Scrollmail

Privacy Policy

This policy explains how Scrollmail handles your information.

Effective date: September 5, 2026

Scope Google user data What we collect Future features Security Choices Changes Contact

Today, Scrollmail retrieves your email content directly from Google on your device. Scrollmail-operated servers do not receive or store Gmail message bodies, attachments, contact lists, or inbox history. Remote images and actions you choose, such as printing or sharing, may involve third parties as described below.

Scope

This Privacy Policy explains how Scrollmail handles information when you use the Scrollmail app and related app pages at scrollmail.tinkertanker.com. Scrollmail is a Gmail-dependent app that lets you review messages as a feed and take a "done" action, such as archiving, marking as read, or moving to trash, when you scroll past a message.

Google User Data

Scrollmail uses Google OAuth so you can connect your Google account. The app currently requests basic Google account profile access, Gmail access, Gmail send access, Google Drive app data access, Google Contacts read access, and Google Other Contacts read access.

Basic profile access is used to identify connected accounts inside the app, including your account email address, display name, and avatar URL when Google provides them. Gmail access is used to load messages, display message details, show sender and authentication signals, send mail you choose to send, and apply actions you initiate or configure, such as archive, mark as read, trash, star, pin, file under a Gmail label, reply, or forward. Contacts and Other Contacts access is used to suggest recipients and contact details in the app. Drive app data access is used to sync Scrollmail app state through your own Google Drive appData folder, including recent action records that may contain Gmail message IDs, action types, timestamps, operation IDs, batch IDs, and device/install identifiers.

Gmail message content is processed on your device and through Google's services. Scrollmail does not currently send Gmail message bodies, attachments, contact lists, or inbox history to Scrollmail-operated servers. The Google Drive appData sync described above is stored in your Google account, not on Scrollmail infrastructure.

Scrollmail's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data. We do not use Google user data for advertising. We do not transfer or disclose Google user data except as needed to provide and secure Scrollmail, comply with law, respond to abuse, or with your explicit direction. We do not allow humans to read your Gmail content except where you explicitly provide it to us for support, security, legal, or abuse-handling purposes.

What We Collect Today

At launch, Scrollmail is designed to avoid collecting email content on Scrollmail servers. The app may store settings and local app data on your device so the product can work, including your preferred "done" behavior, local cache data, connected-account email addresses, display names, avatar URLs, contact suggestion state, and authentication state kept by the operating system or app platform. Scrollmail may also store app-specific state in your Google Drive appData folder so your own devices can coordinate recent actions. That appData state may include message IDs and action metadata, but not message bodies or attachments.

We may count basic app statistics, such as app opens, installation events, crash diagnostics, or aggregate usage measurements. These statistics are intended to understand whether the app is working and improving. They are not intended to include email bodies or attachments.

When displaying an email, Scrollmail may automatically load remote HTTPS images from hosts specified by the sender. Those hosts may receive your IP address, browser or device information, request timing, and identifiers included in image URLs, which can allow the sender to infer that a message was viewed. These requests go directly from your device to those hosts, not through Scrollmail servers.

To display sender logos, Scrollmail may query Cloudflare's DNS service for records associated with a sender's domain and load a logo from the host specified in those records. Cloudflare receives the domain lookup and your IP address; the logo host receives the image request and connection information. These lookups do not send message bodies or attachments to Cloudflare.

If you choose to print or share an email as a PDF, Scrollmail processes its content on your device and passes the output to your device's printing or sharing service and the destination you select. Temporary PDF files may remain in the device's cache, including while Android completes a print job. Copies saved or received outside Scrollmail are subject to the destination's privacy and retention practices.

Future Paid or Cloud Features

We may add paid or cloud-assisted features in the future, such as push notifications, snooze, scheduled reminders, or cross-device state. Those features may require Scrollmail servers to store limited metadata, such as Gmail message IDs, scheduling metadata, notification tokens, account identifiers, subscription status, or feature settings.

If we add those features, we will update this policy before materially changing how we collect or use data. We will aim to collect only the minimum information needed for the feature and avoid storing message bodies or attachments unless a future feature clearly requires it and you choose to use that feature.

Security and Retention

Scrollmail relies on Google OAuth, Google's API protections, and platform security features to connect to Gmail. Authentication tokens and account records are stored using the security mechanisms provided by your device or app platform where available. You should protect your device, operating-system account, Google account, and app unlock settings.

Data stored locally remains subject to your device settings, backups, and platform behavior. Data stored in Google Drive appData remains subject to your Google account and Google's retention controls. If future server-side features store data, we will retain it only as long as reasonably needed to provide the feature, maintain the service, resolve disputes, comply with law, or protect users.

Your Choices, Revocation, and Deletion

You can disconnect Scrollmail by revoking its Google account access in your Google Account permissions. You can also remove locally stored account profile metadata, settings, cached mail data, and authentication state by deleting the app from your device, subject to your device backup settings.

You can remove appData stored with Google through your Google account tools where available. If future Scrollmail server features store account data, you will be able to request deletion of server-stored data by contacting us. Revoking Google access may stop Scrollmail from syncing or applying message actions.

Children

Scrollmail is not intended for children under 13 and is not designed to knowingly collect personal information from children.

Changes

We may update this Privacy Policy as Scrollmail changes. If a change materially affects how Google user data or personal information is handled, we will update the effective date and provide notice appropriate to the change.

Contact

For privacy questions, data requests, or Google OAuth review questions, contact Scrollmail at scrollmail@tinkertanker.com.

A Tinkertanker Product

Privacy Terms Licenses