Privacy Policy
1. What MailWand Is
MailWand is an AI-native email client that transforms high-volume inboxes into structured, adaptive workflows. It connects to your email accounts (Gmail and Outlook), automatically groups and classifies your messages, surfaces priorities, and replaces chronological threads with optimized views for different communication types — enabling faster action, easier retrieval, and better relationship management.
2. Information We Collect
Account information
When you sign in with Google or Microsoft, we receive your name, email address, and profile picture through OAuth. We also store OAuth access tokens and refresh tokens so we can access your email on your behalf.
Email data
We fetch email metadata (sender, recipient, subject, date, labels, folder, read status, and headers) and email body content from the Gmail API and Microsoft Graph API. Attachment metadata (filename, type, size) is also collected; attachment content is only fetched when you explicitly request it.
Workspace data
Classification rules, categories, and extracted table data that you create within MailWand are stored on our servers.
Client-side cache
Email content is cached in your browser's IndexedDB storage to improve performance. This data stays on your device and is not sent to our servers.
3. How We Use Your Data
- Fetching and displaying emails — we use Gmail
API (
gmail.modifyscope) and Microsoft Graph API (Mail.ReadWritescope) to read your messages and perform actions you request (archive, mark as read). - Code-based classification (Tier 1) — emails are classified using pattern-matching rules that run entirely on our server. No third parties are involved.
- AI classification (Tier 2) — email metadata (sender, subject, and a preview of the body up to 300 characters) is sent to OpenAI for sender-group classification.
- AI data extraction — when you use table mode, full email content (sender, recipient, subject, date, and body) is sent to OpenAI for structured data extraction.
- Email actions — when you archive an email or mark it as read in MailWand, we write that change back to your actual mailbox.
4. Third-Party Services
We share your data with the following third-party services solely to provide MailWand's features:
- Google — OAuth authentication, Gmail API
- Microsoft — OAuth authentication, Microsoft Graph API (Outlook)
- OpenAI — AI-powered email classification and structured data extraction. Email content is sent to OpenAI's API for processing.
Data sent to OpenAI via their API is used solely for real-time processing and is not used by OpenAI to train their global models, in accordance with OpenAI's API data usage policies.
We do not sell your data to any third party. We do not use your data for advertising.
5. Data Storage and Retention
- Server-side — workspace configurations, classified email tracking data, extracted table data, and OAuth tokens are stored in MongoDB.
- Client-side — email content is cached in your browser's IndexedDB. Clearing your browser data removes this cache.
- Deletion — if you delete your account, we will remove all server-side data associated with it. Client-side cached data must be cleared through your browser.
6. Google API Limited Use Disclosure
MailWand's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use data obtained through Google APIs to provide and improve email classification features within MailWand.
- We do not transfer Google user data to third parties except as necessary to provide the service (OpenAI for classification), with user consent, or as required by law.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read your Google user data unless you provide affirmative consent, it is necessary for security purposes, or it is required by law.
7. Your Rights
- Access and export — you can request a copy of the data we hold about you.
- Deletion — you can request deletion of your account and all associated data.
- Revoke access — you can disconnect MailWand from your Google or Microsoft account at any time through their respective account settings.
8. Security
We use HTTPS for all data in transit. OAuth tokens are stored server-side and never exposed to the client. We follow industry standard practices to protect your data, but no method of transmission or storage is 100% secure.
9. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date at the top of this page. Continued use of MailWand after changes constitutes acceptance of the revised policy.
10. Contact
If you have questions about this privacy policy or your data, please reach out through our contact page.