Privacy Policy

Last updated: June 2026

Google Workspace Data Usage & Privacy Disclosure

1. Information We Collect and How We Use It

If you choose to connect your Google Account to our service, our application will request access to specific Gmail permissions via Google OAuth scopes. We strictly adhere to the principle of least privilege, requesting only the minimum permissions necessary to deliver our core features:

  • Accessing Email Metadata and Headers (gmail.modify): We programmatically scan your incoming or existing email headers to detect newsletter identifiers (such as List-Unsubscribe fields) and sender addresses. This metadata is processed strictly to provide you with a list of active subscriptions and the ability to unsubscribe from them.
  • Managing Emails and Labels (gmail.modify):When you explicitly direct the application to "clean" or "remove" emails from a specific sender, the application uses this permission to apply the TRASH system label to those specific messages, moving them to your Gmail Trash folder. Our application does not permanently delete or purge messages bypassing your trash.
  • Creating Inbox Filters (gmail.settings.basic): If you choose to block a sender, our application will create a native Gmail rule/filter on your behalf to automatically route future emails from that specific sender to your Trash folder.

2. Data Storage and Retention

Your privacy is our core priority.

  • No Email Body Storage: We do not download, store, or view the actual content or bodies of your personal emails on our servers. All scanning for unsubscribe links happens programmatically in temporary memory (RAM) and is discarded immediately after processing.
  • Minimal Metadata Retention:We only retain anonymized or strictly necessary subscription metadata (such as the sender's domain and the unsubscription link) in our database to maintain your active "unsubscribed" or "blocked" dashboard.

3. Google Limited Use Policy Compliance

Our application's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We never sell, rent, or trade your Gmail data or email metadata to third parties.
  • We never use your Gmail data for serving advertisements, retargeting, or profile-building.
  • No human personnel at our company will ever read your email content unless you explicitly grant us permission to do so for specific troubleshooting purposes (e.g., investigating a critical bug), or if it is strictly necessary for security purposes or to comply with applicable law.

4. Data Protection Mechanisms for Sensitive Data

  • Encryption in transit: Data exchanged between your browser, our application, and Google APIs is transmitted over industry-standard TLS-encrypted connections.
  • Encryption at rest: Sensitive OAuth tokens and mailbox integration credentials are encrypted at rest before being stored.
  • Access controls: Access to production systems and stored integration data is restricted to authorized personnel with a legitimate operational need.
  • Token lifecycle controls: Users can disconnect linked mailbox accounts at any time, and revoked or invalid tokens are no longer used to access Google data.

Overview

stopsub.email helps you identify and unsubscribe from unwanted email senders. We are committed to protecting your privacy and handling your data with care.

What we access

When you connect your Gmail or Outlook account, we access only the metadata needed to identify newsletter and promotional senders: sender addresses, subject lines, dates, and unsubscribe links. We do not read, store, or analyze the body content of your emails.

How we use data

  • Scan your inbox to identify subscription senders
  • Display senders in your dashboard for review
  • Execute unsubscribe requests on your behalf when you choose
  • Track usage limits on the free plan

Data storage

Mailbox OAuth tokens are encrypted at rest. Subscription metadata (sender name, email, domain, frequency) is stored in our database to power your dashboard. You can delete all stored data at any time from Settings.

Third parties

We use Google and Microsoft OAuth for mailbox access, and Stripe for payment processing. We do not sell your personal data to third parties.

Your rights

You can disconnect your mailbox, delete all stored data, or delete your account at any time. For questions about your data, contact us at privacy@stopsub.email.

Changes

We may update this policy from time to time. Continued use of stopsub.email after changes constitutes acceptance of the updated policy.