This policy describes how Axenta GmbH, Lange Gasse 65, 1080 Wien, Austria (registered with the Handelsgericht Wien under FN 650399w) ("Mailinizer", "we", "us") — the data controller — handles personal data when you use our products and websites. We wrote it so a human can understand it; if anything below is unclear, email privacy@mailinizer.com and we'll fix the wording.
1. What we collect
- Account data — your name, email, and OAuth tokens for the providers you connect, encrypted at rest. For mailboxes connected over IMAP (providers without OAuth, such as Yahoo, Apple Mail or Fastmail), the mailbox password you enter is stored encrypted at rest and used only to access that mailbox on your behalf. Payment details are handled entirely by the app store you subscribe through; we never see your card number.
- Email content — the headers, bodies, and attachments of mail in the accounts you connect, stored on the EU servers described in section 4. Bodies are not separately encrypted inside the database today; the database itself is reachable only from our private network.
- Derived data — categories, summaries, draft suggestions, and the undo log of the actions Mailinizer took on your behalf (moves, labels, unsubscribe requests, drafts and follow-ups).
- Device and usage data — nothing beyond what any web server logs: your IP address and user-agent land in our access logs when you use the API or this site, kept for security and rate-limiting. We do not collect an app-version or device-type header, and we run no analytics or telemetry SDK — there is no event stream of what you tap or open. No keystroke logging, no screen recording.
- Push-notification content— if you allow notifications, the sender name and subject line of a new message (or a daily-briefing summary) are sent to Apple's and Google's push services via Expo's push relay so they can be delivered to your device. See section 5.
2. Why we collect it
Strictly to make Mailinizer work for you and to keep the lights on. We do not sell, rent, or share your data with anyone for advertising purposes. We do not train AI models on your mail — ours, OpenAI's, Anthropic's, anyone's.
3. Google user data and Limited Use
When you connect a Gmail account, Mailinizer requests only the permissions it needs to read, organise, and draft mail on your behalf. You can withdraw that access at any time from Mailinizer or from your Google Account's security settings.
One thing happens without a tap: when Mailinizer is highly confident a newsletter is one you no longer read, it can send the unsubscribe request from your account for you. Each such action is logged, can be undone for one minute, and appears in your data export. It never deletes mail from your mailbox on its own.
Mailinizer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely: we do not transfer Google user data to third parties except as needed to provide or improve the features you asked for, to comply with law, or as part of a merger we would notify you about; we do not use it for advertising; we do not sell it; we do not allow humans to read it except with your explicit consent, to resolve a support issue you raised, for security purposes, or where the law requires it; and we do not use it to train generalised AI models.
4. Where it lives
All mail bodies, drafts, and derived indices are stored on dedicated servers we operate at Contabo GmbH, in the European Union. The database and cache are reachable only from inside our private network — they publish no public port — and traffic to the API is TLS-terminated at our edge. We do not currently offer a US or other non-EU residency option.
5. Sub-processors
- Contabo GmbH (server hosting, EU)
- Apple and Google (subscription billing for purchases made in their app stores), with RevenueCat (subscription state and receipt validation)
- OpenAI, Anthropic, and Google (LLM inference for sorting, summaries, and drafts — sent without training rights)
- Resend (transactional email — sign-in links, notifications)
- Expo (push-notification relay), which forwards to Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) — the sender name and subject of a new message, or a daily-briefing summary, transit these services to reach your device
We do not use an advertising network, and the marketing site you are reading runs no third-party analytics or trackers. The current sub-processor list is available from privacy@mailinizer.com on request.
6. Your rights (GDPR / CCPA)
- Export everything as JSON — email privacy@mailinizer.com and we'll send it to you.
- Delete everything — immediate and irreversible, self-serve in Settings.
- Restrict processing — turn off AI processing in Settings (self-serve, reversible) to stop AI-driven analysis of your email content immediately; delete your account (self-serve in Settings) for a full, irreversible stop, or email privacy@mailinizer.com to discuss other options.
- Lodge a complaint with your data protection authority (in Austria: Datenschutzbehörde).
7. Cookies
This marketing site sets no cookies at all— there is no analytics script and no third-party tracker on it. The apps authenticate with tokens held in the device's secure storage rather than browser cookies. No advertising IDs, anywhere.
8. Children
Mailinizer is not directed to children under 16. If you believe a child has created an account, write to us and we'll delete it.
9. Changes to this policy
We'll email every active account at least 30 days before any material change takes effect. Past versions are kept at privacy@mailinizer.com on request.
Terms of Service
Now on its own page.
The full terms — plans and cancellation, acceptable use, AI output, liability, and governing law — are at mailinizer.com/terms-of-service. Questions: legal@mailinizer.com.
Data Processing Addendum
One-page DPA.
Business customers are covered by our standard DPA, available on request from legal@mailinizer.com. It incorporates the EU Standard Contractual Clauses (2021/914) and UK IDTA where applicable.