Your data in Mailfol
This page describes the current beta’s implemented data handling. It is not a complete commercial privacy policy. The operator’s legal identity, privacy contact, and applicable jurisdiction must be supplied before commercial launch.
Account information
Supabase manages Google and email/password sign-in. Mailfol receives your account identifier, email address, and display name when available. Authentication cookies maintain your session.
Workspace records
Your profile, clients, notes, tasks, and drafts are stored in a server-side database and associated with your authenticated user identifier. The app uses that identifier to restrict reads and writes to your records. This service does not claim end-to-end encryption.
Email access
Gmail and Outlook connections are available only after service activation and your explicit provider consent. Connected access tokens are encrypted in the database. This release reads up to 20 inbox messages on demand, displays text previews, and does not delete email. When sending is activated and you grant permission, Mailfol sends only after your explicit confirmation. Send request identifiers, content hashes, timestamps, and outcomes are retained to reduce duplicate sends. Mailbox previews are not saved to workspace records automatically. The demo contains fictional messages. Disconnecting deletes stored tokens; you can additionally revoke consent in your provider account.
AI assistance
When AI is activated and you explicitly consent, the text and instructions you enter in the assistant are sent to OpenAI to generate a draft. Mailfol requests that responses are not stored for later API retrieval; provider security and retention policies may still apply. Mailfol stores monthly request counts, not a separate prompt history. Generated drafts are saved to your workspace only when you choose Save draft. Never include confidential information you are not authorized to share.
Browser storage
The demo saves its sample workspace in local browser storage. Your signed-in workspace uses the database. Sidebar preferences may be stored in a browser cookie. The application has no advertising or third-party analytics added.
Infrastructure
Mailfol runs on Cloudflare with D1 application storage and Supabase authentication. Paddle processes payments and customer billing details; Mailfol stores subscription identifiers, status, plan, and billing event records. Interface fonts load from Google Fonts, which receives the network information necessary to serve those requests. Platform operators may process service and security logs.
Feedback
When you submit feedback, Mailfol stores your email address, message, and submission time. A new submission replaces your previous request.
Export and deletion
Export your workspace from Settings. Delete workspace data removes workspace records, your stored support request, mailbox tokens, and pending connection requests. Billing records, anti-abuse usage counters, and send deduplication metadata are retained. It does not cancel a subscription or delete your Supabase sign-in account or guarantee immediate removal from infrastructure logs or backups governed by platform retention.
Questions
Signed-in beta users can submit a data-handling question through Help & feedback.