Privacy
What we do with your email — and what we never do
MailMoove does two things with email. Migration moves a mailbox from one provider to another — your messages pass through us and we keep none of them. Email Vault backs a mailbox up on a schedule, which means keeping encrypted copies, because that is what a backup is. The two are held to different promises and this page states each one separately. Last updated: DRAFT — not yet published.
The short version
We move your mail, we do not read it
When we migrate a mailbox, your messages pass through our system to reach the new one. We keep no copy of their contents and we do not analyse them. Vault is the deliberate exception — it stores encrypted copies, because you asked it to.
We never sell or share your data
Your email data is never sold, rented, or used for advertising, and it is never used to train any AI model.
What we collect, and why
| What | Why we need it |
|---|---|
| Your account details | Your email address and password hash, so you can sign in, so we can send you updates about your migration or your backups, and so you can recover the account if you lose your password. |
| Mailbox addresses | The addresses you are moving from and to, so we know what to connect and can show you progress. |
| Message fingerprints | A one-way hash of each message plus its size, date and folder — how we prove every message arrived. Where a message has attachments we also store a one-way hash and the byte size of each one, so we can prove the attachments arrived too; we never store attachment filenames. No hash can be turned back into your email. |
| Folder and label names | So your structure is rebuilt at the destination rather than flattened. |
| Counts and sizes | To price the migration, estimate how long it will take, and produce your completion report. |
What we never store when we move your email
This section is about migration — moving a mailbox from one provider to another. If you also use Email Vault, read the Vault section below: a backup necessarily keeps copies, and we describe that separately rather than pretending otherwise.
- The body of any email.
- Attachments.
- Sender or recipient addresses of your messages.
- Your mailbox password — see below.
One exception, and we want to be plain about it: when a message cannot be moved, we record its subject line so your report can tell you which message failed and why. Nothing else from that message is kept, and subject lines are never indexed or written to our logs. If you would rather we did not, tell us and we will disable it for your account.
Email Vault — what a backup necessarily keeps
Vault is a separate, optional product. If you have not connected a Vault account, nothing in this section applies to you.
A backup only works if it holds your actual mail, so Vault stores it. We would rather say that plainly than bury it:
| What Vault stores | Why |
|---|---|
| Complete copies of your messages | That is what a backup is. Each message is compressed and encrypted with a key unique to your account before it leaves our servers, and stored encrypted at rest. |
| Attachment filenames and sizes | So the Large Files view can show you what is taking up space and confirm it is safely backed up before you delete it at source. |
| The sender address of each attachment’s message | So you can find an attachment by who sent it. This is the one place we index sender addresses, and only for Vault. |
Vault works with IMAP mailboxes only. Gmail, Google Workspace and Microsoft 365 mailboxes cannot be connected to Vault, so nothing we receive from Google or Microsoft is ever placed in Vault storage. If that changes we will update this page before it does.
Encryption. Every stored message is compressed and encrypted with AES-256-GCM under a key belonging to your account alone, before it reaches storage. We hold the keys, so we could technically decrypt a message — restoring your mail requires it — but we do not read your backups, and nothing in the product reads a stored message except a restore you ask for.
If you cancel. Your Vault becomes read-only and you get 30 days to export it. After that window a nightly process permanently deletes the stored messages and the attachment index. Ask us to delete it sooner and we will.
How your credentials are handled
IMAP passwords
Held in memory-backed storage only, with an automatic expiry (2 hours by default), and never written to our database. Once the timer runs out, or the migration finishes, the password is gone.
Google and Microsoft sign-in
We never see your password. You sign in with the provider, and we receive a token. That token is encrypted before it is stored, and the short-lived access keys derived from it are used and discarded — never saved.
Revoking access
You can withdraw our access at any time from your Google Account or Microsoft account security settings. Doing so stops any migration in progress.
Google user data
When you connect a Gmail or Google Workspace mailbox, we ask for the narrowest access that lets us do the job:
- Read your messages — on the mailbox you are moving from, so we can copy them.
- Add messages — on the mailbox you are moving to, so they arrive. This only ever adds; it cannot send mail on your behalf.
- Manage labels — on the destination, so your labels are rebuilt.
- Read the destination — so that if a migration is interrupted and resumes, we can see what already arrived and never deliver a message twice.
- Change your forwarding settings — only when you are keeping the same address and have asked us to cover the switch-over window. Never otherwise.
A source mailbox is never granted write access, and we never request permission to send email or to permanently delete anything. Data received from Google APIs is used only to perform the migration you asked for: it is never placed in Vault storage, never used for advertising, and never used to train any AI model.
MailMoove's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft 365 data
The same principle applies to Microsoft mailboxes: read-only on the source, read-and-write on the destination, and mailbox settings only for a same-address switch-over. We request offline access solely so a long migration can continue without asking you to sign in again part-way through.
How long we keep things
- Mailbox passwords: up to 2 hours, then automatically deleted.
- Sign-in tokens: until your migration completes or you revoke access, whichever is first.
- Unsaved Gmail connection tests: kept encrypted in your server session until you save the mailbox pair or the session expires. A test can be reused for two hours; expired tests are cleared when you next open connection setup.
- Per-message fingerprints: 90 days after your migration completes, then reduced to per-folder totals so your report still adds up.
- Vault backups: for as long as your Vault is active. After you cancel: read-only for a 30-day export window, then permanently deleted.
- Your account and reports: until you ask us to delete them.
To delete your account and everything associated with it, email privacy@mailmoove.com and we will action it.
Where your data is processed
MailMoove runs on managed cloud infrastructure. Our sub-processors are listed below; we do not share your data with anyone else.
- Railway — application hosting, database and job queue.
- Amazon Web Services — sending the notification emails described above, for every account; and encrypted Vault storage, for Vault customers only. Both run in AWS's US East (Ohio) region.
Contact
Questions about this policy, or a request about your data: privacy@mailmoove.com.