MailFlows

Privacy Policy

Last updated: July 2026

MailFlows ("we", "our", "the Service") is a cold email platform that lets you connect your own Gmail account to find, verify, and email business contacts from a single dashboard. This policy explains what data we collect, why, and how it's handled — including how we use data accessed through your Google Account.

1. What we collect

2. How we use Google user data

When you connect your Gmail account, MailFlows requests the following Google OAuth scope:

ScopeWhat it's used for
gmail.sendSending emails on your behalf, only when you click Send (Quick Send, Campaigns, or Reply) inside MailFlows. We never send anything without you initiating it.
userinfo.email, userinfo.profileIdentifying which Gmail account you've connected and displaying your name/email in the app.

MailFlows does not request permission to read your Gmail inbox. We do not use any Gmail read scope (gmail.readonly or gmail.metadata). Replies to emails you send through MailFlows are captured through a separate mechanism: outgoing emails carry a unique reply-tracking address on our own domain, and replies sent to that address are routed to us directly — your Gmail inbox itself is never accessed by MailFlows.

Limited Use disclosure: MailFlows' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the specific features described above, is never used for advertising, and is never sold or transferred to third parties except as necessary to provide the Service (see Section 4) or to comply with the law.

3. Data retention

4. Who we share data with

We use the following third-party services to operate MailFlows. Each only receives the minimum data needed to perform its function:

We do not sell your data or any Google user data to anyone, ever.

5. Your rights

6. Security

Passwords are never stored in plain text. Sensitive tokens (such as Gmail access tokens) are encrypted at rest. All traffic between your browser and MailFlows is encrypted via HTTPS.

7. Children's privacy

MailFlows is not directed at children under 16 and we do not knowingly collect data from them.

8. Changes to this policy

If we make material changes to this policy, we'll update the date at the top of this page and, where required, notify you directly.

9. Contact

Questions about this policy or your data? Reach us through the in-app Support option, or email [email protected].

← Back to MailFlows