Strong encryption (libsodium)
Your IMAP credentials are encrypted locally with libsodium (XSalsa20-Poly1305) before being stored. No password is ever kept in plain text, not even in our logs.
Migrating your emails means entrusting years of private correspondence to a tool. We take that seriously. Here's precisely what we do with your data — and what we don't.
Your IMAP credentials are encrypted locally with libsodium (XSalsa20-Poly1305) before being stored. No password is ever kept in plain text, not even in our logs.
For Google and Microsoft 365, we use official OAuth 2.0. We never see your password — you keep control of the permissions granted and can revoke them at any time.
Servers in France, operated by o2switch. Your data never leaves the European Union. Native GDPR compliance, no US Cloud Act.
You can export all your data (JSON), delete an account with a full cascade, or disable any synchronization in one click. The end of your relationship with MailSync is yours to decide.
We never store the content of your emails. Messages pass through memory during the copy, then are forgotten. Only anonymous deduplication fingerprints (hashes) are kept.
Our workers run on code you can audit. The technical choices (encryption, fingerprinting, OAuth) are documented right here. No black box.
Right of access: export all your data in JSON format from your account, with no form and no delay.
Right to rectification: edit or delete any item from your interface — deleting a mailbox is immediate and cascades fully.
Right to erasure: deleting your account permanently erases all associated data within 30 days (the legal delay lets us close out any Stripe accounting obligations).
Right to portability: standard JSON exports, readable by any third-party application.
For any question, write to us at [email protected].