Privacy policy

Last updated 29 July 2026 · Applies to the MailMop Chrome extension and mailmop.ing

The short version. MailMop reads the headers of your Gmail messages — who sent them, who was copied in, the subject and the date. It cannot read message bodies or attachments, because the permission it requests from Google does not return them. Extracted contacts are stored on your own device, not on our servers. We do not sell, share or pool your data, and one control deletes all of it.

1. Who we are

MailMop is operated by Window Insulation Ltd, trading as MailMop. For any privacy question, or to exercise any of the rights described below, contact daniel.thompson@window-insulation.com.

MailMop is currently a pre-release product in closed beta.

2. What MailMop accesses

When you connect your Gmail account, MailMop asks Google for exactly two permissions and no others:

PermissionWhat it gives us
gmail.metadataMessage headers only — sender, recipients, CC, subject line and date. Google describes this scope as: “View your email message metadata such as labels and headers, but not the email body.”
userinfo.emailYour account’s email address, so the extension can show you which account is connected.

This is a technical limit, not a promise of restraint. With this permission the Gmail API will not return message bodies or attachments to MailMop even if MailMop asked for them.

3. What MailMop does with it

MailMop extracts CC’d email addresses and display names from your message headers, associates each one with the subject lines it appeared on and the date first seen, de-duplicates them, and presents the result as a contact list inside the extension.

That is the whole purpose. Your Gmail metadata is used to provide that feature to you, the person who granted access, and for nothing else.

4. Where your data is stored

5. When data leaves your device

Only when you tell it to. Exporting a CSV writes a file to your computer. Pushing contacts to a CRM sends them to the service you chose and authorised. Both require an explicit action by you every time. MailMop does not run background syncs.

6. What we never do

7. Human access to data

Our staff do not view your Gmail metadata or extracted contacts. The only exceptions are where you have specifically asked us to look at something in order to help you, where it is necessary for security purposes such as investigating abuse, where the law requires it, or where data is aggregated and anonymised for internal operations in line with applicable law.

8. Google API Services User Data Policy

Limited Use disclosure. MailMop’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

9. Deleting your data

10. Your rights

Under UK GDPR you have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, and to object. You may exercise any of these by contacting us at the address in section 1. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

11. Third parties

MailMop uses a small number of service providers: Google (the Gmail API and cloud infrastructure), our hosting provider, and a payment processor for paid plans. Where a CRM integration is used, contacts are sent only to the CRM you connected and authorised. We do not send your data to enrichment providers or data brokers.

12. Contacts extracted from your inbox

The contact list MailMop produces contains other people’s personal data. In data protection terms you are the controller of that list and we process it on your behalf. If you intend to contact those people for marketing purposes, UK GDPR and PECR obligations apply to you — including having a lawful basis, telling them where you got their details, and honouring objections. MailMop does not send email on your behalf.

13. Children

MailMop is a business tool and is not intended for anyone under 18.

14. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how your data is handled we will tell beta users by email before it takes effect.