Privacy Policy
Last updated: 25 September 2026
The short version. MailMop is a web application that runs entirely in your browser. It reads Gmail message headers only — never message bodies or attachments — and the results are stored on your own device. For your Gmail data, MailMop has no backend server: it is never sent to us and we cannot see it. The one set of personal data we do hold is the early-access list — the email addresses visitors leave on mailmop.ing to ask for a beta invitation — described in its own section below.
Who we are
MailMop is operated by Quickin Limited, a company registered in England and Wales. For any question about this policy or about your data, contact support@mailmop.ing.
Quickin Limited is the data controller for the purposes of UK data protection law.
What MailMop does
MailMop helps you understand and clean up the CC lists you are part of. It reads the headers of messages in your Gmail account, extracts the addresses and names that appear in CC fields, removes duplicates, and shows you the result as a reviewable list.
What we access, and why
When you sign in with Google, MailMop asks for two permissions and no others:
- Gmail metadata (
gmail.metadata) — message headers only: sender, recipients, CC, subject line and date. This scope does not grant access to message bodies or attachments, and MailMop never requests a scope that would. It is the narrowest Google scope that exposes CC recipients, which is the information MailMop exists to work with. - Your email address (
userinfo.email) — so MailMop can show which account is signed in and keep results associated with the right account.
Where your data is processed and stored
MailMop is a client-side application. Message metadata is requested from Google directly by your browser, processed in your browser, and stored in your browser's local storage on your own device.
For your Gmail data, MailMop has no backend server and no database. Your Gmail data is not transmitted to us, not stored by us, and not accessible to us at any point. Our website is served as static files; it receives no Gmail data. The only personal data we hold is the early-access list described below.
How we protect your data
Gmail message metadata is sensitive personal data, and MailMop is built so that as little of it as possible exists and none of it leaves your device. These are the specific protections that apply to it.
- Data minimisation. MailMop requests the
gmail.metadatascope only. Google does not return message bodies or attachments under this scope, so the application cannot retrieve them even in error. Of the headers it does receive, only sender, recipient, CC, subject and date are used. - Encryption in transit. All requests to Google's APIs are made directly from your browser to Google over TLS 1.2 or higher. MailMop's own pages are served over HTTPS only, and the app at app.mailmop.ing makes no third-party requests of any kind — its only network requests go to Google. On mailmop.ing, the one third-party request is the early-access form submission described below, sent only when you press the button.
- Storage on your device. Results are written to your browser's local storage on your own machine, protected by your operating system's and browser's own protections, including full-disk encryption where you have it enabled. Results are capped in size and can be cleared at any time.
- No server-side copy. MailMop has no backend server, no database and no logging of user data. Your Gmail metadata is never transmitted to Quickin Limited or to any third party, so there is no server-side store to breach, and no subprocessor holds it.
- Access tokens. The Google access token issued when you sign in is held in memory for the duration of your session only. It is not written to disk, not persisted to local storage, and is discarded when you close the tab or disconnect.
- Access controls. Because no copy of your data exists outside your browser, no Quickin Limited employee or contractor can access it. Access to MailMop's source repositories, hosting and Google Cloud project is limited to named administrators, protected by multi-factor authentication and granted on a least-privilege basis.
- Retention and deletion. Your data is retained only for as long as you keep it on your device — there is no server-side retention period because there is no server-side copy. The in-app Disconnect & delete local data control erases everything MailMop has stored, and revoking access in your Google account ends all further retrieval immediately.
- Secure development. Changes are reviewed before release, dependencies are kept current and checked for known vulnerabilities, and MailMop's use of Google user data is re-checked at each release.
- Incident response. Security concerns can be reported to support@mailmop.ing. We investigate promptly and, where a reportable personal data breach occurs, will notify affected users and the Information Commissioner's Office within the timeframes required by UK GDPR.
Early-access list (mailmop.ing only)
What we collect. If you request a beta invitation on mailmop.ing, we store the email address you enter and a short source tag recording which page or link the request came from. Nothing else — no name, no tracking identifier, and never any Gmail data.
Who processes it. The list is stored for us by Supabase (our processor for this one list), in Supabase's eu-west-1 (Ireland) region. The form sends your address directly to that service when you press the button — this is the only third-party request our website makes. Supabase holds the list on our instructions and cannot use it for its own purposes.
Why. Solely to send you a beta invitation. We do not use the list for marketing, we do not share it, and we do not add you to anything else.
Retention and removal. We keep your address until your invitation is sent, and delete the list when the closed beta ends. To be removed sooner, email support@mailmop.ing from that address and we will delete it, normally within 7 days.
What we do not do
- We do not sell your data, or transfer it to advertising platforms, data brokers or information resellers.
- We do not use your Gmail data to train any model, including any artificial intelligence or machine learning model.
- We do not use your Gmail data for advertising or marketing of any kind.
- We do not read your message bodies or attachments, and we do not have the permission to.
- We do not share your Gmail data with third parties, because we never hold it.
Google API Services User Data Policy
MailMop's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Deleting your data
Because everything is stored on your own device, you are in control of removing it. You can:
- Use the delete control inside MailMop to clear the stored results;
- Clear your browser's site data for app.mailmop.ing, which removes everything MailMop has stored;
- Revoke MailMop's access to your Google account at any time at myaccount.google.com/permissions, independently of us.
There is no account to delete on our side, because we do not create one. If you would like confirmation of any of the above, email support@mailmop.ing.
Your rights
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection in relation to personal data a controller holds about you. As set out above, we do not hold your Gmail data, so in most cases these rights are exercised directly on your own device or through your Google account. Where we do hold personal data — for example if you email our support address — those rights apply in the normal way.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.
Changes to this policy
If we change how MailMop handles data, we will update this page and change the date at the top. Material changes will be announced in the application itself.