←Back to home

Privacy Policy

We keep mail data limited to what Vilo Mail needs.

Vilo Mail uses Google sign-in, browser storage, and a Cloudflare Worker backend to power the extension, Pro membership, and optional AI features. This page explains what we process, why we process it, and how you can control it.

Last updated: July 19, 2026

What we collect

Vilo Mail is built to collect only what the product needs. Depending on how you use it, we may process:

  • Cloudflare operational logs generated when you load the site or call the backend API.
  • Your Google account profile, including email address, name, avatar, and Google subject ID.
  • Google OAuth tokens and Vilo Mail session tokens used to keep Gmail connected.
  • Extension state stored locally in your browser, including connected accounts, settings, email cache, AI results cache, pending actions, action history, and UI preferences.
  • Gmail message content, message metadata, sender and recipient fields, labels, thread data, and attachment metadata that the extension fetches on your behalf.
  • Plain-text email, thread, or draft context you choose to process only when you enable and use Cloud AI.
  • Membership and billing records, such as Pro status, Pro activation code grants, billing customer and subscription IDs, activation-code status, and AI usage counts.
  • Information you submit through waitlist, feedback, or support forms.

Raw Google user data

The raw Google user data Vilo Mail accesses is limited to your Google account identifier, email address, name and avatar; OAuth credentials and granted scopes; and the Gmail message content, headers, sender and recipient fields, labels, threads, attachment metadata, settings and filters required by the features you request. Attachment file data is accessed only when you open, download, forward or otherwise use that attachment.

Aggregated or anonymized Google data

Vilo Mail does not create aggregated or anonymized datasets from Gmail bodies, subjects, sender or recipient fields, attachments or OAuth credentials for analytics, advertising, sale or AI model training. We keep non-content service metrics such as AI request counts, API success or failure status, and timing information. Those metrics do not contain Gmail bodies, subjects, sender or recipient fields, attachment data or OAuth tokens.

How we use it

We use this information to operate Vilo Mail and provide the features you request.

  • Sign you in with Google, connect Gmail accounts, and refresh authorized sessions.
  • Load inbox data and perform requested Gmail actions such as send, mark read, trash, block, or unsubscribe.
  • Keep local preferences, cached mail, and action history available between uses.
  • Generate an AI summary, timeline, or draft when you request that optional feature.
  • Manage Pro access, trials, Pro activation codes, billing claims, checkout, and subscription status.
  • Send recovery or billing-claim emails and respond to support requests.
  • Diagnose bugs, protect the service, and maintain performance.

Raw Google user data is used only to provide or improve the user-facing features described above, maintain security, or comply with law. Non-content service metrics are used only for feature limits, reliability, abuse prevention and troubleshooting. Neither raw Google user data nor non-content service metrics are used for targeted advertising, credit or lending decisions, data brokerage, or training general AI/ML models.

Google OAuth scopes and justification

Vilo Mail uses Google OAuth to connect Gmail. We request the following scopes because each is required by a production user-facing feature:

  • openid — authenticate the Google account and bind the Vilo Mail session to Google's stable account identifier.
  • email — display and distinguish the connected Gmail account and route each requested action to the correct account.
  • profile — display the connected account's name and avatar in the account selector.
  • https://www.googleapis.com/auth/gmail.modify — read and display Gmail messages and threads; compose and send user-authored mail; and perform user-requested actions such as mark read, archive, label, trash and restore. Read-only or metadata-only scopes cannot load all message bodies or perform these mutations, while separate send-only scopes still cannot support inbox triage. Vilo Mail does not request the broader https://mail.google.com/ scope and cannot permanently delete messages while bypassing Trash.
  • https://www.googleapis.com/auth/gmail.settings.basic — create, inspect and remove Gmail filters only when you use block sender or unblock sender. Gmail modify does not grant settings/filter access, and Vilo Mail does not request the broader Gmail settings sharing scope.

The Worker stores Google refresh and access tokens encrypted in Cloudflare D1, hashes Vilo Mail session tokens, and returns short-lived access tokens to the extension so the browser can call Gmail APIs for your requested actions.

Vilo Mail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Local browser storage

The extension keeps its working data in your browser using Chrome storage and IndexedDB. This includes inbox cache, thread details, pending mailbox operations, action history, AI insight cache, contact suggestions, and settings such as Cloud AI consent. Removing an account clears that account's cached mail, mailbox projection, pending actions and AI results. Logging out of all accounts clears all Vilo Mail Chrome local storage and IndexedDB data. Browser storage controls or uninstalling the extension also remove this local data.

Backend storage

Cloudflare D1 stores account, session, membership, billing, waitlist, and support records. We do not store the normal inbox cache or full email bodies in D1. OAuth tokens and billing recovery codes are encrypted; Vilo Mail session tokens and billing claim codes are stored as hashes.

Optional Cloud AI processing

Cloud AI is disabled by default and requires consent before new AI content requests are sent. When you use an AI summary, timeline, or draft feature, the extension sends the necessary plain-text email, thread, or draft context through Vilo Mail servers to Cloudflare Workers AI. We do not send raw email HTML and do not store AI request text in the Vilo Mail database. We do not use Google user data, Gmail content, or AI request text to train AI models.

Membership and payments

Pro membership may use checkout billing or a Pro activation code. Our payment provider processes payment details on its systems. Vilo Mail stores only the records needed to connect payment status to your Vilo Mail account, such as customer IDs, subscription IDs, plan IDs, billing period, product state, activation-code status, and webhook updates. Activation-code emails are sent through Mailgun.

Sharing and selling

We do not sell your personal information, Gmail data, or inbox content, and we do not use it for advertising. We transfer data only as needed to provide a feature you request, maintain security, comply with law, or respond to a valid legal request:

  • Google APIs receive OAuth credentials and the Gmail read, send, settings or mailbox mutation requests you initiate. Sent message content and attachments are transferred to Gmail for delivery.
  • Cloudflare infrastructure processes the Google profile fields, encrypted OAuth tokens, hashed Vilo Mail sessions, membership records and non-content operational metrics needed to run Vilo Mail. The normal inbox cache and full Gmail bodies are not stored in Cloudflare D1.
  • Cloudflare Workers AI receives only the necessary plain-text email, thread or draft context when you have enabled Cloud AI and request an AI feature. Vilo Mail does not permit that data to be used to train general AI/ML models.
  • Payment providers and Mailgun receive billing identifiers or an email address only when needed for checkout, subscription administration, billing recovery or delivery of an activation email. They do not receive Gmail message content.
  • Sender-provided unsubscribe endpoints receive the unsubscribe request, including the minimum address or message information required by the sender's advertised unsubscribe method, only when you choose Unsubscribe.

Vilo Mail does not transfer raw, aggregated or anonymized Google user data to advertisers, data brokers, lenders, or third parties for their independent purposes.

Cookies and storage

The website may use cookies for membership sessions and checkout flow state. The extension uses browser storage for product state and cache. We do not rely on advertising cookies or third-party ad trackers.

Admin access

Internal pages for waitlist or support review are protected by Cloudflare Access. We limit human access to personal data to authenticated team members who need it for support, security, billing, or operations. We do not allow humans to read your Gmail messages or other Google user data unless we first obtain your affirmative agreement to view specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized for internal operations. Human access to Gmail content is not part of normal operation.

Retention

  • Local Gmail data remains in the browser only until you remove that account, log out of all accounts, clear extension storage, or uninstall Vilo Mail.
  • AI request content is processed for the requested response and is not persisted in the Vilo Mail database. AI results cached locally follow the same deletion triggers as local Gmail data.
  • Google OAuth authorization is retained while the Gmail account remains connected. Vilo Mail app sessions expire after 30 days unless renewed. Account removal or logout marks the sessions revoked, erases stored Google access and refresh token material, and sends a revocation request to Google before local account data is cleared.
  • Account, membership and billing records are retained while the account or paid service is active and afterward only as needed for support, fraud prevention, legal, tax, accounting or dispute-resolution obligations.
  • Waitlist, support and operational records are retained only while needed to answer the request, secure and operate the service, or satisfy applicable legal requirements.

When a retention purpose ends, Vilo Mail deletes or de-identifies the record. Any legally required retained record is isolated from product use and is not used for advertising, AI training or unrelated analytics.

Your choices

You can disable Cloud AI at any time; when disabled, the extension blocks new AI content requests. You can remove one connected Gmail account or log out of all accounts to revoke the corresponding Vilo Mail sessions, erase stored OAuth token material, and clear the applicable local Gmail data. You can also remove Vilo Mail access from your Google account, clear browser storage, uninstall the extension, or stop using the service at any time. To request deletion of account data, waitlist data, support submissions, or related service records, contact us at the address below. After verifying the request, we delete or de-identify those records except where retention is required for legal, security, tax, accounting or dispute-resolution reasons.

Security

We use reasonable safeguards including encrypted OAuth token storage, hashed session and claim tokens, Cloudflare Access for internal pages, provider webhook signature checks, and HTTPS. No online system is perfectly secure, so keep your browser and operating system updated and protect access to your Google account with strong authentication.

Changes to this policy

We may update this policy when the product or legal requirements change. If the change is significant, we will revise the date on this page and update the site accordingly.

Contact

Questions about this policy or the product can be sent to support@vilomail.com.