← Back to StackMail

Privacy Policy

Last updated: August 1, 2026

StackMail ("we", "our") provides a unified email inbox with optional AI-assisted triage. This policy explains what data we collect, why, and how it's protected.

How you sign in

You create a StackMail account with an email address and a password. Passwords are stored only as bcrypt hashes (cost 12) — we cannot read them, and we never receive or store the password for your Google account.

What we access

StackMail does not ship a Google OAuth client of its own. To connect a mailbox you register your own OAuth client, created in your own Google Cloud project, and paste its credentials into StackMail. Consent is therefore granted by you, to an application you own, and it is revocable by you at any time. The connection requests only the gmail.readonly and gmail.send scopes: enough to display your inbox, and to send a message only when you explicitly click "Send" on a reply you wrote. StackMail never sends mail without your direct action.

What we store

  • Your email address, and a bcrypt hash of your password.
  • The client ID and client secret of the Google OAuth client you registered. The secret is encrypted at rest and is never displayed back to you or returned by any API response.
  • The Gmail OAuth refresh token for each mailbox you connect, encrypted at rest, used only to sync that mailbox.
  • Copies of message metadata and body text for messages in your connected mailbox, so the inbox can be searched and triaged without re-fetching from Gmail on every view.
  • Categories, tags, rules, and priorities you or StackMail's AI assign to senders and messages.
  • If you provide one, your Anthropic API key, encrypted at rest. This key is used solely to make AI requests on your behalf when you use AI features. StackMail does not have or use a shared AI key on your behalf.

What we never do

  • We never sell your data or use your mailbox content to train models.
  • We never access another user's mailbox, messages, or API key. Every table in our database is scoped to your account, and our database credentials are restricted to the StackMail database only.
  • We never send email on your behalf without you clicking Send.

Data retention & deletion

You can disconnect any mailbox from Settings, which deletes its stored token and its message copies immediately. Settings → Delete account removes your account and everything stored against it — mailboxes, tokens, message copies, senders, rules and keys — in a single irreversible action; nothing is retained in a soft-deleted state. You can additionally revoke the app's access from your own Google account at myaccount.google.com/permissions.

Third parties

Message sync uses the Gmail API. AI features, when enabled, call the Anthropic API using the key you provide directly — your key and prompts are sent to Anthropic under Anthropic's own terms, not shared with any other party.

Contact

Questions about this policy: privacy@stackmail.app.