Legal

Privacy policy

Last updated: 01/08/2026.

1. Data controller

The data controller for your data is the publisher of the service, whose contact details are listed in the legal notice.

2. Data collected

We collect and process the following categories of data:

  • Account data: email address, hashed password (bcrypt), optional name.
  • Mailbox connection data: IMAP credentials encrypted with strong encryption (libsodium, XSalsa20-Poly1305), encrypted OAuth tokens.
  • Usage metadata: message fingerprints (anonymous hashes for deduplication), synchronization statistics.
  • Technical data: IP address, browser type, server logs (30-day retention).
  • Billing data: handled exclusively by Stripe; we store neither card numbers nor bank details.

Important: we never store the content of your emails. They pass through memory during the copy and are then erased.

3. Purposes of processing

  • Provision of the Service (migration, synchronization, deduplication).
  • Management of your account and subscription.
  • Communication related to the Service (sync completion notifications, security alerts).
  • Compliance with legal obligations (accounting, authority requests).
  • Improvement of the Service (anonymized usage statistics).

4. Legal basis

Processing is based on the performance of the contract binding us (Terms of Use/Terms of Sale), your consent (where required), and our legal obligations.

5. Retention period

  • Account data: for as long as the account is active, then 30 days after deletion.
  • Billing data: retained for 10 years in accordance with accounting obligations.
  • Server logs: 30 days.
  • Deduplication fingerprints: for as long as the mailbox is synchronized.

6. Recipients

Your data is accessible to the MailSync team and to our technical subprocessors: o2switch (hosting, France), Stripe (payment, PCI-DSS compliant). No data is transferred outside the European Union.

7. Your rights

You have the following rights, exercisable at any time from your account or by email at [email protected]:

  • Right of access and portability (JSON export available in your account).
  • Right of rectification.
  • Right to erasure (account deletion with cascade).
  • Right to object.
  • Right to lodge a complaint with the CNIL (French data protection authority).

8. Cookies

The service uses only technical cookies necessary for its operation (session, CSRF, theme preference). No advertising tracking cookies. Google Analytics (gtag) is present for anonymized audience measurement purposes only — you may block it via your browser with no functional impact.

⚠️ Draft — pending review

This document describes the currently known technical practices. It must be reviewed by a DPO or lawyer, and updated if you add new subprocessors or tracking tools.