The boundary: what we store, what we never store
The strongest security control is not holding the data at all. DeclutrMail’s promise is literal: We never fetch or store full email contents. DeclutrMail requests only the Gmail details listed below.
Gmail details DeclutrMail stores:
- Gmail message and conversation IDs
- Sender name and email address
- Subject line
- Gmail preview snippet (the short text shown in your inbox list)
- Date received
- Gmail labels
- Your Gmail label names
- Read or unread state
- Whether a message was sent by you
- Recipient email addresses from To and Cc on email you sent
- Unsubscribe links and whether one-click unsubscribe is supported
- Estimated Gmail message size
DeclutrMail never fetches or stores:
- Full email contents
- Email HTML
- Attachments
- Images embedded in emails
- Raw email source
- Email headers other than From, Subject, To, Cc, and unsubscribe information
Because full email contents and attachments are never in our systems, they cannot leak from DeclutrMail. Subject lines and Gmail preview snippets can still contain sensitive information, so we list and protect them explicitly.
OAuth scopes, and why
DeclutrMail requests one Gmail scope, gmail.modify, plus openid and your email address to identify the connected account. The product’s job is to act on your email at your instruction — archive, label, delete, unsubscribe — and gmail.modify is the scope that permits those label changes.
This permission is broader than what DeclutrMail uses. The app requests only the listed fields and never asks Gmail for the full or raw email formats that include complete contents and attachments. You can revoke access at any time from Settings or from your Google account permissions page.
Encryption
All data is encrypted in transit (TLS) and at rest. Your Gmail OAuth tokens get an extra layer: each token is envelope-encrypted with its own fresh 256-bit data key (AES-256-GCM), and that key is in turn wrapped by a key-management-service key that never enters the application process. Tokens are never sent to your browser and never included in data exports.
Independent assessment (CASA Tier 2)
Apps using restricted Gmail scopes are subject to Google’s independent CASA (Cloud Application Security Assessment) process. Google approved DeclutrMail’s OAuth verification on 21 April 2026 for the single restricted scope we request, gmail.modify. Verification is recertified annually, and any new scope or change to our consent screen requires a fresh review.
No ML category prediction
DeclutrMail does not use machine learning to predict email categories or route senders. It can automatically protect a sender using fixed product rules when strong engagement signals, such as your reply history, cross the documented threshold; you can review and change that protection. Mail-changing automation follows preset rules you explicitly enable — never a model’s guess. We also do not use Gmail data to train generalized AI or machine-learning models.
Leaving cleanly
You can disconnect an inbox (which revokes our Google access, stops syncing, and preserves its historical DeclutrMail record for reconnection), delete one inbox’s saved data, or schedule deletion of your whole account from Settings. Account deletion waits at least 7 days, and also waits for any open undo window, so undo keeps working for its full window. Undo windows run 30 days on every plan, so a recent action commonly puts deletion up to 30 days out; you can waive both with a typed confirmation to delete immediately. Details are in the Privacy Policy.
Report a vulnerability
If you believe you have found a security vulnerability in DeclutrMail, email privacy@declutrmail.com with the details. We read every report and will respond, and we ask that you give us reasonable time to fix an issue before disclosing it publicly.