Privacy Policy
Last updated: 6th May 2026
1. Introduction
MailZen ("we", "our", or "us") is a unified email operations platform that enables businesses to connect their email accounts, manage inboxes, send campaigns, and collaborate on shared mailboxes. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform.
By using MailZen, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account or are invited to MailZen, we collect:
- Name and email address
- Company name and role within your organization
- Authentication credentials (passwords are hashed using bcrypt; we never store plaintext passwords)
2.2 Google Account Data (OAuth)
When you connect a Google/Gmail account, MailZen requests access via Google OAuth 2.0. We collect and store:
- OAuth access token and refresh token — used solely to send and read emails on your behalf via the Gmail API. These are stored encrypted in our database.
- Gmail address — used to identify and display the connected mailbox.
- Email content — we access your inbox, sent, drafts, and other folders strictly to display them within the MailZen interface. We do not use email content for advertising, training AI models, or any purpose beyond providing the service to you.
2.3 Microsoft Account Data (OAuth)
When you connect a Microsoft/Outlook account, we similarly collect OAuth tokens and your Microsoft email address. The same data handling principles apply as with Google.
2.4 Manual SMTP/IMAP Credentials
If you configure a mailbox using SMTP/IMAP (for Zoho, Yahoo, custom domains, etc.), your SMTP and IMAP credentials (host, port, username, and password) are stored encrypted in our database. These are used exclusively to connect to your mail server to read and send emails on your behalf.
2.5 Email Campaign Data
For bulk email campaigns, we process your contact lists, email templates, and campaign metrics (opens, clicks, unsubscribes). This data is stored within your organization's workspace and is not shared with other organizations.
2.6 Usage and Log Data
We collect activity logs for security and audit purposes, including:
- Login timestamps and IP addresses
- Actions taken within the platform (mailbox connections, emails sent, campaigns launched)
- Browser and device information
3. How We Use Your Information
We use the information we collect to:
- Provide and operate the MailZen platform
- Connect to your email accounts and perform actions you authorize (read, send, manage emails)
- Send bulk email campaigns to your contact lists on your behalf
- Display your inbox, sent mail, drafts, and other email folders
- Enable collaboration on shared mailboxes within your organization
- Provide campaign analytics (open rates, click rates, unsubscribes)
- Ensure platform security and prevent unauthorized access
- Comply with legal obligations
4. Google API Limited Use Disclosure
MailZen's use of information received from Google APIs is limited to the practices disclosed in this privacy policy. Specifically:
- We only access Gmail data that the user has explicitly authorized.
- We do not use Gmail data for serving advertisements.
- We do not allow humans to read user emails unless required by law, for security purposes (e.g., investigating abuse), or with the user's explicit consent.
- We do not use or transfer Gmail data for any purpose other than providing MailZen features directly requested by the user.
- We do not use Gmail data to develop, improve, or train generalized AI or ML models.
This disclosure is consistent with the Google API Services User Data Policy — Limited Use Requirements.
5. Data Storage and Security
We take data security seriously and implement industry-standard protections:
- Passwords are hashed using bcrypt with a salt factor of 12 — we never store plaintext passwords
- OAuth tokens are stored encrypted in our database
- SMTP/IMAP passwords are stored encrypted
- All data transmission uses HTTPS/TLS encryption
- Access to your data is restricted to authenticated users within your organization
- Activity logs provide a complete audit trail of all actions
While we implement reasonable security measures, no method of electronic storage or transmission over the internet is 100% secure. We encourage you to use strong passwords and enable appropriate access controls within your organization's workspace.
6. Data Sharing and Third Parties
We share your data only in the following limited circumstances:
- Within your organization: Users you invite and grant access to shared mailboxes can view those mailboxes. Personal mailboxes are visible only to you.
- Email providers (Google, Microsoft): We transmit data to Google and Microsoft APIs to perform authorized email operations on your behalf.
- Legal requirements: We may disclose your data if required by law, court order, or governmental authority.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before this occurs.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
7. Data Retention
We retain your account data for as long as your organization's account is active. Email thread and message data cached in MailZen is used for display purposes and is periodically refreshed from your connected email provider. You may request deletion of your account and associated data at any time.
Disconnecting a mailbox removes the stored OAuth tokens and SMTP/IMAP credentials from our database. Email content cached in our system is deleted along with the mailbox connection.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data ("right to be forgotten")
- Portability: Request a portable copy of your data
- Revocation: Revoke OAuth access at any time via your Google account settings (myaccount.google.com/permissions) or Microsoft account settings
To exercise any of these rights, contact us at info@ergode.com.
9. Cookies
MailZen uses a single session cookie (mf_session) to maintain your authenticated session. This cookie is essential for the platform to function and does not track you across other websites. We do not use advertising cookies or third-party tracking cookies.
10. Children's Privacy
MailZen is intended for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify users within the platform and update the "Last updated" date at the top of this page. Continued use of MailZen after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: info@ergode.com
Application: MailZen
Data Controller: Your organization (the company that has deployed this instance of MailZen)