Privacy Policy

SweepBox ("we", "our", "us") makes two products for cleaning up Gmail: SweepBox Lite, a Chrome extension that runs in Gmail's side panel, and SweepBox Pro, a web app at pro.sweepbox.app. This Privacy Policy covers both, and explains what data we handle, how, and your rights.

In plain English: your mail is processed on your own device and never reaches us. Both products talk to Gmail directly from your browser. We do run a small payments service, and it holds your email address and licence or subscription record — nothing else, and never any mail.

Contents

  1. Who we are
  2. The two products
  3. Data we handle
  4. What our servers hold
  5. Google API services — Limited Use
  6. Third parties
  7. Cookies and tracking
  8. Data retention
  9. Your rights
  10. Children
  11. International transfers
  12. Security
  13. Changes
  14. Contact

1. Who we are

SweepBox is independently built and operated. For privacy questions: privacy@sweepbox.app

2. The two products

SweepBox Lite (Chrome extension) scans your mail via the Gmail API, groups it by sender, and provides one-click unsubscribe and bulk delete. Scan results and settings are stored in chrome.storage.local on your device.

SweepBox Pro (web app) does the same and adds: a second list for non-subscription mail, sorting by size, age and read rate, a Trash view with per-sender recovery, filing senders under Gmail labels, "smart vaults" that label whole categories, and cleanup routines — saved rules that archive, trash, mark read or label matching mail, plus unsubscribe enforcement that re-sweeps senders who keep mailing after you unsubscribed. Its data is stored in your browser's localStorage under keys beginning sweepbox-pro:.

Both act on your mailbox only when you ask them to, or according to rules you have switched on yourself. Neither transmits your mail to us.

3. Data we handle

Data Where it comes from Where it's stored Why
Google OAuth token You, by signing in to Google Lite: Chrome's encrypted identity store. Pro: sessionStorage, cleared when the tab closes Required to call the Gmail API on your behalf
Email headers (From, Subject, List-Unsubscribe, List-Unsubscribe-Post) Gmail API In-memory during the scan; aggregated per-sender results stored locally To identify senders, group them by brand, and find unsubscribe methods
Message IDs, sizes, dates and read/unread flags Gmail API Locally, in the scan cache To bulk-delete a sender's mail, and (Pro) to show storage used, recency and how much of a sender's mail you actually open
Sender domains Derived from sender addresses Sent to the DeBounce logo API; resolved logo URLs cached locally To display a sender's logo instead of a plain letter tile
Sender domains (MX check) Derived from a sender's unsubscribe address Not stored; cached in memory briefly To check an email-based unsubscribe address still exists before writing to it
Your decisions about senders (unsubscribed, blocked, filed under a label, paused) Your actions in the app Locally, per Google account To show status, and to run enforcement and auto-filing on later cleanups
Rules, smart vaults and cleanup history (Pro) Rules you create; results of each cleanup you run Locally, per Google account To run your cleanups and show what the last one did
Usage counters (Lite) Your actions in the extension chrome.storage.local To enforce the free-tier caps
Licence key (Lite Unlimited) Issued at purchase chrome.storage.local, and on our server (see §4) To verify your unlock
Email address and subscription status (Pro) Your Google account, verified server-side against Google Our server (see §4) and Stripe To check whether your subscription is active

We do not store, transmit, or process:

4. What our servers hold

We run one small service, api.sweepbox.app (a Cloudflare Worker), purely for payments and entitlements. It stores, in Cloudflare KV:

That is the complete list. It never receives your mail, sender lists, message IDs, rules, or scan results — those never leave your browser.

5. Google API services — Limited Use disclosure

SweepBox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

SweepBox requests these Google OAuth scopes:

Data accessed via these scopes is used solely to provide the user-facing features described above. It is not transferred to any third party except as necessary to provide those features, and is not used for advertising, sold, or used to train AI/ML models.

6. Third parties

7. Cookies and tracking

Neither product uses cookies, web beacons, analytics SDKs or any tracking technology, and neither phones home. There is no advertising, no profiling and no third-party script embedded in the extension or the app.

8. Data retention

Your local data stays in your browser until you remove it:

9. Your rights (GDPR / UK GDPR / CCPA)

If you are in the EU, UK or California, you have rights including:

To exercise any of these, contact privacy@sweepbox.app. We will respond within 30 days.

10. Children

SweepBox is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from children.

11. International data transfers

Your mail is processed in your own browser, so we initiate no cross-border transfer of it. Our payments service runs on Cloudflare's global network, and Google, Stripe and Resend may process data in any country where they operate, governed by their own policies and transfer safeguards.

12. Security

Lite stores its OAuth token in Chrome's encrypted identity store and its data in chrome.storage.local, sandboxed to the extension. Pro keeps its access token in sessionStorage — scoped to that browser tab, dropped when you close it, and expiring within the hour Google allows — and its data in localStorage, scoped to pro.sweepbox.app by the browser's origin model. Both are served over HTTPS with a strict Content-Security-Policy. Our payments service verifies every request against Google's token endpoint, so no one can look up or alter someone else's entitlement by guessing an email address. No system is perfectly secure; keep your browser and your Google account protected.

13. Changes to this Policy

We may update this Policy. Material changes will be announced in the products and reflected in the "Last updated" date above. Continued use after such changes constitutes acceptance.

14. Contact

Privacy questions: privacy@sweepbox.app
Support: support@sweepbox.app