Effective October 3, 2026

Privacy policy

Mailbridge is a private, single-user email relay. This policy explains the limited data it processes to move the owner's mail.

Data accessed

Mailbridge uses delegated Microsoft Graph access to read new messages from the owner's Hotmail Inbox and Junk Email folders. It uses delegated Gmail API access to import those messages into the owner's Gmail mailbox.

How data is used

Message content and attachments are streamed from Microsoft Graph to Gmail solely to provide the relay. They are not retained by Mailbridge, used for advertising, sold, or shared for any unrelated purpose.

Stored data and retention

  • OAuth client credentials and bootstrap refresh tokens are stored as encrypted Cloudflare Worker secrets.
  • The rotating Microsoft refresh token is encrypted with AES-256-GCM before storage in Cloudflare KV.
  • Message identifiers used for duplicate prevention expire after 30 days.
  • Failed-delivery retry records expire after seven days.
  • Subscription metadata and operational timestamps are retained while the utility is active.

Service providers

Processing is limited to Microsoft Graph, Cloudflare Workers and KV, and the Gmail API. Each provider processes data under its own terms and privacy commitments.

Security

Mailbridge validates webhook requests, encrypts rotating credentials, avoids logging message content or tokens, and grants only the permissions needed for operation.

Control and deletion

The owner can stop processing by revoking Mailbridge in Microsoft or Google account security settings and deleting the Cloudflare Worker and KV namespace. Google access can be reviewed or revoked at Google Account connections.

Contact

Privacy questions can be sent to the developer support email displayed on the Google OAuth consent screen.