Privacy
What IMAP2AI stores, what it does not, and where it runs. Written to be checked, not to be skimmed.
Last updated 4 September 2026.
Who is responsible
The controller is Jure Šavron s.p., Regentova 2b, 6280 Ankaran, Slovenia. For anything in this policy, including a request to see or delete your data, write to info@imap2ai.com.
The short version
Your messages are not stored. IMAP2AI opens a connection to your mail server for each request, passes the result back to Claude, and keeps nothing from it — no message bodies, no subjects, no senders, no folder names, no attachments. What is stored is the settings needed to reach your mailbox, your mailbox password in encrypted form, and a log of which tool ran and whether it worked.
What is stored
- Your account
- The email address you sign in with, and the identity record our authentication provider keeps for it.
- Mailbox settings
- A label, the mailbox address, the IMAP and SMTP host, port and security setting, the username, any folder overrides, and whether sending is enabled.
- Your mailbox password
- Encrypted with AES-256-GCM before it reaches the database, under a key held only in the server’s environment and never written beside the data. Each mailbox gets its own data key, cryptographically bound to that mailbox so a record cannot be moved to another account and opened. A copy of the database, without the environment, decrypts nothing.
- Connector URLs
- Only a SHA-256 hash of each one. The URL itself is shown to you once and never stored, which is also why we cannot show it to you again. Revoking one takes effect immediately.
- A usage log
- One row per request: which account, which tool ran, when, and whether it succeeded. No arguments and no results — never a subject, a sender, a folder name or a message. It exists to enforce the daily limit and to let you see what has been happening in your mailbox.
- Billing, if you subscribe
- A Stripe customer id, your plan, subscription status and renewal date. Card details are entered on Stripe’s own hosted page and never reach this service.
What is not stored
No message content, at any point. Nothing is mirrored, indexed, cached or copied into a database for later. While a request is running, the message passes through the server in memory so it can be converted to text and handed to Claude — it is not written down, but the server is one more machine in the path, and you should know that before connecting a mailbox rather than after.
Your mail is never used to train any model, is never sold, and is never shared with anyone other than the processors listed below.
Where it runs
The application server is in Frankfurt, Germany (EU). The database is in London, United Kingdom, which is covered by the European Commission’s adequacy decision for the UK, so no additional transfer safeguards are required for it. Your mail server is wherever your provider keeps it; IMAP2AI connects out to it and does not move it.
Who else processes your data
- Anthropic — Claude is what reads your mail. Anything Claude retrieves through the connector goes to Anthropic and is handled under your own agreement with them. This is the point of the product, and it is the most important sentence on this page.
- Fly.io — hosting for the application server, in Frankfurt, Germany (EU).
- Supabase — the database and the sign-in system, in London, United Kingdom.
- Stripe — payments, only if you subscribe to a paid plan.
Cookies and tracking
This site has no analytics, no advertising and no tracking cookies, and loads nothing from a third-party domain — no fonts, no scripts, no images from anywhere but here. Signing in stores a session in your browser so you stay signed in; that is the only thing kept on your device, and it is not used to follow you anywhere.
How long it is kept
Mailbox settings and the encrypted password are kept until you delete the mailbox, which deletes them and revokes its connector URLs at the same time. Usage-log rows are kept so you can review recent activity and so the daily limit can be enforced. Deleting your account removes your mailboxes, their credentials and their connector URLs. Billing records are kept as long as tax law requires.
Your rights
Under the GDPR you may ask for a copy of your data, ask for it to be corrected or deleted, ask for it in a portable form, or object to how it is processed. Write to info@imap2ai.com. Most of it you can also do yourself in the dashboard, immediately.
The lawful basis is the contract between us: this data is what makes the service work, and there is none collected that is not needed for it. If you think it is being handled wrongly you can complain to the Slovenian Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana), or to the supervisory authority where you live.
Changes
If this policy changes in a way that affects what is collected or who receives it, the date at the top changes and account holders are told by email before it takes effect.