Legal

Privacy Policy

ShareMail is a collaboration layer on top of Gmail. Your mail stays in Google; we hold a working copy plus the things we add to it. Last updated 7 September 2026.

ShareMail is operated by VeloTech LLC ("we", "us"), 1309 Coffeen Ave, Sheridan, WY 82801, United States. This policy covers the ShareMail application and the sharemail.app website. Questions, requests and complaints: [email protected], or by post to the address above.

Google user data: what we request and why

You connect ShareMail to Google yourself, and Google shows you exactly what you are granting. We request three things, and nothing else:

  • Sign-in (openid, userinfo.email, userinfo.profile). Your email address, name and profile picture, used to create your account, confirm which Google account is connecting an inbox, and show you to teammates.
  • Gmail (gmail.modify). Read the conversations in an inbox you connect so they appear in the shared inbox; archive, mark read or unread, and apply labels by changing the labels on the Gmail thread so the two stay in step; create, update and remove the Gmail draft that mirrors a shared draft; and send replies as the connected address. It cannot permanently delete anything. We ask for this scope rather than a narrower one because Gmail's read-only and send-only scopes cannot change labels on a message, and label changes are how archive and read state stay in sync with Gmail.
  • Workspace directory, optional (admin.directory.user.readonly). Only if a Workspace admin chooses to import the company user list to invite teammates. Read-only, requested only by that admin, and you can skip it.

We use Google user data only to provide the features described on this site to the people in your workspace. We do not use it for anything else.

You can revoke any of this at any time from your Google account permissions, or by disconnecting the inbox in ShareMail, which revokes our token with Google as well as deleting it here.

Limited Use

ShareMail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data for advertising, we do not sell it, we do not transfer it except as described under "Who else sees it", and we do not use it to develop, improve or train generalized machine-learning or AI models, our own or anyone else's. Humans do not read your mail except where you explicitly ask us to for support, and then only the specific thread you point us at, or where it is necessary for security purposes or to comply with the law.

What we store

  • A working copy of your conversations in a connected inbox: message metadata, the headers the product uses, and a sanitised copy of the message body so search and the reader are fast. Attachments are fetched from Gmail on demand and cached, not copied wholesale.
  • The collaboration layer we add: internal comments, @mentions, tags, assignments, drafts, rules, templates and an audit trail of who did what. This is the part that is genuinely ours to store, and it is the part you get back in an export.
  • Your account: name, email, profile picture, role, availability, and sign-in timestamps.
  • OAuth tokens, encrypted at rest. We never see or store your Google password, and ShareMail has no password of its own.

What we never do

  • We are not in the delivery path. Mail is delivered by Google, stored by Google, and remains yours in Gmail whether or not you use us. We never become the system of record.
  • Personal inboxes are private, including from your own admins. If you connect your own Gmail, its contents never appear in a team view, an analytics report or a workspace export. This is enforced in code, not by policy, and it is covered by tests.
  • No advertising, no selling data, no AI training on your mail.

Who else sees it

Your teammates see what you would expect them to: shared inboxes they are a member of, and the comments and assignments in them. Outside your workspace, your data reaches only the services we need to run the product:

  • Google, as the source and destination of your mail.
  • Amazon Web Services, which hosts the application servers and the database in the United States.
  • Cloudflare, which serves this website and sits in front of the application as a network proxy. The one thing the website collects is an email address you type into the "tell me when it opens" form, stored with a timestamp and nothing else: no IP address, no user agent, no referrer.

One more only applies if you switch it on, and it is off by default:

  • Integrations you connect, such as Stripe. When a workspace connects one with its own key, we send that service the sender's email address to look up their record and show it beside the conversation. Read-only, and nothing else about the conversation leaves ShareMail.

We do not sell or rent personal data, and we do not share it with advertisers or data brokers. If we are ever legally compelled to disclose something, we will tell you unless the law forbids it.

How we protect it

Everything travels over TLS, between you and us and between us and Google. OAuth tokens are encrypted at rest with a key that lives outside the database. Application logs never contain message bodies or tokens. Access to production is limited to the people who operate it, and every inbox is access-controlled in code so that a teammate only ever sees the inboxes they are a member of. The security page goes into more detail, including what we do not claim yet.

Cookies and tracking

This website sets no cookies and runs no cross-site trackers or analytics that identify you. The application itself sets a session cookie, because it has to in order to keep you signed in.

Keeping it, and deleting it

  • Disconnect an inbox and we revoke the token with Google and stop syncing immediately.
  • Export everything ShareMail added (comments, tags, assignments, the full audit history) at any time, including after you cancel. Your mail is not in the export because it never left Gmail.
  • Disconnecting also purges. An admin can disconnect an inbox and purge its synced copy from ShareMail in one step, from Settings, without asking us.
  • Delete a workspace by emailing [email protected] from an owner address. We remove the synced copy, the collaboration layer and your account within 30 days. Automated database backups expire on a fixed schedule after that, and we do not restore deleted workspaces from them.
  • Cancelling does not delete anything by itself: the workspace goes read-only so you can still get to your history, and your mail is in Gmail regardless.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to how we process it. Email [email protected] and we will action it. We will not make you fill in a form or wait on a queue for the privilege.

Children

ShareMail is a business tool and is not directed at anyone under 16. We do not knowingly collect their data.

Changes

If we change this policy in a way that materially affects you, we will email the workspace owner before it takes effect rather than quietly editing the page. The date at the top always reflects the current version.

How the security works → The pledge →