1. Who operates SenderWho
SenderWho is operated by SenderWho. This policy applies to the SenderWho mobile application, backend service, and public website. Contact details are provided in section 12.
2. Information we process
We process only the information needed for the user-facing SenderWho features:
- Account and authorization data: email address, provider account identifier, display name and avatar when supplied by the provider, granted permissions, encrypted OAuth access and refresh tokens, connection state, and app-session records.
- Stored mailbox metadata: provider message and thread identifiers, sender name and address, domain, subject, short snippet, date, labels or flags, message size, attachment indicator, importance state, mailing-list unsubscribe headers, and authentication or identity-risk signals.
- Message content on demand: when you open a message, SenderWho retrieves its text and basic addressing and attachment details from your provider, sends that result to your app, and does not save the full body or attachment content in the SenderWho database.
- Your instructions and preferences: sender trust or block choices, categories, read/archive/trash/restore actions, cleanup selections, unsubscribe requests, settings, exports, and security-alert status.
- Security and operations data: request identifiers, IP address, user agent, hashed device identifier, device name supplied by the app, session and job status, safe error category, rate-limit records, and audit events.
3. Google and Yahoo permissions
SenderWho uses OAuth authorization and does not ask for or store your Google or Yahoo mailbox password.
- Google: SenderWho requests identity and email-address access plus the Gmail modify permission. This lets the service read the mailbox data described above and apply user-requested read, archive, trash, restore, organization, and cleanup actions.
- Yahoo: when Yahoo access is available, SenderWho requests OpenID identity, email and profile information, and Yahoo Mail read and write permissions. They are used for the same visible inbox, sender, organization, security, and user-requested mailbox-management features.
Permissions are requested during provider consent. SenderWho does not use these permissions to send marketing email or access a mailbox after its authorization credentials have been removed.
4. How we use information
We use data to authenticate you; connect and synchronize the mailbox you choose; list and display messages; identify and classify senders; calculate inbox-health, cleanup, and security signals; show trusted or blocked senders; perform the message and unsubscribe actions you select; maintain progress and retries; prevent abuse; diagnose service problems; provide support; and comply with applicable law.
Blocking a sender is an instruction that allows future messages found during scans to be moved to Trash. Cleanup and one-click unsubscribe actions are presented for review before they are started. One-click unsubscribe sends the standardized request to the sender's public HTTPS unsubscribe service; whether the sender honors it is controlled by that sender.
5. Google API and Yahoo data limited use
Google and Yahoo mailbox data is used only to provide or improve the user-facing features described in this policy. We do not sell mailbox data, use it for advertising, determine creditworthiness, build advertising profiles, or use it to train general-purpose artificial-intelligence models.
We do not permit employees, contractors, or other people to read mailbox content except when you affirmatively provide specific content for support, when access is necessary to investigate a security or abuse incident, when required by law, or when data has been aggregated so that it does not identify a user, subject to provider policy and applicable law.
6. Sharing and processors
We disclose data only as needed to operate the service:
- Your selected email provider processes authorization, mailbox reads, and mailbox changes.
- Hosting, database, network, and security providers process encrypted or access-controlled data on our behalf under service agreements.
- A sender's public unsubscribe service receives a standardized one-click request only when you ask SenderWho to unsubscribe.
- Authorities or other recipients may receive information when legally required, to protect users or the service, or during a business transfer with appropriate safeguards and any consent required by provider policy.
We do not transfer mailbox data to data brokers, advertising platforms, or unrelated third parties.
7. Storage, retention, and deletion
Full message bodies and attachment content are not stored in the SenderWho database. Stored mailbox metadata and short previews are retained under the current service default for up to 365 days based on message date. Completed background-job records are retained for up to 90 days. Security and audit records are retained for the configured audit period, currently no more than 730 days. Expired OAuth login records and expired or revoked sessions are removed on scheduled retention cycles.
Encrypted provider authorization tokens are retained while a connection remains active. Disconnecting clears those tokens and stops future synchronization but does not itself erase previously synchronized SenderWho metadata. Deleting the SenderWho account deletes the user record and associated SenderWho mailbox metadata, sender records, preferences, sessions, and jobs. Where infrastructure backups exist, residual encrypted copies are isolated from normal use and expire under the infrastructure provider's backup cycle, unless longer retention is legally required.
8. Security
We use measures designed to protect information, including HTTPS/TLS transport, application-level encryption for provider credentials, hashed app refresh tokens and device identifiers, authorization checks, limited session lifetimes, audit logging, rate limits, bounded background work, and restricted production configuration. No system is completely secure, so you should also protect your device and provider account.
Please do not send passwords, OAuth codes, tokens, or private message content in a support request. Suspected security issues can be reported through SenderWho Support.
9. Your controls and rights
You can review connected accounts and permissions, disconnect a mailbox, change supported preferences, manage trusted and blocked senders, export your SenderWho data, sign out sessions, and permanently delete your SenderWho account in the app. You can also revoke SenderWho directly in Google or Yahoo account settings.
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or a portable copy of personal information. See the account deletion page or contact us. We may verify account ownership before acting on a request.
10. International processing
SenderWho and its service providers may process information in countries other than the one where you live. Where required, we use appropriate safeguards for international transfers and continue to protect the information as described in this policy.
11. Children
SenderWho is not directed to children under 13, and we do not knowingly collect their personal information. A higher minimum age applies where local law requires it.
12. Changes and contact
We may update this policy when the service, provider permissions, or law changes. If a change materially expands how provider data is used, we will provide notice and obtain additional consent where required before applying the new use. The effective date identifies the current version.
Questions, privacy-rights requests, and security reports can be sent using the contact details below.
Contact: senderwho.app@gmail.com