Thaivo Mail

Privacy Policy

Effective August 31, 2026

Overview

Thaivo Mail is a private Gmail administration application. This policy explains how information is accessed, used, stored, protected, and deleted when a Gmail account is connected through Google OAuth 2.0.

Information we collect

We store the administrator username and password hash, server-side session records, security audit events, and connected Google account metadata such as Google user ID, email address, display name, profile image, connection state, and timestamps.

We store the Google OAuth refresh token needed for authorized ongoing access. The token is encrypted at rest. We do not request or store Gmail passwords.

Google user data

With the account holder’s authorization, Thaivo Mail uses the Gmail API to retrieve message lists, message content, labels, headers, and attachments, and to perform requested actions such as sending mail, replying, changing read or starred status, and moving messages to or from trash.

Gmail content is fetched on demand and is not used to create an independent mailbox archive. Thaivo Mail does not sell Google user data, use it for advertising, or use it to train generalized artificial-intelligence models.

How information is used

Information is used only to authenticate administrators, provide the mail-management functions they request, maintain authorized Google access, secure and operate the service, diagnose errors, and record limited security and operational events.

Sharing and disclosure

Google user data is not sold or shared with advertisers or data brokers. It may be processed by infrastructure providers strictly as necessary to host and secure the service, or disclosed when required by law or to protect users, the service, or others. OAuth tokens and message bodies are not included in ordinary application logs.

Google API Services User Data Policy

Thaivo Mail’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Storage, retention, and security

Refresh tokens are protected with authenticated AES-256-GCM encryption and a server-held key. Administrative access uses hashed passwords, expiring server-side sessions, secure cookies, TLS, request validation, and audit logging.

Account metadata and encrypted authorization credentials are retained while the connection remains active or as needed for security and legal obligations. Removing a connection deletes its stored credential. Limited audit records may be retained for security and accountability.

Control, revocation, and deletion

An administrator can disable or remove a Gmail connection in Thaivo Mail. The Google account holder can also revoke access from the Google Account permissions page. To request deletion of associated application data, contact the Thaivo Mail operator through the administrative contact used during onboarding.

Changes and contact

This policy may be updated when the service or legal requirements change. Material revisions will update the effective date. Privacy questions and data requests should be directed to the Thaivo Mail operator or organization that provided access to this private service.

Return home