Privacy Policy
Effective date: March 27, 2026 · Last updated: March 27, 2026
1. What This App Does
Email Unsubscribe Manager ("the app") is a personal productivity tool that connects to your Google Gmail account to scan for emails containing unsubscribe links. It displays those emails in a single interface so you can unsubscribe from mailing lists quickly and track what you have already unsubscribed from.
The app is operated privately and access is restricted to explicitly invited users.
2. Google Account Access
When you sign in, the app requests the following Google OAuth scopes:
- gmail.readonly — read access to your Gmail messages and metadata. This is used solely to search for emails that contain unsubscribe links.
- userinfo.email / userinfo.profile — your email address, name, and profile picture. These are used to identify your account and display your name in the app.
The app cannot and does not send, delete, modify, or forward any of your emails. Access is strictly read-only.
3. Data We Collect and Store
We store the minimum data necessary to operate the app:
- Your email address, name, and profile picture — stored in the user allowlist to authenticate you and display your profile in the app.
- Session data — an encrypted session token stored in our database to keep you signed in. Sessions expire automatically after 24 hours (or 30 days if you choose "Remember me").
- Unsubscribe history — when you click an unsubscribe button, we log the sender domain, sender email address, unsubscribe URL, and the date and time of the action. This is used to mark previously unsubscribed senders in future scans.
We do not store email content, subject lines, message bodies, or any other data from your Gmail account. Email data is fetched in real time when you request it and is never written to persistent storage.
4. How We Use Your Data
Data collected is used exclusively to provide the app's functionality:
- To authenticate you and manage your session
- To display your name and profile picture within the app
- To track which senders you have previously unsubscribed from and surface that information in future scans
- To provide admins with an audit log of unsubscribe activity across the app's users
We do not use your data for advertising, analytics, profiling, or any purpose beyond operating the app.
5. Data Sharing and Third Parties
We do not sell, rent, or share your personal data with third parties.
The app uses the following infrastructure to operate:
- Amazon Web Services (AWS) — the app runs on AWS Lambda and stores data in AWS DynamoDB, both located in the
us-east-1region. AWS is bound by its own Privacy Policy. - Google APIs — Gmail and Google Sign-In are provided by Google LLC. Use of Google APIs is subject to Google's Privacy Policy.
The app's use of data obtained from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Retention
- Sessions are automatically deleted from our database when they expire (24 hours or 30 days depending on your preference).
- Unsubscribe history is retained indefinitely to power the "already unsubscribed" indicator. You may request deletion at any time by contacting the app administrator.
- Your account (email address, name, picture) remains in the allowlist until an administrator removes it.
7. Security
We take reasonable steps to protect the data we store:
- All traffic is encrypted in transit via HTTPS (TLS 1.2+) enforced by AWS CloudFront.
- Sessions are stored as encrypted tokens in AWS DynamoDB with automatic TTL-based expiry.
- Access to the app is restricted to allowlisted users only — there is no open registration.
- Google OAuth tokens are held in memory during your session and are not persisted to disk or database.
8. Your Rights and Choices
- Revoke access — you can revoke this app's access to your Google account at any time via Google Account Permissions. This will sign you out of the app immediately.
- Sign out — clicking "Sign out" in the app deletes your session immediately.
- Data deletion — to request deletion of your stored data (unsubscribe history, account entry), contact the app administrator.
9. Children's Privacy
This app is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
If this policy changes materially, we will update the effective date at the top of this page. Continued use of the app after changes are posted constitutes acceptance of the updated policy.
11. Contact
If you have questions about this privacy policy or how your data is handled, contact the app administrator at brad.l.doran@gmail.com.