Privacy policy

jmap-bridge is self-hosted software. The operator who deployed this instance is the controller of any data it holds; this page describes what the software does with Google user data when the operator connects a Google account.

What is accessed

How it is used

Solely to provide the mailbox and contacts to the JMAP client(s) the operator configures. The data is not used for advertising, profiling, or training machine-learning models, and its use complies with the Google API Services User Data Policy, including the Limited Use requirements.

Where it is stored

Message headers, flags, mailbox structure, a local search index and cached message bodies are stored on the operator's own server, in the configured data directory. OAuth refresh and access tokens are stored there as well, encrypted with JMAP_BRIDGE_SECRET_KEY when one is configured.

Sharing

Data is not sold, shared, or transferred to third parties. The software contains no analytics or telemetry, and the API is reachable only with the account's access token.

Retention and deletion

The operator controls retention: deleting the data directory removes the local copy. Revoking the app's access at myaccount.google.com/permissions stops all further access.

Contact

For questions about this instance, contact its operator. The project source and issue tracker are at github.com/CaffeinatedTech/jmap-bridge.