SECURITY.MODEL: DEFAULT-DENY
Granting software access to email is a serious decision. This page describes exactly what MailTract can do, what it can never do, and how your data is protected — in specific, verifiable terms.
MailTract uses strict Read-Only OAuth scopes for Gmail (gmail.readonly). Our app physically cannot send, alter, or delete your emails — the permission to do so is never requested, so it never exists.
IMAP connections are TLS-only; plaintext connections are refused. App passwords are supported, so your primary password never has to touch MailTract.
All connection credentials, OAuth tokens, and IMAP passwords are encrypted using AES-256-GCM before they are stored. The application refuses to store credentials at all if the encryption key is not configured.
If you disconnect an account, your credentials are wiped in milliseconds. Passwords, tokens, and the contents of your financial documents never appear in logs.
Your financial data is explicitly ring-fenced. We pass email and document content to our AI strictly as delimited, untrusted text — and your invoices are never used to train public AI models.
This same boundary is our prompt-injection defense: instructions hidden inside an email or PDF are treated as text to read, never as commands to follow.
Fully automated data-retention purging: choose a retention window and MailTract deletes extracted documents and source data on schedule, without you having to remember.
Account deletion is instant and permanent — one action removes your account, credentials, documents, and exports. Security-sensitive actions (connect, disconnect, scan, edit, export, delete) are written to an audit log you can inspect.
The legal detail lives in our Privacy Policy and Terms of Service.
🔒 Read-only access. GDPR compliant. We never send, alter, or delete your emails.