Privacy policy
Effective September 30, 2026. MailReveal is operated by Ilias Miraoui. For privacy questions or a data deletion request, contact ilias.miraoui@gmail.com.
What MailReveal does
MailReveal helps a workspace track email image loads, prepare and send tracked emails, save Gmail drafts, and share activity with integrations selected by the workspace owner. The current release is a private workspace with one connected Gmail account. Workspace access is controlled by its owner; it does not yet provide separate customer accounts.
Information we access and store
We store the recipient, subject and body of messages you prepare, sending status, timestamps, provider message and thread identifiers, signature details, and image-load events. An event includes its timestamp, associated message or signature, and a source category such as Gmail image proxy. Image loads can be caused by previews, proxies or automated services and do not prove that a person read an email. A reused signature does not identify a particular recipient or email.
Image requests and website visits reach our hosting provider, which may process connection information such as IP addresses and browser headers in operational logs. MailReveal uses the image request's user-agent to classify the signal; the application event table does not store raw IP addresses or user-agent strings.
Google and Gmail data
The optional Chrome extension runs on Gmail to insert trackers into compose windows. It sends the sender, recipient and subject to MailReveal; it does not upload email body content. Its scoped API key is stored locally in the extension, outside the Gmail page. Chrome permissions allow access to Gmail and MailReveal and block direct MailReveal tracking-image requests originating in your browser’s Gmail page. Disconnect the extension or revoke its key to stop creating trackers. Uninstalling removes its browser access.
Connecting Google gives MailReveal your account email address and OAuth credentials. Gmail compose access is used to create tracked drafts and send emails you request. Gmail read access verifies the connected account and reconciles tracked drafts or uncertain sends with Sent mail. A manual sync inspects up to 100 recent Sent messages within 30 days. Unrelated message bodies and headers are processed transiently for matching and are not saved in the MailReveal message database. Matched messages can provide recipient, subject, sending date and Gmail identifiers.
Google client secrets and OAuth access and refresh tokens are encrypted in the application database using AES-256-GCM. Google handles authentication; MailReveal does not collect your Google password.
MailReveal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used to provide the email features you authorize. We do not sell Google user data, use it for advertising, or use it to train generalized AI or machine-learning models. Human access is limited to your authorization, necessary security investigations, legal requirements, or aggregated internal operations as permitted by that policy.
Sharing and integrations
Google processes mail sent or saved through Gmail. Vercel hosts the application and Turso stores application records. These providers process data to operate the service. The workspace owner can approve API keys and agents with specific permissions and configure signed webhooks to trusted destinations. Authorized integrations can retrieve workspace data; email-activity webhooks include the recipient, subject, message status and event information. Only connect destinations and agents you trust. We do not sell personal data.
Retention, disconnection and deletion
Workspace messages, signatures and activity are retained until the workspace owner requests their deletion; automatic expiry is not currently enabled. Disconnect Gmail in Connections to revoke Google access and remove the stored mailbox credentials. Disconnecting does not delete existing tracked messages or emails in Gmail. You can also revoke access in your Google Account.
To request access, correction or deletion of MailReveal data, email the privacy contact above with the relevant mailbox or workspace. We verify your authority before processing the request. Provider logs and backup copies may remain until the provider's normal retention cycle expires. We will explain any legal retention requirement that prevents deletion.
Cookies and changes
MailReveal uses essential cookies for workspace authentication and the Google connection flow. Changes to this policy will be published here with an updated effective date. Material changes to the use of Google data require appropriate notice and authorization.