Privacy Notice
Last updated August 2026. This app is currently in private testing, not a public launch.
What we access
With your permission, we request read-only access to your Gmail account (gmail.readonly). We only ever request message metadata: the From header, the Date header, and the List-Unsubscribe / List-Unsubscribe-Post headers. We never request write, send, or delete access to your mailbox, and we never fetch message bodies.
What we store
For each sender that included an unsubscribe header, we store their name, email address, and domain. When you unsubscribe or send a data-rights request, we store a permanent record of that action (who, when, which method, and its status) so we can tell you if a company emails you again afterward. Full detail on exactly which fields are stored is on the how we protect your data page.
Who can see it
Only your account can read your data through the app. Every table is scoped by row-level security tied to your Supabase login, so no other user can query your data through the app, even by accident. The project owner does retain administrative database access through Supabase's own dashboard, the same way any hosting provider or SaaS operator technically can. We don't use that access to look at your data outside of debugging something you've reported.
Third parties involved
Google (Gmail API, for reading your inbox), Supabase (authentication and database hosting), Vercel (application hosting), and Web3Forms (delivering messages sent through the contact form). None of these receive your inbox contents; each only receives what's necessary for its specific role.
Your rights over your own data
You can export everything we store about you, or delete it entirely (including disconnecting Gmail), from the Danger Zone in Settings. Deleting your data does not delete your login itself. You can sign back in afterward and start clean.
Questions
Reach out through the contact form.