Last updated 16 September 2026
Privacy Policy
The short version
- MailFrame accesses Gmail only after you grant permission.
- MailFrame does not read your inbox. It creates drafts and sends the emails you compose.
- MailFrame does not sell email content, contacts or any personal data.
- MailFrame never sends an email without your explicit confirmation.
- You can disconnect Gmail at any time, and delete your data from Settings.
Information we collect
Account information: your name, email address and profile photo from Google sign-in.
Brand Kit: details you choose to add, such as company name, logo, colours, signature, website, phone number and social links.
Emails you compose: recipients, subject and message content, stored so you can edit, reopen and duplicate them. You can choose in Settings not to retain content after sending.
Gmail connection: your Gmail address, the permissions granted, and OAuth tokens, which are encrypted at rest and never exposed to your browser.
How MailFrame uses Gmail
MailFrame requests the narrowest Gmail permissions that allow it to send email and, if you enable it, create drafts on your behalf. MailFrame uses these permissions only to create the drafts and send the messages you explicitly ask it to. It does not list, read, scan or analyse the messages in your mailbox.
MailFrame's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is not used for advertising, is not sold, and is not used to train generalised AI models.
AI writing assistance
When you choose an AI action such as “Improve” or “Shorten”, the text of the email you are editing is sent to MailFrame's AI provider solely to return the suggested revision. MailFrame never sends your inbox contents to an AI provider, and AI suggestions are never sent as email automatically.
Tracking
MailFrame does not add tracking pixels to your emails and does not measure opens or clicks. Campaign parameters (UTM) are added to links only if you switch them on for an individual email.
Security
Data is transmitted over HTTPS. Access to your records is restricted to your account by database row-level security. Gmail tokens are encrypted with AES-256-GCM and are only used on MailFrame's servers.
Retention and deletion
You can disconnect Gmail from Settings, which revokes MailFrame's access with Google and deletes stored tokens. You can delete individual emails, all emails, or your entire account from Settings. Account deletion removes your profile, Brand Kits, emails, version history, preferences, uploaded logos and Gmail credentials. Security audit records are kept in anonymised form.
Contact
For privacy questions or data requests, contact privacy@mailframe.app.