Privacy policy
Last change: 8 October 2026
mailroom is open-source webmail software. This page is about the mailroom service at mailroom.lechat.dev. The admin of this service runs it on Cloudflare and invites its users.
The data that mailroom keeps
- The mail of the mailboxes that you can read: the mail of the domains of this service, and the mail of the Gmail accounts that you connect.
- Each message, its attachments and the copies of its remote images, encrypted with AES-256-GCM, in Cloudflare R2. The key stays with the service and its admin.
- An index of each message in Cloudflare D1, not encrypted: the sender, the recipients, the subject, the dates, the start of the text, the folders, and the read and star state.
- Your account: your name, the public keys of your passkeys, your sessions, and your MCP tokens. D1 keeps a SHA-256 hash of each session and token, not the value.
- For each Gmail account that you connect: its address, the OAuth tokens from Google (encrypted), and the state of the sync.
- The logs of the service at Cloudflare, for a short time: mostly errors, with message ids and addresses.
Google user data
When you connect a Gmail account, you allow mailroom to use two Google permissions:
gmail.modify: mailroom copies the messages of the last 90 days in Inbox, Sent and Spam, then each new message and each change of their labels. It deletes the copy of a message that you delete in Gmail. It uses the labels for the folders and for the read and star state. A message of 10 MiB or more stays in Gmail only. When you read, star, move or delete a message in mailroom, mailroom changes its labels in Gmail. A delete forever in mailroom moves the message to the Gmail trash, which Gmail empties after 30 days: this permission cannot delete a message.gmail.send: mailroom sends the messages that you write from the Gmail address, through Gmail, when you click Send.
mailroom changes your mail in Gmail only for an action that you do in mailroom. It shows the mailbox of a Gmail account only to the user who connected it.
The use and transfer to any other app of information that mailroom receives from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. mailroom does not sell your data, does not use it for advertising, and does not use it to train AI models.
Who can read your mail
- You, with your passkeys.
- An MCP client that you choose, for example an AI assistant, when you give it an MCP token that you create in Settings. It reads the same mailboxes as you, the Gmail copies included. You can revoke the token at any time.
- The admin of this service controls the servers and the encryption key, so the admin can read the stored mail. The admin does not read your mail without your permission, except for the security of the service or when the law requires it.
- Cloudflare stores and processes the data as the host of the service.
How long mailroom keeps the data
- Mail stays until you delete it. Mail in Junk goes away after 30 days. Mail to an address without its own mailbox goes away after 30 days, unless the admin changes this time.
- When you disconnect a Gmail account in Settings, mailroom revokes its access at Google and deletes the copies of its mail within minutes. Gmail keeps the original mail.
- When the admin deletes your account, mailroom deletes your sessions, your tokens and the copies of your Gmail mail.
You can also remove the access of mailroom in your Google account, at myaccount.google.com/permissions. mailroom then stops the sync.
Cookies
mailroom uses cookies for your session, your view mode, your time zone, and the sign-in and Google connect steps. It has no analytics, no advertising and no tracking.
Remote content
For received mail, mailroom can fetch the remote images of a message once and keep an encrypted copy. Opening the message then does not contact the servers of the sender.
Questions and requests
To see, correct or delete your data, ask the admin of this service. The software is at github.com/max-lt/mailroom.