01Who we are
Mailroom is a software product and related digital service operated by the Mailroom business entity. For data-protection purposes, that entity is the data controller for the limited personal data described in this notice, and can be reached at the addresses below.
You can reach us by email: contact@mailroomclean.com for privacy and legal questions, and support@mailroomclean.com for support and billing.
02Our core privacy principle — local-first
All mailbox scanning, classification, and cleanup happen on your own device. Mailroom is designed so that your email content (message bodies), senders, subjects, and folder names never leave your device.
That information is never sent to Mailroom, to any Mailroom server, or to any third party. The product works by reading message metadata locally and applying its own product logic on your device — not by uploading your mailbox somewhere to be read.
To show you where your space has gone, Mailroom also reads attachment names, types and sizes — never the file contents. An attachment's file name is treated as private data: it is used only on your device and it never leaves it.
Your messages, senders, subjects, folder names, and attachment file names stay on your device. We do not receive them and we cannot read them.
03What leaves the device
Apart from the direct connection to your own mailbox described in section 06, Mailroom makes four kinds of outbound network call. None of them carries any mailbox content. Three of the four run in the app you can install today; the fourth is not reachable in this release. They are:
- a startup update check — Mailroom downloads a small public version file to see whether a newer version of the app exists. It is a plain download of a public file, with no user identity attached, in the same way any web browser fetches a public page. This runs in every build;
- a pricing catalog fetch — Mailroom downloads the public pricing and plan file so the app can show current prices and tiers. This is the same kind of plain download of a public file, with nothing about you attached. This runs in every build;
- a licensing check and usage meter — Mailroom validates your licence and records the volume of reclaimed space (for example, reclaimed megabytes). This data is pseudonymous: it is tied to your licence and your device rather than to your name or your mailbox, and it carries no mailbox content. This runs in every build; and
- a browser sign-in to your own email provider — for providers that require a browser sign-in (OAuth) rather than an app password, the app opens that provider's own sign-in page and the exchange happens between you and your provider; nothing about it reaches Mailroom. This is not reachable in the current release: Mailroom supports Yahoo only today, and Yahoo is connected using an app password, so this path is never used in the app you can install. It is listed here because the code exists, not because it runs.
That is the complete list of network calls the app itself makes. Buying a licence also opens a checkout page in your own web browser, which you complete with our payment provider (section 06). Everything else — scanning, classification, review, and deletion — happens on your own device.
04Mailbox credentials
If you choose to save your mailbox credentials (for example, a Yahoo app password), they are stored in your operating system's secure credential store — Windows Credential Manager or the OS keyring — encrypted by the operating system and kept local to your device.
Saving credentials is optional. Your credentials are never transmitted to Mailroom servers. They are used only on your device to connect to your mailbox.
05Limited service records we do process
For licensing, billing, security, fraud prevention, refunds, and support, Mailroom processes a limited set of pseudonymous service records. These may include:
- pseudonymous licence identifiers;
- entitlement and activation events;
- meter values (for example, reclaimed megabytes);
- device-related identifiers; and
- service-consumption records reasonably required to determine whether paid functionality was made available and used.
These records contain no email body content. This is consistent with the "service-consumption evidence" described in the Terms of Use.
06Third parties and processors
Mailroom keeps third-party data sharing to a minimum:
- the licensing backend (self-hosted) and the licensing provider (Keygen) receive only the pseudonymous licence and meter data described above;
- your email provider (Yahoo today, with more planned) is connected to directly from your device over IMAP using your own credentials — Mailroom is not a man-in-the-middle and does not relay your mailbox through its servers; and
- payment processing is handled by Stripe, a third-party payment provider. When you buy a licence, your card details are entered with Stripe and go to Stripe — Mailroom does not receive or store full card details.
07Local data on your device
Scan results, mailbox metadata, settings, and logs are stored locally on your device (for example, under %LocalAppData% on Windows) as part of the product's normal operation.
You can delete this local data at any time. Once removed, that deletion may not be reversible.
08No behavioural telemetry, no ads, no data sales
Mailroom does not run behavioural analytics, does not show advertising, and does not sell personal data.
Section 03 lists every outbound channel the app has, and none of them carries mailbox content. If that ever changes, this notice changes with it: we will not add an outbound channel without describing it there first.
09The website
The Mailroom website sets no cookies and stores nothing in your browser. It does not run third-party advertising or cross-site tracking, and it loads no third-party resources — the fonts are served from this site.
10Data retention
The limited service records described above are kept only for as long as needed for licensing, accounting, fraud and dispute handling, and legal obligations.
After that, they are deleted or anonymised.
11Your rights
Depending on where you live, applicable data-protection law (including UK GDPR) may give you rights over your personal data, including the rights to:
- access the personal data we hold about you;
- have inaccurate data rectified;
- have your data erased;
- restrict or object to processing;
- data portability; and
- complain to a supervisory authority — in the UK, the Information Commissioner's Office (ICO).
To exercise any of these rights, email contact@mailroomclean.com. Because Mailroom holds only limited pseudonymous records, we may need information that helps us locate the records that relate to you.
12International processing
Where Mailroom processes the limited service records described above, that processing takes place on servers located in the EU (hosted with Hetzner).
Your mailbox content is not part of this processing — it remains on your own device.
13Changes to this notice
We may update this Privacy Notice from time to time. If a change is material, we will give notice by updating the website or the app.
14Contact
Privacy questions, rights requests, and other data-protection enquiries can be sent to contact@mailroomclean.com. For help with a purchase, your licence, or billing, email support@mailroomclean.com.