jmap-bridge is self-hosted software. The operator who deployed this instance is the controller of any data it holds; this page describes what the software does with Google user data when the operator connects a Google account.
https://mail.google.com/ scope: reading
mailboxes, messages, flags and labels, and sending mail through Gmail's SMTP
servers.https://www.googleapis.com/auth/carddav to read and write the
account's contacts.Solely to provide the mailbox and contacts to the JMAP client(s) the operator configures. The data is not used for advertising, profiling, or training machine-learning models, and its use complies with the Google API Services User Data Policy, including the Limited Use requirements.
Message headers, flags, mailbox structure, a local search index and cached
message bodies are stored on the operator's own server, in the configured data
directory. OAuth refresh and access tokens are stored there as well, encrypted
with JMAP_BRIDGE_SECRET_KEY when one is configured.
Data is not sold, shared, or transferred to third parties. The software contains no analytics or telemetry, and the API is reachable only with the account's access token.
The operator controls retention: deleting the data directory removes the local copy. Revoking the app's access at myaccount.google.com/permissions stops all further access.
For questions about this instance, contact its operator. The project source and issue tracker are at github.com/CaffeinatedTech/jmap-bridge.