Legal
Privacy Policy
Last updated: July 5, 2026
This policy is written for MailPlate as an email workspace. Because MailPlate connects to real mailboxes, this policy explains email-specific data handling in plain language. It is not a substitute for independent legal advice.
1. Who we are
MailPlate is operated and legally managed by Aahav Labs. The current public app domain is https://mailplate.aahavlabs.in. For privacy, support, data, or security requests, contact hi@aahavlabs.in.
Aahav Labs website: https://aahavlabs.in.
2. What MailPlate does
MailPlate lets you connect supported email accounts, including Gmail and custom IMAP/SMTP mailboxes, so you can view, search, triage, reply to, send, archive, delete, star, mark, and manage email from one workspace.
MailPlate is an email client/workspace layer. It does not replace your email provider. Your Gmail, Google account, IMAP server, SMTP server, domain host, and mailbox provider continue to operate under their own terms and privacy policies.
3. Information we collect and process
- Account profile data: your sign-in email address, display name if provided, user identifier, authentication metadata, account status, plan or usage limits, and basic preferences.
- Connected account metadata: connected mailbox email address, provider type, account identifier, connection status, sync timestamps, folder counts, and provider-specific identifiers.
- Gmail connection data: OAuth tokens, authorized scopes, refresh/access token metadata, and Google account email needed to access Gmail features you approve.
- Custom mailbox connection data: IMAP/SMTP hostnames, ports, usernames, encrypted passwords or app passwords, SMTP-specific password if provided, and connection test results.
- Mailbox data: email metadata such as sender, recipients, subject, dates, message IDs, thread IDs, labels, folders, unread/starred state, snippets, and attachment metadata.
- Email content: message bodies, draft bodies, reply/forward content, and provider attachment data when needed to display, compose, send, search, or download mail.
- Actions and audit data: actions such as read/unread, archive, trash, delete, spam, star/unstar, send, sync, account connect/disconnect, export, and deletion requests.
- Technical and security data: IP-derived request metadata, device/browser details, error logs, performance timings, rate-limit events, abuse-prevention signals, and security diagnostics.
- Support communications: information you send to us by email or other support channels.
4. Why we process this data
- To connect your selected mailboxes and verify that the connection works.
- To display your inbox, folders, message bodies, attachments, drafts, replies, sent mail, and mailbox state.
- To let you send messages through Gmail APIs or your configured SMTP server.
- To apply actions you choose, such as read/unread, archive, trash, delete, spam, star/unstar, and sync.
- To cache mailbox data for faster search, folder switching, triage, and reading-pane performance.
- To secure the service, prevent abuse, debug failures, recover from sync errors, and maintain auditability.
- To provide support, service notices, account notices, and security-related communication.
- To comply with applicable legal obligations and respond to valid legal requests where required.
5. Gmail and Google API data
When you connect Gmail, MailPlate requests Gmail permissions only for product functions such as reading mailbox data, sending messages you intentionally send, and applying mailbox actions you choose.
MailPlate uses Google API data only to provide and improve user-facing MailPlate features. We do not sell Gmail data, use Gmail data for advertising, transfer Gmail data to advertising platforms, or use Gmail data to train generalized AI models.
If you disconnect Gmail from MailPlate, we stop using the stored connection to access that account. You can also revoke MailPlate access from your Google Account security settings. Revoking access in Google may immediately prevent MailPlate from syncing or sending through Gmail.
6. IMAP and SMTP mailbox data
When you connect a custom mailbox, MailPlate uses the IMAP settings to read and sync mailbox data, and SMTP settings to send messages you initiate. You should only connect mailboxes that you own or are authorized to access.
Some providers require app passwords instead of your normal account password. You are responsible for following your provider's security requirements, including two-factor authentication and app-password rules where applicable.
7. Credentials, tokens, and security
- OAuth tokens, IMAP passwords, SMTP passwords, and similar secrets are encrypted before storage.
- Mail server connections use TLS where supported by the provider and where required by the configured port/protocol.
- We apply rate limits, same-origin protections, scoped mailbox actions, and server-side validation to reduce abuse risk.
- Some sensitive events may be logged for security, audit, debugging, and support.
- No internet service can be guaranteed perfectly secure. You should keep your MailPlate account, email provider account, and app passwords secure.
8. Caching, search, and retention
MailPlate may store cached copies of mailbox metadata and message content so the app can load faster, search more effectively, preserve folder state, and recover from provider latency or temporary provider errors.
Cached mailbox data is part of your MailPlate workspace. Removing a connected account or deleting your MailPlate account is intended to remove MailPlate's stored connection data and cached workspace data, but it does not delete email from Gmail, your IMAP server, or your original email provider unless you separately choose a mailbox action that deletes or moves messages there.
We retain account, connection, cached mailbox, support, audit, and operational data for as long as reasonably needed to provide the service, maintain security, debug issues, comply with legal obligations, and handle disputes or support requests.
9. Sharing and service providers
MailPlate depends on third-party infrastructure and service providers, including hosting, database, authentication, email provider APIs, email transport, logging, analytics, and security infrastructure. These providers process data only as needed for MailPlate to operate.
MailPlate does not sell your mailbox data. We do not provide your email content to advertisers. We may disclose limited information if required by law, to protect users or the service, to investigate abuse, or as part of a business transfer involving MailPlate or Aahav Labs, subject to appropriate safeguards.
10. Exports, deletion, and your choices
- Disconnect an account: removes that mailbox connection from MailPlate and stops future access through that connection. It does not delete the provider mailbox.
- Delete MailPlate workspace data: is intended to remove account data, connected account metadata, encrypted credentials/tokens, cached mailbox data, drafts/settings stored in MailPlate, and related workspace records, subject to legal, security, backup, and operational retention requirements.
- Export data: may include profile data, connected account metadata, settings, drafts or templates stored in MailPlate, cached mailbox records, and audit/security data where technically available and appropriate.
- Provider controls: you can revoke Gmail access from your Google Account and manage IMAP/SMTP passwords or app passwords through your email provider.
To request export, deletion, correction, or privacy support, contact hi@aahavlabs.in.
11. Children
MailPlate is not intended for children. Do not use MailPlate if you are not legally able to create an account or authorize mailbox access under the laws that apply to you.
12. International processing
MailPlate is managed from Surat, Gujarat, India by Aahav Labs. Infrastructure and service providers may process data in India, the United States, or other jurisdictions where their systems, vendors, or subprocessors operate.
13. Changes to this policy
We may update this policy as MailPlate evolves, including when we add features, providers, storage behavior, security controls, pricing, or legal requirements. The latest version will be published on this page with the updated date above.
14. Contact
Aahav Labs
Website: https://aahavlabs.in
Email: hi@aahavlabs.in
See also our Terms of Service.