Effective October 3, 2026
Privacy policy
Mailbridge is a private, single-user email relay. This policy explains the limited data it processes to move the owner's mail.
Data accessed
Mailbridge uses delegated Microsoft Graph access to read new messages from the owner's Hotmail Inbox and Junk Email folders. It uses delegated Gmail API access to import those messages into the owner's Gmail mailbox.
How data is used
Message content and attachments are streamed from Microsoft Graph to Gmail solely to provide the relay. They are not retained by Mailbridge, used for advertising, sold, or shared for any unrelated purpose.
Stored data and retention
- OAuth client credentials and bootstrap refresh tokens are stored as encrypted Cloudflare Worker secrets.
- The rotating Microsoft refresh token is encrypted with AES-256-GCM before storage in Cloudflare KV.
- Message identifiers used for duplicate prevention expire after 30 days.
- Failed-delivery retry records expire after seven days.
- Subscription metadata and operational timestamps are retained while the utility is active.
Service providers
Processing is limited to Microsoft Graph, Cloudflare Workers and KV, and the Gmail API. Each provider processes data under its own terms and privacy commitments.
Security
Mailbridge validates webhook requests, encrypts rotating credentials, avoids logging message content or tokens, and grants only the permissions needed for operation.
Control and deletion
The owner can stop processing by revoking Mailbridge in Microsoft or Google account security settings and deleting the Cloudflare Worker and KV namespace. Google access can be reviewed or revoked at Google Account connections.
Contact
Privacy questions can be sent to the developer support email displayed on the Google OAuth consent screen.