MailClient
Privacy
How MailClient handles connected email accounts and provider access.
Last updated: August 19, 2026.
Connected email providers
When you connect a Gmail or Outlook.com account, you sign in directly with Google or Microsoft. MailClient never asks for or stores your Google or Microsoft password.
MailClient stores the information needed to maintain the connection:
- the provider and its stable account identifier;
- the verified email address and granted permissions;
- an encrypted refresh token;
- connection, synchronization, and error status information.
Short-lived access tokens are kept in memory only when they are needed for provider operations.
How provider access is used
MailClient uses the permissions you approve to receive and synchronize email through IMAP and to send email through SMTP. Provider credentials are used only with the fixed Gmail or Outlook.com mail endpoints.
MailClient stores synchronized messages, folders, rules, and user state locally so the mailbox features can operate. It does not use connected-account data for advertising.
MailClient's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing mailbox features described here. It is not sold, used for advertising, used to determine creditworthiness, or used to train generalized artificial intelligence or machine-learning models.
MailClient does not allow humans to read connected Google data except with the user's affirmative agreement for specific data, when necessary for security or abuse investigation, or when required by law. Data is not transferred to third parties except where necessary to provide the user-requested service with consent, for security, to comply with law, or as part of a business transfer with the required prior consent.
Consent and your controls
You can reconnect an account when its authorization expires or is revoked. Disconnecting removes MailClient's local provider grant and stops future provider access. It does not delete messages or other content from Google or Microsoft.
Disconnecting keeps mail and settings already stored in MailClient. Contact your MailClient administrator if you also want that local content deleted.
- Review or remove Google access at Google Account permissions.
- Review or remove Microsoft access at Microsoft apps and services.
Security and retention
Provider client secrets are kept outside the application content and source code. Refresh tokens are encrypted before they are stored. Authorization codes, access tokens, refresh tokens, and account passwords are not written to application logs.
Connection attempts are short-lived. Operational records and synchronized content are retained while they are needed to provide the service or until an authorized deletion request is completed.
Google and Microsoft
Google and Microsoft process your provider login and consent under their own terms and privacy policies. MailClient receives only the authorization response and account information required to create the connection.
For questions, access requests, or deletion requests, contact your MailClient administrator.
Review the Terms of Service for the conditions that apply when using MailClient.