RapidMailSync alpha

Security overview

This page describes the design as built for the private alpha. The independent security assessment required by Google for Gmail API access is planned but not yet complete; the "unverified app" warning you see at sign-in will disappear once it is.

RapidMailSync is operated by Secure Software Systems B.V., KvK 42168942, Naarden, the Netherlands. Last updated: 22 September 2026.

Principles

Transport

Accounts and sessions

Operations

Deleting your data

Deleting your account destroys the stored mailbox passwords first, then asks Google to revoke the Gmail authorisation, then destroys the stored Gmail token — that order, because the token is what performs the revocation; it is destroyed whether or not Google answered. Every remaining record is then removed. The deletion works even when Google cannot be reached (the grant can then be revoked from your Google account settings), and produces an anonymous receipt you can check afterwards. Mail already imported into Gmail is yours and stays in Gmail.

Reporting a vulnerability

Please report security issues privately to security@rapidmailsync.com. We aim to acknowledge a report within two working days and to keep you informed until it is resolved. Please do not test against other users' data, do not attempt denial of service, and give us reasonable time to fix an issue before disclosing it. We will not pursue legal action over good-faith research that follows those limits.