Privacy Policy
1 Information We Collect
Mass Email PRO is designed with a privacy-first approach. We collect minimal information to provide the service:
- Email credentials (SMTP mode): Server address, port, and password entered in the SMTP form. These are held only in your browser session and are never written to a database.
- Contact list data: Excel or CSV files you upload are parsed entirely in your browser. No contact data is transmitted to or stored on our servers.
- Email content: Subject lines, body text, and attachments are sent to your mail server (SMTP or Gmail API) only at the moment of sending. We do not retain copies.
- Server logs: Standard web server access logs (IP address, request path, timestamp) may be retained for up to 30 days for security and debugging.
2 How We Use Your Information
We use information you provide solely to deliver the service:
- Authenticate your email session (SMTP login or Google OAuth token exchange)
- Transmit emails on your behalf to your recipients via Gmail API or your SMTP server
- Display your connected account email address in the app interface
We do not sell, rent, or share your personal data with any third party for marketing or advertising purposes.
3 Google OAuth & Gmail API
When you connect your Google Account via OAuth 2.0:
- We request only the gmail.send scope (send email on your behalf) and userinfo.email (to display your email address).
- Your Google access token is stored in a secure, temporary server-side session and used exclusively to call the Gmail API send endpoint.
- We do not read, scan, index, or store the contents of your Gmail inbox.
- We do not share your Google credentials or access token with any third party.
- Your token is discarded when your browser session ends or when you click "Disconnect".
- You can revoke access at any time at myaccount.google.com/permissions.
4 Data Storage & Security
- All traffic between your browser and our server is encrypted via HTTPS/TLS.
- SMTP passwords and OAuth tokens are never written to persistent storage.
- Contact lists and email content exist only in your browser's memory during your session.
- We use HTTP security headers (X-Frame-Options, X-Content-Type-Options) to protect against common web vulnerabilities.
Despite these measures, no internet transmission method is 100% secure. We encourage the use of strong, unique App Passwords rather than your primary account password.
5 Third-Party Services
- Google APIs (Gmail, OAuth 2.0): Governed by Google's Privacy Policy.
- Google Fonts: Font files loaded from Google servers. Google may log request metadata per their privacy policy.
- jsDelivr CDN: JavaScript libraries loaded from jsDelivr. No personal data is shared beyond standard HTTP request logs.
6 Cookies & Local Storage
- Session cookie: A secure, HTTP-only cookie maintains your authentication state during your visit. It expires when you close your browser.
- LocalStorage — theme preference: Your light/dark mode preference is saved locally. No personal information is stored here.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
7 Your Rights
Because we do not store personal data in a database, most data rights requests are satisfied automatically. However:
- To revoke Google OAuth access, visit myaccount.google.com/permissions.
- To request deletion of server logs containing your IP address, contact us at satbirsingh.dev@gmail.com.
8 Children's Privacy
Mass Email PRO is not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
9 Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of Mass Email PRO after changes constitutes acceptance of the updated policy.
10 Contact
- Email: satbirsingh.dev@gmail.com
- Response time: We aim to respond within 5 business days.