Privacy Policy
1. Summary
Email Cleaner deletes email you tell it to delete. That is the entire purpose, and it is the only reason we ever touch your mailbox.
We do not sell your data. We do not use it for advertising. We do not use it to train AI or machine-learning models. We do not let humans read your email. We keep the smallest amount of information needed to show you a preview and to undo a deletion, and we delete it on request.
This policy explains exactly what we access, why, how long we keep it and how to remove it. Defined terms used here have the meanings given in our Terms of Service.
2. Who we are
Email Cleaner ("Email Cleaner", "we", "us") operates the service at https://emailcleaner.xyz. We act as the data controller for account information, and as a data processor acting on your instructions when we access the contents of a mailbox you have connected.
For any privacy question, contact privacy@emailcleaner.xyz.
3. What we collect
3.1 Account information
- Email address — to identify your account and send service notices.
- Password — stored only as a scrypt hash with a per-user salt. We cannot recover it.
- Two-factor secret and recovery codes — the TOTP secret is encrypted at rest; recovery codes are stored as hashes.
- Display name, if you choose to set one.
- Sign-in metadata — timestamps, sign-in counts and IP addresses of authentication attempts, kept for security and abuse prevention.
3.2 Mailbox credentials
- For Gmail and Microsoft — OAuth access and refresh tokens. We never receive, see or store your provider password.
- For IMAP providers — the server hostname, port, username and the app password you supply, encrypted with AES-256-GCM and cryptographically bound to your account record.
3.3 Mailbox data
When you run a cleaning job we access your mailbox to find messages that match the rule you wrote. Specifically:
- Folder and label names and message counts — so you can choose what to clean.
- Message metadata for matching messages — provider message identifier, folder, subject, sender, recipient, date, size and flags such as starred or unread.
- Message body text — only when your rule requires a keyword search that the provider cannot perform server-side. This content is held in memory for the duration of the check and is never written to disk, logged or retained.
We never access, copy or store attachments.
3.4 What we store after a job
For each message a job deletes, we retain the provider message identifier, its original folder, subject, sender, date and size. This exists for exactly one reason: so that the undo function can put those specific messages back. It is deleted when the job history is deleted.
3.5 Technical logs
We keep operational logs containing timestamps, request paths, error messages and IP addresses. Logs are automatically scrubbed of credentials, tokens and passwords before they are written, and are retained for up to 30 days.
4. How we use your information
We use the information above only to:
- authenticate you and keep your account secure;
- connect to the mailboxes you choose and list their folders;
- find messages matching the rules you write, and show you a preview before acting;
- delete those messages when you confirm, and restore them if you undo;
- run scheduled rules you have created;
- enforce plan limits, prevent abuse, and diagnose faults;
- send transactional messages about your account or a job.
Our legal bases, where the UK/EU GDPR applies, are performance of a contract (operating the service), legitimate interests (security and abuse prevention) and consent (where you grant mailbox access, which you may withdraw at any time).
5. Google API Services disclosure
Email Cleaner's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, for Google user data obtained through the Gmail API:
- We use it only to provide and improve the mailbox-cleaning features you have asked for — finding the messages your rule describes, showing you a preview, deleting them on your confirmation and restoring them on undo.
- We do not transfer it to third parties except as necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use it for serving advertising, and we do not allow it to be used for advertising by anyone else.
- We do not use it to develop, improve or train generalised or non-personalised AI or machine-learning models.
- We do not allow humans to read it, except where we have your affirmative agreement for a specific support request, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised.
5.1 Scopes we request and why
| Scope | Why it is needed |
|---|---|
gmail.modify |
To list labels and their message counts, search for messages matching your rule, read the minimum metadata needed to show a preview, and move matched messages to Trash. This is the narrowest scope that permits moving mail to Trash in bulk. |
https://mail.google.com/ |
Requested only where a deployment enables permanent deletion, which bypasses Trash. Google offers no narrower scope for that operation. If permanent deletion is not enabled, this scope is not requested. |
userinfo.email |
To identify which mailbox was connected, so it can be labelled correctly in your account. |
You can review and revoke Email Cleaner's access at any time at myaccount.google.com/permissions. Revoking access immediately stops all access; we delete the stored tokens when we next detect the revocation, or immediately if you disconnect the mailbox in Email Cleaner.
6. Microsoft Graph data
For Outlook.com and Microsoft 365 mailboxes we use Microsoft Graph with delegated permissions only, meaning we can act solely within the mailbox of the signed-in user who granted consent:
| Permission | Why it is needed |
|---|---|
Mail.ReadWrite | To list mail folders and counts, search for matching messages, read the metadata shown in the preview, move messages to Deleted Items, and move them back on undo. |
User.Read | To read the signed-in user's address so the connected mailbox can be labelled. |
offline_access | To refresh access without asking you to sign in again for every job, including scheduled ones. |
We apply the same commitments to Microsoft data as to Google data: it is used only to deliver the features you requested, never sold, never used for advertising and never used to train AI models. You can revoke access at myaccount.microsoft.com.
7. IMAP providers
For Yahoo, iCloud, Mail.com, GMX, Zoho, Fastmail, AOL and other IMAP mailboxes, you supply an app password — a single-purpose credential issued by your provider that you can revoke without changing your main password. We strongly recommend app passwords over account passwords, and most providers now require them.
The credential is encrypted with AES-256-GCM using a key held only by the server, with your account identifier bound into the ciphertext as additional authenticated data. A credential record copied out of the database cannot be decrypted against any other account. We connect only over TLS, on port 993 by default.
8. What we never do
- We never sell, rent or trade your personal data or mailbox content.
- We never use your mailbox content for advertising or profiling.
- We never use your mailbox content to train AI or machine-learning models.
- We never read your mail for any purpose other than executing the rule you wrote.
- We never store message bodies or attachments.
- We never delete anything you have not previewed and confirmed, except where you have explicitly enabled an auto-confirm scheduled rule, which can only move mail to Trash.
9. Retention and deletion
| Data | Retention |
|---|---|
| Message body content | Never stored. In-memory only, discarded within the job. |
| Mailbox credentials (OAuth tokens, app passwords) | Until you disconnect the mailbox or delete your account — then deleted immediately. |
| Deleted-message records (for undo) | 7–90 days by plan, then removed. Deleted immediately if you delete the job. |
| Job history and rules | 30 days to 3 years by plan, or until you delete them. |
| Account record | Until you delete your account. |
| Security and audit logs | Up to 30 days. Authentication audit entries up to 12 months. |
| Backups | Rolling, overwritten within 30 days. |
To delete everything: sign in and delete your account, or email privacy@emailcleaner.xyz from your registered address. Credentials are destroyed immediately and all remaining data within 30 days, backups included.
Deleting your Email Cleaner account does not delete anything in your actual mailbox.
10. Security
- All traffic is served over HTTPS with HSTS.
- Credentials are encrypted at rest with AES-256-GCM; passwords are scrypt-hashed.
- Two-factor authentication (TOTP) is available on every account and recommended.
- Sign-in attempts are rate-limited and temporarily locked out after repeated failures.
- Logs are scrubbed of secrets before being written.
- The service runs as an unprivileged account with a read-only filesystem except for its own data directory.
Details are on our security page. To report a vulnerability, email security@emailcleaner.xyz.
11. Sharing and subprocessors
We do not share your data with third parties for their own purposes. We rely on a small number of infrastructure providers strictly to operate the service:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Our hosting provider | Servers and storage | All stored data, encrypted at rest |
| Cloudflare | DNS | DNS queries only |
| Google LLC | Gmail API; optional reCAPTCHA | Mailbox access you granted; captcha signals |
| Microsoft Corporation | Microsoft Graph | Mailbox access you granted |
We may disclose information where legally required, to enforce our terms, or to protect the rights and safety of users. If we are ever acquired, we will give notice before your data becomes subject to a different policy.
If bot protection is enabled on this deployment, the sign-in and registration pages load a captcha script from Google or Cloudflare, which processes your IP address and interaction signals under that provider's own privacy policy.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. Residents of California have rights under the CCPA/CPRA, including the right to know and delete — and we confirm we do not sell or share personal information as those terms are defined.
Exercise any of these by emailing privacy@emailcleaner.xyz from your registered address. We respond within 30 days. You may also complain to your local data protection authority.
13. International transfers
Our servers are located in Europe. If you access the service from elsewhere, your data is transferred to and processed there. Where required, we rely on Standard Contractual Clauses or an adequacy decision for such transfers.
14. Children
The service is not directed to anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
15. Changes to this policy
We will update this page when our practices change and revise the "last updated" date. For material changes — particularly any change to what we access or how long we keep it — we will notify registered users by email at least 14 days before the change takes effect. Continued use after that date constitutes acceptance.
16. Contact
Privacy enquiries: privacy@emailcleaner.xyz
Security reports: security@emailcleaner.xyz
General support: support@emailcleaner.xyz
Email Cleaner is an independent service and is not affiliated with, endorsed by or sponsored by Google LLC, Microsoft Corporation, Yahoo Inc. or Apple Inc.