Privacy policy
This policy has not yet been through an external legal review. It was written by the people who built the service and describes it accurately; a reviewed version will replace it before the service opens to the public.
Last updated: 22 September 2026.
Who is responsible for your data
RapidMailSync is a service of Secure Software Systems B.V., a private limited company registered in the Netherlands, Chamber of Commerce (KvK) number 42168942, registered office Binnenhof 62C, 1412 LC Naarden, the Netherlands. Secure Software Systems B.V. is the data controller for the personal data described on this page.
For any question about this policy, or to exercise the rights described below, write to privacy@rapidmailsync.com. For security issues specifically, use security@rapidmailsync.com — see the security overview.
What RapidMailSync is
RapidMailSync imports mail from POP3 and IMAP mailboxes that you own into your Gmail account. To do that it needs a small amount of data about you and about each mailbox you add. This page lists all of it.
Use of Google user data (Limited Use disclosure)
RapidMailSync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail access only to add messages you have chosen to import. We do not read your Gmail, do not store message content, do not use it for advertising or analytics, and do not allow humans to access it except for security investigation or with your consent.
Concretely, RapidMailSync requests two Gmail permissions: gmail.insert, used solely to add each original message to your mailbox through Gmail's import operation, and gmail.labels, used to create the label that marks imported mail. It never requests permission to read, search, modify, send or delete existing Gmail data, and the service has no code path that could do so. Signing in uses a separate, standard Google sign-in grant (your Google account id, e-mail address and display name).
What we store
- Your account: Google account id, e-mail address, display name, sign-in times, the status of the Gmail connection (connected, disconnected, revoked), the date and scopes of the Gmail grant, and an encrypted Gmail refresh token.
- Each mailbox you add: label, protocol, host name, port, TLS mode, user name, an encrypted copy of the password, your settings (polling interval, spam handling, delete-after-import consent and grace period), state, counters and the last error category.
- Import bookkeeping: for every message seen in a mailbox, an identifier of that message (the POP3 UIDL or IMAP UID, not the message itself), its size, the import state and, after a successful import, the Gmail message id. This is what prevents duplicates.
- Job history: when each sync ran, how long it took, how many messages were imported, skipped or failed, and error categories.
- Sessions: a hashed session identifier, creation and expiry times.
- Operational logs (90 days): request identifiers, timings, error categories, pseudonymous references, and the IP address each request came from — used to apply rate limits and to investigate abuse. Log lines never contain passwords, tokens, message content, or a host name together with a user name; e-mail addresses are masked automatically.
What we never store
- Message content. Each message exists only in the memory of one short-lived process while it is copied from the mailbox to Gmail, and is discarded as soon as Gmail has accepted it. There is no spool, no cache and no backup of mail.
- Plaintext passwords or tokens. Secrets are encrypted with a hardware-backed key before they are written; only the component that performs a sync can decrypt them, for that sync only.
- Anything from your Gmail account other than the ids of the messages and labels RapidMailSync itself created there.
How your data is used
Only to provide the service: to connect to the mailbox you configured, to add mail to your Gmail account, to show you the state of the import, and to detect abuse or security problems. There is no advertising, no profiling and no sale or sharing of data.
Delete after import
RapidMailSync can delete messages from a POP3 mailbox after they have been imported, but only if you switch this on for that mailbox and confirm an explicit consent text. It is off by default, is never applied to IMAP mailboxes, is never applied during the first verification pass, and is only applied to a message once Gmail has confirmed the import with a message id. You can switch it off at any time. Messages already deleted from the mailbox cannot be restored by RapidMailSync; they remain in your Gmail account.
Where data is processed
On Amazon Web Services in the European Union (Ireland region). Amazon Web Services acts as our processor under its data processing agreement and stores everything encrypted under keys we control. Google is contacted only to sign you in and to add messages to your Gmail account, where your own relationship with Google governs what happens to them. Your mailbox provider is contacted only with the credentials you supplied. There is no analytics provider, no error-tracking service and no advertising network: no other third party receives your data.
Retention and deletion
- Your account, mailboxes, bookkeeping, job history and sessions exist until you delete them. Removing a mailbox deletes its bookkeeping and history; deleting your account deletes everything listed above.
- Deleting your account first destroys the stored mailbox passwords, then asks Google to revoke the Gmail authorisation, then destroys the stored Gmail token — in that order, because revoking at Google requires the token. The token is destroyed whether or not Google could be reached. Every remaining record is then removed. You receive an anonymous receipt (kept 30 days) that shows the progress and completion of the deletion. Mail already imported into Gmail stays in Gmail, under your control.
- The private alpha runs without database backups: point-in-time recovery is switched off, so no copy of your data survives a deletion in a backup. When backups are switched on for the production service they will be kept for 35 days for disaster recovery only, not used for anything else and not accessible to the application.
- Operational logs are kept for 90 days; audit records of key usage are kept as required by our infrastructure provider's audit trail.
Your rights
You can export the data RapidMailSync holds about you as a JSON document from the Account page — your account, your mailboxes and their settings, your recent sync history and per-mailbox message counts — and you can delete your account there without contacting anyone. If you are in the EU/EEA or the UK you also have the rights of access, rectification, erasure, restriction, objection and data portability under the GDPR. Write to privacy@rapidmailsync.com and we will respond within one month. You also have the right to lodge a complaint with a supervisory authority; ours is the Dutch Autoriteit Persoonsgegevens, and you may also complain to the authority where you live.
Cookies
RapidMailSync uses two cookies, both essential: a session cookie after you sign in, and a short-lived cookie that protects the sign-in flow against forgery. No tracking or analytics cookies are used.
Changes
This policy will change when the legal review is complete. Material changes will be announced in the app before they take effect.