1. Who operates RedsMail
RedsMail is a web-based Gmail client operated under the RedsBlack name at redsblack.com.
Privacy contact: jack78787812@gmail.com
2. Google user data accessed
After a user voluntarily connects a Google account through Google OAuth, RedsMail may access data necessary to provide the requested email functions, including:
- the connected Google account email address and basic account identification returned by Google;
- Gmail message identifiers, thread identifiers, headers, senders, recipients, dates, subjects, snippets and message content;
- Gmail labels and message status such as read, unread, starred, inbox, sent, draft, spam and trash;
- attachment names, types, sizes and attachment content when the user opens, downloads or sends an attachment;
- messages composed or sent by the user through RedsMail.
RedsMail does not request or receive the user's Google password.
3. How Google user data is used
Google user data is used only to provide and improve user-facing email functionality, including:
- displaying mailboxes, messages, threads and attachments;
- searching messages and filtering mailbox views;
- composing, sending, replying to and forwarding messages;
- marking messages read or unread, adding or removing stars and Gmail labels;
- archiving messages and moving messages to Trash or Spam;
- creating user-requested Gmail labels and organising messages;
- caching selected data locally so the application opens faster and can show recently loaded information;
- using Gmail history identifiers to request only new and changed mailbox data after the first synchronisation, with a full refresh when Google requires it.
RedsMail does not use Gmail data for personalised advertising, credit decisions, surveillance, sale to data brokers, or training general-purpose artificial intelligence models.
4. Where data is processed and stored
Direct browser-to-Google processing
Most Gmail API requests are made directly from the user's browser to Google. Message data is not routinely copied into a RedsMail server database.
Server-side OAuth token storage
To keep a connected Gmail account signed in, RedsMail stores Google's long-lived refresh token in encrypted server-side storage linked to a random, secure HttpOnly session cookie. The refresh token is used only to obtain short-lived access tokens from Google. Gmail message content is not stored in this OAuth token store.
Local browser storage
To keep the application responsive, RedsMail may store account settings, short-lived Google access tokens, message metadata, recently loaded message content, Gmail history identifiers, local rules, preferences and cached mailbox information in browser storage such as sessionStorage, localStorage and IndexedDB. This local database is specific to the device and browser profile. The information remains there until it expires, is replaced, the account is disconnected, or the user clears the app/browser data.
Hosting logs
The web-hosting provider may process ordinary technical request information such as IP address, browser type, requested file, date/time and error details for security and operation. RedsMail does not intentionally place Gmail message content in normal web access logs.
5. Subscription identity and Paddle billing
When subscription status is checked, RedsMail sends the short-lived Google access token for the selected owner account to its own subscription endpoint. The endpoint uses it only to request that account's Gmail profile address from Google and verify who is requesting the licence. The token and email address are not written to the subscription store. Instead, RedsMail stores a one-way, secret-keyed pseudonymous reference.
When Plus is purchased, the pseudonymous reference and selected plan are sent to Paddle. Payment details, billing address and the billing email entered at checkout are collected directly by Paddle as merchant of record. RedsMail receives subscription identifiers, status and renewal information needed to enable or disable Plus. Gmail messages, attachments and mailbox content are not sent to Paddle.
6. Translation feature
Automatic translation is disabled by default. When a user actively requests translation, the relevant message text is sent through the RedsMail translation endpoint and forwarded to a configured translation provider or the Google Translate web service for translation. The provider receives the text required to perform that request.
RedsMail does not intentionally retain translated message text on its server after the request is completed. Translation providers may process data under their own terms and privacy practices. Users should not use translation for content they do not want transmitted to a translation provider.
7. Remote images and external links
Emails may contain remote images, tracking pixels and links controlled by the sender or another website. RedsMail does not automatically display remote images unless the user enables that option or chooses to show them. Opening a remote image or external link may disclose the user's IP address and browser information to that third party.
8. Sharing and disclosure
RedsMail does not sell or rent Google user data. Data may be disclosed only in these limited circumstances:
- to Google, as required to authenticate the account and perform Gmail actions selected by the user;
- to a translation provider when the user requests translation;
- to Paddle for checkout, tax, invoicing, payment and subscription management; RedsMail sends Paddle a pseudonymous licence reference rather than Gmail message content;
- to technical service providers that host or secure the website, only to the extent necessary to operate the service;
- when required by law, legal process, or to protect users, the service, or the public from fraud, abuse or security threats;
- with the user's explicit consent.
Human access to Gmail content is not permitted except with the user's affirmative consent for support, when necessary for security or abuse investigation, or when required by law.
9. Retention and deletion
RedsMail keeps locally cached information only for as long as it remains in the user's browser storage. An encrypted Google refresh token is retained only while the Gmail connection remains active and is deleted from the RedsMail session when the user disconnects or removes that account. Pseudonymous subscription status and Paddle transaction/subscription references are retained for billing, fraud prevention, support and legal record-keeping for as long as reasonably necessary. Paddle retains billing records under its own legal obligations and privacy policy. Users can remove local data by:
- using Settings → Disconnect session or removing an account in RedsMail;
- clearing site data for redsblack.com in the browser or removing the installed PWA data;
- revoking RedsMail access in the Google Account connections/security settings.
For assistance with deletion, contact jack78787812@gmail.com. Identity verification may be required before acting on a request.
10. Security
RedsMail uses HTTPS, Google OAuth, encrypted server-side refresh-token storage, secure HttpOnly session cookies and browser security controls. Google passwords are not handled by RedsMail. No internet service can guarantee absolute security, and users should protect their device, browser profile and Google account.
11. Children's privacy
RedsMail is not directed to children and is intended for people able to authorise access to their own Google account. The operator does not knowingly collect children's data outside information a user chooses to process through their own mailbox.
12. Changes to this policy
This policy may be updated when functionality, legal requirements or data practices change. The effective date at the top will be revised. Material changes will be presented in an appropriate manner before they take effect where required.
13. Contact
Questions, privacy requests or complaints can be sent to jack78787812@gmail.com.