What we do with your data
Privacy Policy
Short version
We connect to your Gmail to clear your inbox. Your mail never touches our servers; reading and clearing run in your browser, direct to Google. (The one paid one-click unsubscribe relays just the sender's unsubscribe link through us, because your browser can't; details below.) If you buy access, we store exactly one thing: who you are and what you paid for. Never your mail. Vail0 does not allow human review of your Google user data.
What we access
When you sign in with Google, we request permission to modify your Gmail. For the free clear, your browser accesses only the message IDs needed to remove the UNREAD label. If you use the paid cleanup tools, your browser additionally reads message headers (sender, mailing-list ID, unsubscribe address) to build your sender list, sends unsubscribe emails from your own account when you ask it to, marks mail as read when you ask it to (nothing is deleted or moved), and writes labels. All of it happens in your browser, directly with Google. None of it is visible to Vail0's servers.
What we do with it
Exactly what you clicked, and nothing else: clear, count, unsubscribe, label. Every action is something you asked for on screen. Nothing runs after you leave the page.
What we store if you buy access
Paid access is tied to your Google account, so there's nothing to store or lose on your end. To honor your license, our server keeps the minimum possible record, stored encrypted on AWS:
- Your Google account identifier and email address
- Which license you bought and when it expires
- A reference to the Stripe payment (Stripe processes your card — we never see the number)
- If you arrived through a creator's link, the referral code that credits them. We ask before keeping it: allow, and it's held in your browser's localStorage for up to 30 days (the most recent creator link you clicked wins, and your choice is remembered so we don't ask again); decline, and it lasts only until you close or reload the page — nothing is stored
- So you aren't asked to sign in again on every visit, your browser keeps a small signed pass in localStorage for up to 30 days. It contains only your Google account identifier — no email address — and it can't touch your mail. Our server still checks your actual license every time the pass is used, so it stops working the moment a license expires or is refunded.
That's the entire record. It contains nothing from your mailbox — no message content, no message IDs, no tokens. We also send service emails about that license through Resend: a receipt when you buy, and we may send a heads-up before your license expires or a note when your existing access gains a new feature. If you click “Email me this summary” after a cleanup, our servers process that summary — your counts and remaining unsubscribe links — briefly to send it to you, but don’t store it. We do not send users marketing emails. You can ask us to delete the record at any time. If you never ask, we delete it anyway: the record self-destructs 180 days after your license expires. (Deleted records can persist in our encrypted backups for up to 35 days before those cycle out.)
What lives in your browser
The complete list of what Vail0 keeps in your browser's localStorage — there are no cookies, no analytics scripts, and no trackers:
- The signed sign-in pass (
vail0_license) and, if you allowed it, a creator referral code and your consent choice (vail0_ref,vail0_ref_consent) — all three described above - A resume marker while a clear is running (
vail0-clear-resume): only counts — how many messages the run covers and how many are done — so an interrupted clear can offer to pick up where it left off. Removed when the run finishes. - A one-time flag (
vail0_counted) noting this browser has already been counted in our anonymous usage total, so it isn't counted twice. Its value is literally1— no identifier, nothing about you.
Nothing else, ever. Clearing your browser's site data removes all of it and breaks nothing — a paid license lives on our server, tied to your Google account, and comes right back when you sign in.
The tools' memory lives in your mailbox, not our database
So the paid tools don't re-offer a mailing list you've already unsubscribed from, they mark handled messages with hidden vail0/ labels inside your own Gmail. Hidden means tidy, not secret: they're your labels, in your account, readable by you, and deleting the vail0/ labels erases the memory completely. Nothing about what the tools did is recorded on our side. More detail →
What we can technically see with that permission
In the interest of full transparency: gmail.modify technically grants broader access than we use. We could read full message content and subject lines. We don't — no Vail0 code path requests message bodies or subjects, in any tier. The free clear accesses only the list of message IDs that carry the UNREAD label and removes that label. The paid tools additionally read the sender and mailing-list headers described above — on your screen only, never sent to us.
You can verify exactly what API calls we make here: how it works →
How we protect your data
- All communication between your browser and Google APIs is protected using Transport Layer Security (TLS). Our hosting on AWS Amplify ensures that all traffic is served over a secure HTTPS connection with industry-standard 256-bit encryption.
- When you use Vail0 to clear your inbox, your Google access token lives only in your browser's volatile memory (RAM). It is never written to a database, a cookie, or permanent storage. Data is deleted immediately after the task is completed or the session is closed.
- Reading your inbox and marking mail as read happen directly between your browser and Google's servers. Your personal Gmail data never touches a Vail0 server. The one exception is the paid one-click unsubscribe: because your browser's security policy won't let it send the unsubscribe request straight to a sender's servers, Vail0 relays that single request for you. Only the mailing list's own unsubscribe link passes through; we don't store it, and we log just the sender's domain and whether it succeeded, for a short period. Nothing from your mailbox is part of it.
- We do not scrape your Gmail profile for contact info. The only personal data we collect is the license record described above, and only if you buy access.
- Vail0 itself sets no cookies. Google's sign-in library — and Stripe, only if you open checkout — set their own cookies for sign-in and fraud prevention, governed by Google's and Stripe's privacy policies.
- Our pages load fonts from Google Fonts. Like any web request, that shares your IP address and browser info with Google.
- If you use the optional share feature, your browser generates an image containing only your cleared-email count and uploads it to our storage so the link can be previewed. It's visible to anyone with the link and auto-deletes after 90 days. Nothing else from your session is in it.
- The JavaScript that runs this site is readable in your browser's developer tools at any time. You can verify every API call we make.
- Vail0's use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.
What we never do
- Read your email content
- Store any information about your emails on our servers
- Sell or share your data. The only third parties that process it are Stripe (payments), Resend (service emails), and AWS (hosting and the license database), each receiving ONLY what that job requires
- Use your Gmail access for advertising
- Retain anything from your Gmail session after it ends — the only thing that persists on our side is the license record described above, and only if you bought one
- Write your message IDs, email content, or email address into server logs — your address lives only in the encrypted license record (if you bought access), with Stripe, and in the service emails we send you (the paid one-click unsubscribe briefly logs only the sender's domain and result, as described above)
- Auto-renew anything — licenses simply expire
- No human at Vail0 will ever read your emails or data.
How the token works
When Google authorizes Vail0, it issues a short-lived access token that your browser uses to make API calls directly to Google's servers. This token lives only in your browser's memory. It is never written to a cookie, never stored in localStorage or sessionStorage after the auth flow completes, never transmitted to Vail0's servers.
The token expires after one hour. It's gone immediately when you close the tab. After that, Vail0 has no access to your Gmail account whatsoever.
Revoking access
You can remove Vail0's access to your Google account at any time: myaccount.google.com/permissions. Find Vail0 in the list and click Remove Access. We have no way to retain access after you revoke it.
Children
Vail0 is not directed at anyone under 13.
Delete your data
The only thing we store server-side is your paid license record (your Google identifier, email, and what you bought). You can delete it yourself here, or email privacy@vail0.com and we'll remove it. Free users have nothing stored on our servers to delete.
Questions
Reach out at privacy@vail0.com with any privacy question or data request.