Privacy Policy

Last updated: March 20, 2026

1. Introduction

PromptMail ("we", "our", or "the application") is a service that lets you send and read emails from within ChatGPT by connecting your Gmail account. This Privacy Policy describes how we collect, use, store, and protect information when you use PromptMail, including data we receive from Google when you sign in and authorize access to Gmail.

By using PromptMail, you agree to this Privacy Policy. If you do not agree, please do not use the service.

2. Data We Collect

When you sign in with Google and authorize PromptMail, we receive and store the following:

  • Account information — Your name, email address, profile picture, and Google account ID, provided by Google Sign-In.
  • OAuth tokens — Access and refresh tokens that allow PromptMail to call Gmail on your behalf (read and send email) only while you use the service.
  • Session identifier — A unique token we generate to identify your session when you use PromptMail (e.g., from ChatGPT via our MCP server).

When you use PromptMail to send or read email, we use the Gmail API to access only the data necessary to perform those actions (e.g., message content for sending or listing). We do not collect or store the full contents of your emails on our servers beyond what is needed to fulfill a single request.

3. How We Use Your Data

We use the data described above only to:

  • Identify you and maintain your account and session.
  • Provide the core PromptMail features: sending emails and reading (listing, fetching) your emails when you ask ChatGPT or another connected client to do so.
  • Refresh your Google access token when it expires so the service continues to work.
  • Improve the reliability and security of the application (e.g., logging errors, investigating abuse).

We do not use your data for advertising, retargeting, or interest-based ads. We do not sell, rent, or share your data with data brokers or information resellers.

4. How We Store Your Data

Account information and OAuth tokens are stored on our servers in association with your account. We use industry-standard practices to protect data in transit (e.g., HTTPS) and at rest. Access tokens are used only to make API requests to Google and are refreshed as needed; we do not retain email content beyond what is required to complete a single operation (e.g., sending one email).

5. Data Sharing and Disclosure

We do not sell or rent your personal information. We may share or disclose data only in these limited circumstances:

  • To provide the service — For example, we send requests to Google's Gmail API using your authorized access so that emails can be sent or read as you request.
  • For security or legal reasons — To investigate abuse, comply with applicable law, or respond to valid legal process.
  • Business transfer — In the event of a merger, acquisition, or sale of assets, we would only transfer user data with your explicit prior consent as required by applicable policy.

We do not transfer or use your data for serving ads, for credit-worthiness or lending purposes, or to third parties like advertising platforms or data brokers.

6. Google API Services and Limited Use

PromptMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We use data obtained from Google (including Gmail) only to provide or improve user-facing features that are prominent in PromptMail (sending and reading email from ChatGPT).
  • We do not allow humans to read your email content unless you have given affirmative agreement (e.g., by asking to view or send a specific message), except where necessary for security (e.g., investigating abuse) or to comply with law.
  • We do not transfer user data to third parties for advertising, and we do not use or sell your data for ad targeting, retargeting, or similar purposes.

7. Security

We take reasonable steps to protect your data. We use HTTPS for all traffic, secure storage for credentials, and limit access to data to what is necessary to operate and secure the service. If you believe your account or data has been compromised, please contact us.

8. Your Choices and Rights

You can revoke PromptMail's access to your Gmail account at any time via your Google Account permissions. You may also sign out of PromptMail from our website. If you want your account data deleted from our systems, please contact us using the details below.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. If we make material changes to how we use Google user data, we will notify you and ask for your consent where required by Google's policies before using your data in the new way.

10. Contact Us

If you have questions about this Privacy Policy or our handling of your data, you can reach us at: support@promptmail.to.