Privacy Policy
Last updated: September 4, 2026
KanbanMail ("KanbanMail", "we", "us") is a Chrome extension and Gmail add-on that turns your emails into cards on a sales pipeline, inside Gmail. This page explains exactly what data we access, why, and how you stay in control of it.
What we access, and why
When you connect your Google account, KanbanMail requests the following permissions:
- Gmail (gmail.modify) — to read the subject, sender and body of the email threads you add to your pipeline, and to create, apply and remove the
KanbanMail/<Column>labels that keep your board in sync with your inbox. We never send email on your behalf, and we never permanently delete messages. - Basic profile (email address and name) — to identify your account and greet you by name.
We only read the threads you explicitly assign to a pipeline card (or that arrive in your Primary inbox, if you've enabled automatic intake) — we do not scan your entire mailbox.
What we store
On our own server we store the minimum needed to run your board:
- Your pipeline columns and their names, colors and order.
- Cards: the associated contact, linked Gmail thread IDs, deal value, currency, due date and any private notes you write.
- Your Google OAuth access and refresh tokens, so you don't have to reconnect every time you open Gmail. These are stored server-side and are never exposed to the browser or to other users.
We do not store the full content of your emails on our server beyond what's shown on a card (subject, sender, snippet, dates) — the full message body is fetched live from the Gmail API each time you open a card, and is not persisted.
What we don't do
- We do not sell, rent or share your data with third parties.
- We do not show ads, and we do not use your data for advertising.
- We do not use your Gmail content to train AI or machine-learning models.
- We do not use any third-party analytics or tracking scripts inside the extension.
Limited Use disclosure
KanbanMail's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data retention and security
Your data is retained for as long as your KanbanMail account is active. Data in transit between your browser, our server and Google's APIs is encrypted via HTTPS/TLS. Access to the production database is restricted to the KanbanMail maintainer.
Revoking access and deleting your data
You can revoke KanbanMail's access to your Google account at any time from myaccount.google.com/permissions. Revoking access stops all further syncing; your Gmail labels remain untouched.
To request full deletion of your KanbanMail data (columns, cards, notes and stored tokens), email us at support@kanbanmail.co and we'll delete it within 30 days.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page. Continued use of KanbanMail after a change constitutes acceptance of the updated policy.
Contact
Questions about this policy or your data? Write to support@kanbanmail.co.