Privacy Policy
Last updated: 6 September 2026
SweepBox ("we", "our", "us") makes two products for cleaning up Gmail: SweepBox Lite, a Chrome extension that runs in Gmail's side panel, and SweepBox Pro, a web app at pro.sweepbox.app. This Privacy Policy covers both, and explains what data we handle, how, and your rights.
In plain English: your mail is processed on your own device and never reaches us. Both products talk to Gmail directly from your browser. We do run a small payments service, and it holds your email address and licence or subscription record — nothing else, and never any mail.
Contents
1. Who we are
SweepBox is independently built and operated. For privacy questions: privacy@sweepbox.app
2. The two products
SweepBox Lite (Chrome extension) scans your mail via the Gmail API, groups it by sender, and provides one-click unsubscribe and bulk delete. Scan results and settings are stored in chrome.storage.local on your device.
SweepBox Pro (web app) does the same and adds: a second list for non-subscription mail, sorting by size, age and read rate, a Trash view with per-sender recovery, filing senders under Gmail labels, "smart vaults" that label whole categories, and cleanup routines — saved rules that archive, trash, mark read or label matching mail, plus unsubscribe enforcement that re-sweeps senders who keep mailing after you unsubscribed. Its data is stored in your browser's localStorage under keys beginning sweepbox-pro:.
Both act on your mailbox only when you ask them to, or according to rules you have switched on yourself. Neither transmits your mail to us.
3. Data we handle
| Data | Where it comes from | Where it's stored | Why |
|---|---|---|---|
| Google OAuth token | You, by signing in to Google | Lite: Chrome's encrypted identity store. Pro: sessionStorage, cleared when the tab closes |
Required to call the Gmail API on your behalf |
| Email headers (From, Subject, List-Unsubscribe, List-Unsubscribe-Post) | Gmail API | In-memory during the scan; aggregated per-sender results stored locally | To identify senders, group them by brand, and find unsubscribe methods |
| Message IDs, sizes, dates and read/unread flags | Gmail API | Locally, in the scan cache | To bulk-delete a sender's mail, and (Pro) to show storage used, recency and how much of a sender's mail you actually open |
| Sender domains | Derived from sender addresses | Sent to the DeBounce logo API; resolved logo URLs cached locally | To display a sender's logo instead of a plain letter tile |
| Sender domains (MX check) | Derived from a sender's unsubscribe address | Not stored; cached in memory briefly | To check an email-based unsubscribe address still exists before writing to it |
| Your decisions about senders (unsubscribed, blocked, filed under a label, paused) | Your actions in the app | Locally, per Google account | To show status, and to run enforcement and auto-filing on later cleanups |
| Rules, smart vaults and cleanup history (Pro) | Rules you create; results of each cleanup you run | Locally, per Google account | To run your cleanups and show what the last one did |
| Usage counters (Lite) | Your actions in the extension | chrome.storage.local |
To enforce the free-tier caps |
| Licence key (Lite Unlimited) | Issued at purchase | chrome.storage.local, and on our server (see §4) |
To verify your unlock |
| Email address and subscription status (Pro) | Your Google account, verified server-side against Google | Our server (see §4) and Stripe | To check whether your subscription is active |
We do not store, transmit, or process:
- The bodies of your emails — we request specific headers only. The single exception is the one message you ask us to search for an unsubscribe link when a sender provides no unsubscribe header; that fetch happens in your browser and is not retained
- Your Google password (Google handles authentication)
- Any payment card data (Stripe handles all payment information)
- Your mail, sender lists, rules or scan results on any server of ours
4. What our servers hold
We run one small service, api.sweepbox.app (a Cloudflare Worker), purely for payments and entitlements. It stores, in Cloudflare KV:
- For Lite Unlimited: your licence key, the email address used at checkout, the Stripe session/customer reference, and the expiry date
- For Pro: your email address (as verified with Google), your Stripe customer and subscription references, plan, and current period end
That is the complete list. It never receives your mail, sender lists, message IDs, rules, or scan results — those never leave your browser.
5. Google API services — Limited Use disclosure
SweepBox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
SweepBox requests these Google OAuth scopes:
https://www.googleapis.com/auth/gmail.modify(both products) — to read email headers, apply and remove labels, archive, move mail to Trash and restore it, and send unsubscribe emails to senders that only accept the email-based method (RFC 8058mailto:)https://www.googleapis.com/auth/userinfo.email(Pro only) — so our payments service can confirm which account an access token belongs to when checking subscription status
Data accessed via these scopes is used solely to provide the user-facing features described above. It is not transferred to any third party except as necessary to provide those features, and is not used for advertising, sold, or used to train AI/ML models.
6. Third parties
- Google LLC — Gmail API and OAuth. Subject to Google's Privacy Policy.
- Stripe, Inc. — payment processing, used only when you buy Lite Unlimited or subscribe to Pro. Subject to Stripe's Privacy Policy. We never see your card details.
- Cloudflare, Inc. — hosts this site and the app, and runs the payments service and its key-value store. Subject to Cloudflare's Privacy Policy.
- Resend — sends the one-time licence key email after a Lite Unlimited purchase; processes your email address and licence key for that delivery only. Subject to Resend's Privacy Policy.
- Cloudflare DNS (1.1.1.1) — before sending an email-based unsubscribe, we ask
cloudflare-dns.comwhether the sender's domain still has a mail server, so we don't write to a dead address. The request contains only that domain. Subject to Cloudflare's 1.1.1.1 Privacy Policy. - DeBounce (logo API) — both products request sender logos from
logo.debounce.com. Each request tells DeBounce a domain that emails you (e.g.example.com). No addresses, subjects, message content or account identifiers are sent. If a logo isn't found, the sender keeps a plain letter tile. - Senders' own unsubscribe endpoints — when you unsubscribe, your browser contacts the address the sender published in its own List-Unsubscribe header (an HTTPS request, or an email sent from your account). That request goes to the sender, not to us, and is the mechanism by which unsubscribing works at all.
7. Cookies and tracking
Neither product uses cookies, web beacons, analytics SDKs or any tracking technology, and neither phones home. There is no advertising, no profiling and no third-party script embedded in the extension or the app.
8. Data retention
Your local data stays in your browser until you remove it:
- Lite: uninstall the extension and Chrome deletes everything it stored. "Wipe local data" in the account page clears scan results, caches, usage counters and unsubscribe history (your licence is preserved). "Sign out" revokes the OAuth token and clears local data.
- Pro: signing out drops the session token; clearing your browser's site data for
pro.sweepbox.appremoves everysweepbox-pro:key — scan caches, sender decisions, rules, cleanup history and counters. - On our server: licence and subscription records are kept while the entitlement is live and for a reasonable period afterwards for support and accounting. Email privacy@sweepbox.app to have yours deleted.
- Stripe retains payment records as required by tax and finance law (typically 7 years).
9. Your rights (GDPR / UK GDPR / CCPA)
If you are in the EU, UK or California, you have rights including:
- Access — to see what we hold (on our side: your email address and licence or subscription record; everything else is on your device)
- Erasure — to delete it (locally: wipe or uninstall; on our side: email us)
- Portability — to receive it in machine-readable form
- Objection / restriction — to stop processing
- Complaint — to your local data protection authority (e.g. the ICO in the UK)
To exercise any of these, contact privacy@sweepbox.app. We will respond within 30 days.
10. Children
SweepBox is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from children.
11. International data transfers
Your mail is processed in your own browser, so we initiate no cross-border transfer of it. Our payments service runs on Cloudflare's global network, and Google, Stripe and Resend may process data in any country where they operate, governed by their own policies and transfer safeguards.
12. Security
Lite stores its OAuth token in Chrome's encrypted identity store and its data in chrome.storage.local, sandboxed to the extension. Pro keeps its access token in sessionStorage — scoped to that browser tab, dropped when you close it, and expiring within the hour Google allows — and its data in localStorage, scoped to pro.sweepbox.app by the browser's origin model. Both are served over HTTPS with a strict Content-Security-Policy. Our payments service verifies every request against Google's token endpoint, so no one can look up or alter someone else's entitlement by guessing an email address. No system is perfectly secure; keep your browser and your Google account protected.
13. Changes to this Policy
We may update this Policy. Material changes will be announced in the products and reflected in the "Last updated" date above. Continued use after such changes constitutes acceptance.
14. Contact
Privacy questions: privacy@sweepbox.app
Support: support@sweepbox.app
SweepBox is independently built and is not endorsed by, affiliated with, or sponsored by Google LLC. "Gmail" is a trademark of Google LLC.