EmailSlimEmailSlim processes email metadata through Google and Microsoft email APIs to show you storage usage patterns. We never access, read, store, or analyze the actual content of your emails—only the information needed to help you understand what's using your storage space.
When you sign in with Google or Microsoft, you're using OAuth—a secure way to grant EmailSlim permission to access your email account. We request two specific permissions (same for both providers):
This lets us see sender, date, size, and labels—but NOT the content of your emails
This lets us move emails to Trash (Gmail) or Deleted Items (Outlook) when you explicitly request deletion
These are the minimum permissions needed to show you storage usage and help you delete emails. We don't request permission to read your email content, and we never access it.
When you choose to delete emails through EmailSlim, here's exactly what happens:
EmailSlim shows you which emails will be deleted before any action is taken
Nothing happens until you click the delete button and confirm
Gmail: moved to Trash. Outlook/Hotmail/Microsoft 365: moved to Deleted Items. Not permanently deleted.
Gmail: 30 days in Trash. Outlook: recovery period varies by account; you can restore from Deleted Items.
Important: EmailSlim never permanently deletes emails. All deletions go through your provider's Trash or Deleted Items, where you can recover them within the provider's retention period.
You're always in control. You can revoke EmailSlim's access to your email account at any time:
Go to your Google Account → Security → Third-party apps → Remove EmailSlim access
Go to account.microsoft.com → Privacy → Apps and services → Remove EmailSlim access
You can disconnect your email account from within EmailSlim's settings page
You can delete your EmailSlim account at any time, which removes all stored data
When you revoke access, EmailSlim immediately stops accessing your email account. Any metadata we've already processed remains stored until you delete your account, but we stop accessing new data as soon as you revoke permission.
No. We never read your email content. We only access metadata (sender, date, subject length, size). We don't have permission to read email content, and we never request it.
No. We don't sell, rent, or trade your personal information. We only share limited data with trusted service providers (like Google and Microsoft for email API access, and Stripe for payments) as necessary to provide our service. Your email metadata is never shared with marketers, advertisers, or other services.
No. All deletions require your explicit approval. We never delete anything automatically without your consent. You review what will be deleted, then explicitly approve the action. All deleted emails go to Trash (Gmail) or Deleted Items (Outlook) first, where they can be recovered within the provider's retention period.
Yes. You can revoke EmailSlim's access to your email account at any time through Google Account settings or Microsoft account settings. When you remove access, we immediately stop accessing your account. You can also delete your EmailSlim account at any time, which removes all stored data.
For complete legal details, see the sections below. This information is required for Google App verification and compliance with privacy regulations.
When you sign in with Google, we collect: email address, display name, profile photo (optional), and Google account ID for authentication and account linking.
When you sign in with Microsoft (Outlook.com, Hotmail, Microsoft 365), we collect: email address, display name, profile photo (optional), and Microsoft account ID for authentication and account linking.
We process the following email metadata through the Gmail API (Google) or Microsoft Graph (Outlook, Hotmail, Microsoft 365):
To identify email sources and group by sender
For search functionality and basic categorization
For chronological organization and cleanup recommendations
To calculate storage usage and cleanup potential
To assess email engagement patterns
To understand email organization and importance
To identify storage-heavy emails (attachment content NOT accessed)
IMPORTANT: We never access, read, store, or analyze the actual content of your emails. Only metadata is processed to provide cleanup recommendations.
Feature usage, scan frequency, cleanup actions taken
Response times, error rates (to improve service quality)
For compatibility and security purposes
For security monitoring and service optimization
For premium subscriptions, we collect payment information through Stripe:
Processed securely by Stripe, we only store transaction IDs
To manage access to premium features
When you contact us or submit feedback
Settings and customizations you choose
We use the collected information for the following purposes:
EmailSlim's use of information received from Gmail APIs adheres to the Gmail API Services User Data Policy, including the Limited Use requirements.
We request the following minimal Gmail API permissions:
Read email metadata only (sender, subject, date, size) — NOT email content
Move emails to Trash or perform other actions only when you explicitly request deletion
We never read, store, or analyze email body content
Gmail data is not sold, shared with third parties, or used for advertising
Gmail data is used solely for email management and cleanup features
All Gmail actions require explicit user consent and initiation
All Gmail metadata is encrypted in transit and at rest
Only authorized systems can access your Gmail metadata
We conduct regular security reviews of our Gmail API usage
EmailSlim's use of information received from Microsoft Graph adheres to the Microsoft API Terms of Use and Microsoft's data handling requirements for application access to mail data.
We request the following minimal Microsoft Graph permissions for mail:
Read email metadata only (sender, subject, date, size) — NOT email content beyond what is needed for storage analysis
Move emails to Deleted Items or perform other actions only when you explicitly request deletion
We never read, store, or analyze email body content
Microsoft mail data is not sold, shared with third parties, or used for advertising
Microsoft mail data is used solely for email management and cleanup features
All mail actions require explicit user consent and initiation
All mail metadata is encrypted in transit and at rest
Only authorized systems can access your mail metadata
We conduct regular security reviews of our Microsoft Graph usage
Secure, encrypted cloud database hosted by Google
Data stored in Google's secure data centers with enterprise-grade security
Data stored in the United States with appropriate safeguards
All data transmitted using HTTPS/TLS encryption
All stored data encrypted using industry-standard encryption
Multi-factor authentication and role-based access controls
Systems regularly updated with latest security patches
Continuous monitoring for security threats and unauthorized access
Each user's data is logically separated and isolated from other users. We implement strict access controls to ensure users can only access their own data.
We do not sell, rent, or trade your personal information. We may share limited data with trusted service providers in the following circumstances:
For authentication, data storage, and Gmail API access
For authentication and Microsoft mail API access (Outlook, Hotmail, Microsoft 365)
For payment processing (they handle all payment data securely)
For displaying relevant ads to trial users (anonymized data only)
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety, or that of our users or the public.
In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the business assets, subject to the same privacy protections.
To help improve email quality for everyone, we may share anonymized, aggregated email engagement data with brands for marketing research. This data:
No names, emails, or identifying details
Only aggregated statistics across thousands of users
By showing brands what works and what doesn't
For all users by helping brands send better emails
Examples of shared data: Average open rates by brand domain, subject line performance (anonymized), send frequency analysis, geographic engagement patterns.
You can opt-out of this data sharing anytime in your account settings.
Access all data we have about you through your account dashboard
Modify your profile information and preferences at any time
Export your email metadata and account information
Permanently delete your account and all associated data
Remove EmailSlim's access to your email account at any time through Google Account settings or Microsoft account settings
We only request the minimum permissions necessary for our service (read metadata, modify only when you approve)
Control which emails you receive from us
Opt out of promotional emails (service emails may still be sent)
Opt out of usage analytics collection in your privacy settings
Choose whether to share performance analytics to help improve the service
We retain your data for as long as your account is active and as necessary to provide our services.
When you delete your account, all data is permanently removed within 30 days
Accounts inactive for 24 months may be deleted after notification
Some data may be retained longer if required by law, to resolve disputes, or enforce agreements.
Data may persist in backups for up to 90 days after deletion for disaster recovery purposes, but is not accessible during this time.
Required for secure login and session management
Store your settings and customizations
Understand how users interact with our service (can be disabled)
Monitor service reliability and performance
Trial users may see ads served by Google AdSense, which may use cookies for ad personalization. Premium users see no ads.
You can control cookies through your browser settings. Note that disabling essential cookies may affect service functionality.
EmailSlim is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete such information promptly.
Parents who believe their child has provided us with personal information should contact us immediately at the email address provided below.
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.
Significant changes will be communicated via email
Changes will be highlighted when you next use the service
Updated policies will be posted on our website
Changes become effective 30 days after notification, unless immediate changes are required by law. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: privacy@emailslim.com
Response Time: We aim to respond to privacy inquiries within 72 hours
Data Protection Officer: Available for GDPR-related inquiries
If you are located in the European Union or United Kingdom, you have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.
This Privacy Policy was last updated on January 15, 2024
© 2024 EmailSlim. All rights reserved.