MailMoove
Menu

Privacy

What we do with your email — and what we never do

MailMoove does two things with email. Migration moves a mailbox from one provider to another — your messages pass through us and we keep none of them. Email Vault backs a mailbox up on a schedule, which means keeping encrypted copies, because that is what a backup is. The two are held to different promises and this page states each one separately. Last updated: DRAFT — not yet published.

The short version

We move your mail, we do not read it

When we migrate a mailbox, your messages pass through our system to reach the new one. We keep no copy of their contents and we do not analyse them. Vault is the deliberate exception — it stores encrypted copies, because you asked it to.

We never sell or share your data

Your email data is never sold, rented, or used for advertising, and it is never used to train any AI model.

What we collect, and why

WhatWhy we need it
Your account detailsYour email address and password hash, so you can sign in, so we can send you updates about your migration or your backups, and so you can recover the account if you lose your password.
Mailbox addressesThe addresses you are moving from and to, so we know what to connect and can show you progress.
Message fingerprintsA one-way hash of each message plus its size, date and folder — how we prove every message arrived. Where a message has attachments we also store a one-way hash and the byte size of each one, so we can prove the attachments arrived too; we never store attachment filenames. No hash can be turned back into your email.
Folder and label namesSo your structure is rebuilt at the destination rather than flattened.
Counts and sizesTo price the migration, estimate how long it will take, and produce your completion report.

What we never store when we move your email

This section is about migration — moving a mailbox from one provider to another. If you also use Email Vault, read the Vault section below: a backup necessarily keeps copies, and we describe that separately rather than pretending otherwise.

One exception, and we want to be plain about it: when a message cannot be moved, we record its subject line so your report can tell you which message failed and why. Nothing else from that message is kept, and subject lines are never indexed or written to our logs. If you would rather we did not, tell us and we will disable it for your account.

Email Vault — what a backup necessarily keeps

Vault is a separate, optional product. If you have not connected a Vault account, nothing in this section applies to you.

A backup only works if it holds your actual mail, so Vault stores it. We would rather say that plainly than bury it:

What Vault storesWhy
Complete copies of your messagesThat is what a backup is. Each message is compressed and encrypted with a key unique to your account before it leaves our servers, and stored encrypted at rest.
Attachment filenames and sizesSo the Large Files view can show you what is taking up space and confirm it is safely backed up before you delete it at source.
The sender address of each attachment’s messageSo you can find an attachment by who sent it. This is the one place we index sender addresses, and only for Vault.

Vault works with IMAP mailboxes only. Gmail, Google Workspace and Microsoft 365 mailboxes cannot be connected to Vault, so nothing we receive from Google or Microsoft is ever placed in Vault storage. If that changes we will update this page before it does.

Encryption. Every stored message is compressed and encrypted with AES-256-GCM under a key belonging to your account alone, before it reaches storage. We hold the keys, so we could technically decrypt a message — restoring your mail requires it — but we do not read your backups, and nothing in the product reads a stored message except a restore you ask for.

If you cancel. Your Vault becomes read-only and you get 30 days to export it. After that window a nightly process permanently deletes the stored messages and the attachment index. Ask us to delete it sooner and we will.

How your credentials are handled

IMAP passwords

Held in memory-backed storage only, with an automatic expiry (2 hours by default), and never written to our database. Once the timer runs out, or the migration finishes, the password is gone.

Google and Microsoft sign-in

We never see your password. You sign in with the provider, and we receive a token. That token is encrypted before it is stored, and the short-lived access keys derived from it are used and discarded — never saved.

Revoking access

You can withdraw our access at any time from your Google Account or Microsoft account security settings. Doing so stops any migration in progress.

Google user data

When you connect a Gmail or Google Workspace mailbox, we ask for the narrowest access that lets us do the job:

A source mailbox is never granted write access, and we never request permission to send email or to permanently delete anything. Data received from Google APIs is used only to perform the migration you asked for: it is never placed in Vault storage, never used for advertising, and never used to train any AI model.

MailMoove's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft 365 data

The same principle applies to Microsoft mailboxes: read-only on the source, read-and-write on the destination, and mailbox settings only for a same-address switch-over. We request offline access solely so a long migration can continue without asking you to sign in again part-way through.

How long we keep things

To delete your account and everything associated with it, email privacy@mailmoove.com and we will action it.

Where your data is processed

MailMoove runs on managed cloud infrastructure. Our sub-processors are listed below; we do not share your data with anyone else.

Contact

Questions about this policy, or a request about your data: privacy@mailmoove.com.