Privacy Policy
Last updated: 2026-09-09
Who operates the Service
The Gmail Cleaner application ("the Service") is operated by Ulf Jährig, the data controller for the purposes of the EU General Data Protection Regulation (GDPR).
Contact: ujaehrig@gmail.com
What the Service does
Gmail Cleaner lets you define Gmail search queries and then bulk-moves the messages matching those queries to your Gmail Trash. It performs only two actions against your mailbox: searching for messages that match your queries, and moving matched messages to Trash (a reversible action; Gmail retains trashed messages for about 30 days). It never sends email, never permanently deletes messages, and never reads or stores the body or contents of your messages.
Google account data and OAuth scopes
To act on your behalf, the Service uses Google OAuth 2.0 and requests:
openidandemail— to identify you (your Google account identifier and email address).https://www.googleapis.com/auth/gmail.modify— the least-privilege scope that allows moving messages to Trash. The Service uses it only to search for messages and to add theTRASHlabel to messages matching your configured queries.
The Service's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
What we store
- Account identity: your Google account identifier and email address.
- Gmail refresh token: a Google credential that lets the Service obtain short-lived access tokens, stored encrypted at rest when an encryption key is configured.
- Application access tokens: stored only as a one-way hash, never in plaintext.
- Your queries: the Gmail search strings you configure, their names, enabled state, and automatic-purge schedule.
- Audit log: a record of each purge — the query run, matched/trashed counts, duration, any error, and the Gmail message IDs moved to Trash (identifiers only, not message content).
We do not store the content, subjects, senders, recipients, or bodies of your email messages.
How we use the data
- To authenticate you and associate your configuration with your account.
- To execute the searches and trash operations you configure.
- To provide the audit log so you can verify what was trashed.
We do not sell your data, use it for advertising, share it with third parties for their own purposes, or use it to train AI/ML models.
Data sharing
- Google: the Service communicates with the Gmail API to perform searches and trash messages on your behalf.
- Hosting: the Service runs on the operator's own server on OVH, where the database resides.
Data retention and deletion
Your data is retained while your account exists in the Service. You can revoke the Service's access at any time from your Google Account permissions, and you can request deletion of your stored data by contacting ujaehrig@gmail.com.
Security
- Gmail refresh tokens are encrypted at rest (when configured); application tokens are stored only as hashes.
- Access is over HTTPS in production deployments.
- Session cookies are signed, HttpOnly, and
SameSite=Lax; state-changing forms are CSRF-protected.
Your rights (GDPR)
If you are in the EU/EEA you have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing. The legal basis for processing is your consent, which you may withdraw at any time by revoking access and requesting deletion. To exercise these rights, contact ujaehrig@gmail.com. You may also lodge a complaint with your local data protection authority.
Children
The Service is not directed to children under 16 and does not knowingly collect their data.
Changes to this policy
We may update this policy; the "Last updated" date reflects the latest version.