Last updated: August 1, 2026
StackMail ("we", "our") provides a unified email inbox with optional AI-assisted triage. This policy explains what data we collect, why, and how it's protected.
You create a StackMail account with an email address and a password. Passwords are stored only as bcrypt hashes (cost 12) — we cannot read them, and we never receive or store the password for your Google account.
StackMail does not ship a Google OAuth client of its own. To connect a mailbox you register your own OAuth client, created in your own Google Cloud project, and paste its credentials into StackMail. Consent is therefore granted by you, to an application you own, and it is revocable by you at any time. The connection requests only the gmail.readonly and gmail.send scopes: enough to display your inbox, and to send a message only when you explicitly click "Send" on a reply you wrote. StackMail never sends mail without your direct action.
You can disconnect any mailbox from Settings, which deletes its stored token and its message copies immediately. Settings → Delete account removes your account and everything stored against it — mailboxes, tokens, message copies, senders, rules and keys — in a single irreversible action; nothing is retained in a soft-deleted state. You can additionally revoke the app's access from your own Google account at myaccount.google.com/permissions.
Message sync uses the Gmail API. AI features, when enabled, call the Anthropic API using the key you provide directly — your key and prompts are sent to Anthropic under Anthropic's own terms, not shared with any other party.
Questions about this policy: privacy@stackmail.app.