Trust
Security
EsteemWay reads your mailbox to build your plan. Here is exactly how that data is protected, and how it is removed.
Gmail data is encrypted at rest
Your Google OAuth tokens are encrypted with AES-256-GCM before they are stored, using versioned keys that can be rotated without downtime.
Row-level security on every user data table
Each table that holds your data enforces database-level policies scoped to your account, so one user can only ever read or write their own rows.
Instant deletion when you disconnect
Using "Disconnect & delete my data" revokes our access at Google and immediately deletes the mailbox-derived data we hold for you, with an audit record of what was removed.
Automatic purge after inactivity
If an account is inactive for 120 days, all mailbox-derived data is purged automatically. We email warnings at 90, 105 and 115 days so you can log back in and keep your data.
OAuth tokens never reach the browser
Tokens are handled exclusively by our server. They are never sent to, or stored in, the browser.
More detail
Read the Privacy Policy for what we collect and how long we keep it, and the Terms of Service for the agreement covering your use of EsteemWay.
