EmailSlimEmailSlim

Your Data is Yours — How EmailSlim Uses Email Access

Last Updated: January 15, 2024

What We Access

We only analyze metadata (sender, date, subject length). We do NOT read your email content.

EmailSlim processes email metadata through Google and Microsoft email APIs to show you storage usage patterns. We never access, read, store, or analyze the actual content of your emails—only the information needed to help you understand what's using your storage space.

Why We Need Permissions

OAuth is required to scan metadata and perform deletions you approve.

When you sign in with Google or Microsoft, you're using OAuth—a secure way to grant EmailSlim permission to access your email account. We request two specific permissions (same for both providers):

  • Read email metadata

    This lets us see sender, date, size, and labels—but NOT the content of your emails

  • Modify emails (when you approve)

    This lets us move emails to Trash (Gmail) or Deleted Items (Outlook) when you explicitly request deletion

These are the minimum permissions needed to show you storage usage and help you delete emails. We don't request permission to read your email content, and we never access it.

Deletions Explained

Deletions go to Trash (Gmail) or Deleted Items (Outlook) — you can recover them.

When you choose to delete emails through EmailSlim, here's exactly what happens:

  • 1. You review what will be deleted

    EmailSlim shows you which emails will be deleted before any action is taken

  • 2. You explicitly approve the deletion

    Nothing happens until you click the delete button and confirm

  • 3. Emails go to Trash or Deleted Items

    Gmail: moved to Trash. Outlook/Hotmail/Microsoft 365: moved to Deleted Items. Not permanently deleted.

  • 4. You can recover them

    Gmail: 30 days in Trash. Outlook: recovery period varies by account; you can restore from Deleted Items.

Important: EmailSlim never permanently deletes emails. All deletions go through your provider's Trash or Deleted Items, where you can recover them within the provider's retention period.

Control & Revocation

You can remove access via Google or Microsoft account settings anytime.

You're always in control. You can revoke EmailSlim's access to your email account at any time:

  • Through Google Account Settings

    Go to your Google Account → Security → Third-party apps → Remove EmailSlim access

  • Through Microsoft Account Settings

    Go to account.microsoft.com → Privacy → Apps and services → Remove EmailSlim access

  • Through EmailSlim Settings

    You can disconnect your email account from within EmailSlim's settings page

  • Delete Your Account

    You can delete your EmailSlim account at any time, which removes all stored data

When you revoke access, EmailSlim immediately stops accessing your email account. Any metadata we've already processed remains stored until you delete your account, but we stop accessing new data as soon as you revoke permission.

Common Questions

Can we read your emails?

No. We never read your email content. We only access metadata (sender, date, subject length, size). We don't have permission to read email content, and we never request it.

Do we share data?

No. We don't sell, rent, or trade your personal information. We only share limited data with trusted service providers (like Google and Microsoft for email API access, and Stripe for payments) as necessary to provide our service. Your email metadata is never shared with marketers, advertisers, or other services.

Can we delete emails without your permission?

No. All deletions require your explicit approval. We never delete anything automatically without your consent. You review what will be deleted, then explicitly approve the action. All deleted emails go to Trash (Gmail) or Deleted Items (Outlook) first, where they can be recovered within the provider's retention period.

Can you remove access anytime?

Yes. You can revoke EmailSlim's access to your email account at any time through Google Account settings or Microsoft account settings. When you remove access, we immediately stop accessing your account. You can also delete your EmailSlim account at any time, which removes all stored data.



Detailed Privacy Information

For complete legal details, see the sections below. This information is required for Google App verification and compliance with privacy regulations.

1. Information We Collect

1.1 Google and Microsoft Account Information

When you sign in with Google, we collect: email address, display name, profile photo (optional), and Google account ID for authentication and account linking.

When you sign in with Microsoft (Outlook.com, Hotmail, Microsoft 365), we collect: email address, display name, profile photo (optional), and Microsoft account ID for authentication and account linking.

1.2 Email Metadata (NOT Email Content)

We process the following email metadata through the Gmail API (Google) or Microsoft Graph (Outlook, Hotmail, Microsoft 365):

  • Sender email addresses

    To identify email sources and group by sender

  • Subject lines

    For search functionality and basic categorization

  • Date and time received

    For chronological organization and cleanup recommendations

  • Email size

    To calculate storage usage and cleanup potential

  • Read/unread status

    To assess email engagement patterns

  • Labels or folders (Gmail labels / Outlook categories)

    To understand email organization and importance

  • Attachment presence and sizes

    To identify storage-heavy emails (attachment content NOT accessed)

IMPORTANT: We never access, read, store, or analyze the actual content of your emails. Only metadata is processed to provide cleanup recommendations.

1.3 Usage and Analytics Data
  • Application usage statistics

    Feature usage, scan frequency, cleanup actions taken

  • Performance data

    Response times, error rates (to improve service quality)

  • Device and browser information

    For compatibility and security purposes

  • IP address and general location

    For security monitoring and service optimization

1.4 Payment Information

For premium subscriptions, we collect payment information through Stripe:

  • Billing information

    Processed securely by Stripe, we only store transaction IDs

  • Subscription status

    To manage access to premium features

1.5 Voluntary Information
  • Feedback and support requests

    When you contact us or submit feedback

  • User preferences

    Settings and customizations you choose


2. How We Use Your Information

We use the collected information for the following purposes:

2.1 Core Service Functionality
  • Analyze email metadata to provide cleanup recommendations
  • Generate statistics about your email usage patterns
  • Enable bulk email management operations
  • Provide search and filtering capabilities
2.2 Account Management
  • Authenticate and secure your account
  • Manage subscription status and billing
  • Provide customer support
  • Send important service notifications
2.3 Service Improvement
  • Analyze usage patterns to improve features
  • Monitor service performance and reliability
  • Develop new features and capabilities
2.4 Legal Compliance
  • Comply with applicable laws and regulations
  • Protect against fraud and abuse
  • Enforce our Terms of Service

3. Gmail API Usage and Data Handling

Gmail API Restricted Use Disclosure

EmailSlim's use of information received from Gmail APIs adheres to the Gmail API Services User Data Policy, including the Limited Use requirements.

3.1 Gmail API Permissions

We request the following minimal Gmail API permissions:

  • gmail.metadata

    Read email metadata only (sender, subject, date, size) — NOT email content

  • gmail.modify

    Move emails to Trash or perform other actions only when you explicitly request deletion

3.2 Data Processing Limitations
  • Metadata Only Processing

    We never read, store, or analyze email body content

  • No Data Transfer

    Gmail data is not sold, shared with third parties, or used for advertising

  • Purpose Limitation

    Gmail data is used solely for email management and cleanup features

  • User Control

    All Gmail actions require explicit user consent and initiation

3.3 Data Security for Gmail Information
  • Encrypted Storage

    All Gmail metadata is encrypted in transit and at rest

  • Access Controls

    Only authorized systems can access your Gmail metadata

  • Regular Security Audits

    We conduct regular security reviews of our Gmail API usage


4. Microsoft Graph Usage and Data Handling

Microsoft Graph and API Use

EmailSlim's use of information received from Microsoft Graph adheres to the Microsoft API Terms of Use and Microsoft's data handling requirements for application access to mail data.

4.1 Microsoft Graph Permissions

We request the following minimal Microsoft Graph permissions for mail:

  • Mail.Read

    Read email metadata only (sender, subject, date, size) — NOT email content beyond what is needed for storage analysis

  • Mail.ReadWrite

    Move emails to Deleted Items or perform other actions only when you explicitly request deletion

4.2 Data Processing Limitations
  • Metadata Only Processing

    We never read, store, or analyze email body content

  • No Data Transfer

    Microsoft mail data is not sold, shared with third parties, or used for advertising

  • Purpose Limitation

    Microsoft mail data is used solely for email management and cleanup features

  • User Control

    All mail actions require explicit user consent and initiation

4.3 Data Security for Microsoft Mail Information
  • Encrypted Storage

    All mail metadata is encrypted in transit and at rest

  • Access Controls

    Only authorized systems can access your mail metadata

  • Regular Security Audits

    We conduct regular security reviews of our Microsoft Graph usage


5. Data Storage and Security

5.1 Storage Infrastructure
  • Google Firebase/Firestore

    Secure, encrypted cloud database hosted by Google

  • Data Centers

    Data stored in Google's secure data centers with enterprise-grade security

  • Geographic Location

    Data stored in the United States with appropriate safeguards

5.2 Security Measures
  • Encryption in Transit

    All data transmitted using HTTPS/TLS encryption

  • Encryption at Rest

    All stored data encrypted using industry-standard encryption

  • Access Controls

    Multi-factor authentication and role-based access controls

  • Regular Security Updates

    Systems regularly updated with latest security patches

  • Monitoring and Logging

    Continuous monitoring for security threats and unauthorized access

5.3 Data Isolation

Each user's data is logically separated and isolated from other users. We implement strict access controls to ensure users can only access their own data.


6. Data Sharing and Third Parties

We do not sell, rent, or trade your personal information. We may share limited data with trusted service providers in the following circumstances:

6.1 Service Providers
  • Google (Gmail API, Firebase, OAuth)

    For authentication, data storage, and Gmail API access

  • Microsoft (Microsoft Graph, OAuth)

    For authentication and Microsoft mail API access (Outlook, Hotmail, Microsoft 365)

  • Stripe

    For payment processing (they handle all payment data securely)

  • Google AdSense

    For displaying relevant ads to trial users (anonymized data only)

6.2 Legal Requirements

We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety, or that of our users or the public.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of the business assets, subject to the same privacy protections.

6.4 Email Marketing Research

To help improve email quality for everyone, we may share anonymized, aggregated email engagement data with brands for marketing research. This data:

  • Contains NO personal information

    No names, emails, or identifying details

  • Contains NO individual user data

    Only aggregated statistics across thousands of users

  • Helps reduce spam

    By showing brands what works and what doesn't

  • Improves email quality

    For all users by helping brands send better emails

Examples of shared data: Average open rates by brand domain, subject line performance (anonymized), send frequency analysis, geographic engagement patterns.

You can opt-out of this data sharing anytime in your account settings.

6.5 What We DON'T Share
  • Email content (we never access this)
  • Individual user behavior patterns
  • Personal information for marketing purposes
  • Detailed email metadata with marketers or advertisers (except as described in 5.4)

7. Your Rights and Choices

7.1 Access and Control
  • View Your Data

    Access all data we have about you through your account dashboard

  • Update Information

    Modify your profile information and preferences at any time

  • Download Data

    Export your email metadata and account information

  • Delete Account

    Permanently delete your account and all associated data

7.2 Email API Permissions (Google and Microsoft)
  • Revoke Access

    Remove EmailSlim's access to your email account at any time through Google Account settings or Microsoft account settings

  • Limited Permissions

    We only request the minimum permissions necessary for our service (read metadata, modify only when you approve)

7.3 Communication Preferences
  • Email Notifications

    Control which emails you receive from us

  • Marketing Communications

    Opt out of promotional emails (service emails may still be sent)

7.4 Analytics and Tracking
  • Usage Analytics

    Opt out of usage analytics collection in your privacy settings

  • Performance Data

    Choose whether to share performance analytics to help improve the service


8. Data Retention

8.1 Active Accounts

We retain your data for as long as your account is active and as necessary to provide our services.

8.2 Account Deletion
  • User-Initiated Deletion

    When you delete your account, all data is permanently removed within 30 days

  • Inactive Accounts

    Accounts inactive for 24 months may be deleted after notification

8.3 Legal Requirements

Some data may be retained longer if required by law, to resolve disputes, or enforce agreements.

8.4 Backup and Recovery

Data may persist in backups for up to 90 days after deletion for disaster recovery purposes, but is not accessible during this time.


9. Cookies and Tracking Technologies

9.1 Essential Cookies
  • Authentication Tokens

    Required for secure login and session management

  • Preferences

    Store your settings and customizations

9.2 Analytics Cookies
  • Usage Analytics

    Understand how users interact with our service (can be disabled)

  • Performance Monitoring

    Monitor service reliability and performance

9.3 Advertising Cookies (Trial Users Only)

Trial users may see ads served by Google AdSense, which may use cookies for ad personalization. Premium users see no ads.

9.4 Cookie Management

You can control cookies through your browser settings. Note that disabling essential cookies may affect service functionality.


10. Children's Privacy

EmailSlim is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete such information promptly.

Parents who believe their child has provided us with personal information should contact us immediately at the email address provided below.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

11.1 Notification of Changes
  • Email Notification

    Significant changes will be communicated via email

  • In-App Notification

    Changes will be highlighted when you next use the service

  • Website Notice

    Updated policies will be posted on our website

11.2 Effective Date

Changes become effective 30 days after notification, unless immediate changes are required by law. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.


12. Contact Information

If you have questions about this Privacy Policy or our data practices, please contact us:

EmailSlim Support Team

Email: privacy@emailslim.com

Response Time: We aim to respond to privacy inquiries within 72 hours

Data Protection Officer: Available for GDPR-related inquiries

12.1 Regulatory Authorities

If you are located in the European Union or United Kingdom, you have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.


This Privacy Policy was last updated on January 15, 2024

© 2024 EmailSlim. All rights reserved.