Mailbreak

Privacy Policy

Last updated: 2026-04-30 · Effective: 2026-04-30

Plain-English summary: Your email content never leaves your device. We collect license info (whether you've paid, which tier) on a Supabase database we operate. Stripe handles payments — they see card info, we don't. You can revoke access anytime at myaccount.google.com → Security → Third-party access.

What Mailbreak collects

From your Google account, via the Gmail API

When you connect your Gmail account, Mailbreak requests three Gmail OAuth scopes:

This data is processed in your browser memory and on your device only. None of it is transmitted to any Mailbreak-operated server.

Locally on your device

Mailbreak stores the following in your browser's IndexedDB (encrypted at rest with AES-256, key held only in chrome.storage.session for the browser session):

This data auto-expires per the project's threat model (180 days for senders, 365 days for results, 10 000-entry cap on audit log).

From your Stripe payment, sent to our license server

If you purchase a paid plan, after Stripe confirms payment our backend receives a webhook and writes to our Supabase database:

We do NOT receive or store your full credit card number, CVV, or billing address. Stripe holds that.

What Mailbreak does NOT collect

Where data lives

DataLocationEncrypted at rest
Email headers (during scan)Your browser memory(in-memory only)
Sender recordsYour browser's IndexedDBYes (AES-256-GCM)
Unsubscribe resultsYour browser's IndexedDBYes (sensitive fields)
Audit logYour browser's IndexedDBNo (plaintext for tamper-evidence)
OAuth tokenchrome.storage.session(wiped on browser close)
License recordsSupabase (US region)Yes (Supabase-managed)
Stripe customer/transactionStripe's servers(per Stripe's policy)

Who we share data with

Your rights

Anyone (regardless of jurisdiction)

EU / UK (GDPR)

You have the right to access, rectify, port, and erase the personal data we hold (license records on Supabase). Contact us at the email below — we respond within 30 days.

California (CCPA / CPRA)

You have the right to know what personal information we collect, request deletion, and opt out of any "sale" of your data. We do not sell personal information.

Children

Mailbreak is not directed at children under 13 (US) or 16 (EU). We do not knowingly collect data from anyone in those age groups.

Changes to this policy

We'll post material changes to this URL and update the "Last updated" date. For significant changes we'll also notify users via the extension popup the next time they open it.

Contact

Privacy questions, GDPR/CCPA requests, deletion requests: see the support email in the extension's Settings → About, or message us via the Chrome Web Store listing's Support tab.