Privacy Policy
Effective August 31, 2026
Overview
Thaivo Mail is a private Gmail administration application. This policy explains how information is accessed, used, stored, protected, and deleted when a Gmail account is connected through Google OAuth 2.0.
Information we collect
We store the administrator username and password hash, server-side session records, security audit events, and connected Google account metadata such as Google user ID, email address, display name, profile image, connection state, and timestamps.
We store the Google OAuth refresh token needed for authorized ongoing access. The token is encrypted at rest. We do not request or store Gmail passwords.
Google user data
With the account holder’s authorization, Thaivo Mail uses the Gmail API to retrieve message lists, message content, labels, headers, and attachments, and to perform requested actions such as sending mail, replying, changing read or starred status, and moving messages to or from trash.
Gmail content is fetched on demand and is not used to create an independent mailbox archive. Thaivo Mail does not sell Google user data, use it for advertising, or use it to train generalized artificial-intelligence models.
How information is used
Information is used only to authenticate administrators, provide the mail-management functions they request, maintain authorized Google access, secure and operate the service, diagnose errors, and record limited security and operational events.
Sharing and disclosure
Google user data is not sold or shared with advertisers or data brokers. It may be processed by infrastructure providers strictly as necessary to host and secure the service, or disclosed when required by law or to protect users, the service, or others. OAuth tokens and message bodies are not included in ordinary application logs.
Google API Services User Data Policy
Thaivo Mail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage, retention, and security
Refresh tokens are protected with authenticated AES-256-GCM encryption and a server-held key. Administrative access uses hashed passwords, expiring server-side sessions, secure cookies, TLS, request validation, and audit logging.
Account metadata and encrypted authorization credentials are retained while the connection remains active or as needed for security and legal obligations. Removing a connection deletes its stored credential. Limited audit records may be retained for security and accountability.
Control, revocation, and deletion
An administrator can disable or remove a Gmail connection in Thaivo Mail. The Google account holder can also revoke access from the Google Account permissions page. To request deletion of associated application data, contact the Thaivo Mail operator through the administrative contact used during onboarding.
Changes and contact
This policy may be updated when the service or legal requirements change. Material revisions will update the effective date. Privacy questions and data requests should be directed to the Thaivo Mail operator or organization that provided access to this private service.