender's team through GmailFlow, whichever of its campaigns or mailboxes would have sent it. To find out what a sender holds about you, or to have it deleted, contact the sender.
How we use data
- To run the service: sending campaigns on schedule, detecting replies and bounces, stopping sequences, and showing reports.
- To bill teams through Stripe.
- To send you emails about your account and your teams, such as invitations, data export links, and notices when a team you're in is deleted.
- To keep the service secure and to prevent spam and abuse.
- To meet our legal obligations.
We send you marketing email only if you opt in from Privacy settings. Where the GDPR applies, we rely on our contract with you to provide the service, on your consent for marketing, and on our legitimate interest in keeping the service secure.
Who we share data with
We don't sell personal data. We share it with the providers that run parts of the service for us, and each gets only what it needs:
- Google, for sign-in, the Gmail API and new mail notifications.
- Stripe, for payments.
- Sentry, for error monitoring. When something fails, Sentry gets a report with the error, the page or background job involved, and recent log lines, which can include email addresses. Reports leave out form contents, cookies and visitors' IP addresses.
- Our hosting providers, which run our servers, database, file storage and backups.
- Our email delivery provider, which sends account emails such as export links.
We may also disclose data when the law requires it, or to a buyer if GmailFlow is sold or merged. If that happens, we'll tell you before your data falls under a different privacy policy.
How long we keep data
- Your account stays until you delete it. A team's campaigns, contacts and everything else in it stay until they're deleted or the team is.
- An invitation stays until it's accepted or cancelled, or its team is deleted.
- Records of sent emails are deleted after 365 days, unless their campaign is still running.
- Open and click events are deleted after 365 days.
- Data exports are deleted after 7 days, when their download links expire.
- Application logs are deleted after 14 days, and security logs after 90 days.
- Backups are deleted after 30 days.
When a team's owner deletes it, we cancel its subscription, disconnect its mailboxes and delete their tokens, and immediately delete its campaigns, sequences, templates, contacts, lists, sent email records and unsubscribe records. We also ask Google to revoke GmailFlow's access to each mailbox, unless another team still has the same mailbox connected. Its members lose access and get an email saying so.
When you delete your account:
- If you own a team that has other members, you first make one of them its owner or delete the team.
- Every team you own alone is deleted, as above.
- You leave the other teams you're in. What you created there, mailboxes you connected included, stays with those teams and is no longer linked to you, and each team's owner is told which mailboxes you connected.
- We delete the CSV files you imported, your privacy choices and your notifications.
- We anonymize your account record straight away and delete it for good after 30 days.
Copies in backups are gone within 30 days. Stripe keeps billing records for as long as the law requires.
Security
We encrypt Gmail access and refresh tokens in our database, and we store tracking IP addresses only as keyed hashes. No service is perfectly secure. If a breach affects your data, we'll tell you and the relevant authorities as the law requires.
Your rights
From Privacy settings in your account you can export your own data: your account, your privacy choices and the teams you're in. You can delete your account there or from your Account page. A team's owner can export the team's data (its members, mailboxes without their tokens, contact lists, contacts, templates, sequences, campaigns, sent and received email records with their open and click counts, and unsubscribes), and delete the team, from its settings. You can correct your details and your contacts in the app. Depending on where you live, you may also have the right to object to or restrict how we process your data, to withdraw consent, and to complain to your data protection authority.
International transfers
We and our providers may process data in countries other than yours. Where the GDPR applies, those transfers rely on safeguards such as the European Commission's standard contractual clauses.
Children
GmailFlow is a business tool for people 18 and over. We don't knowingly collect data from children.
Changes to this policy
When we change this policy, we update the date at the top. If a change is significant, we'll email you before it takes effect.
Contact
To export or delete your data, use Privacy settings in your GmailFlow account. A team's owner exports or deletes the team from its settings.