ICARUS Mail Organizer Privacy Policy

Published by: [PUBLISHER LEGAL NAME — Gav to confirm before public release] Effective date: August 31, 2026

ICARUS Mail Organizer creates Gmail labels and label-only filters at your request, from a one-time setup link. It does not read your message content.

What we ask permission for

Exactly four OAuth scopes, and nothing else:

ScopeWhy
openid, emailTo record which Google account completed the setup, so the sender can confirm the right person used their link.
gmail.labelsTo list your labels and create the eight ICARUS labels.
gmail.settings.basicTo list your filters and create the thirteen sorting rules.

We do not request, and therefore cannot perform, any operation that reads message content, sends email, creates drafts, deletes or archives email, marks email read, or configures forwarding.

How your Google access is handled

This is a one-time setup, not a connected app.

  1. You approve the permissions on Google's own screen.
  2. Google issues us a short-lived access token. We request it as an *online*

token, so no refresh token is ever created.

  1. The token is held in memory only, for the few seconds it takes to create

your labels and filters. It is never written to a database, log, or file.

  1. We then revoke the token ourselves, on every run, whether the setup

succeeded or failed.

After the setup finishes, ICARUS has no further access to your Gmail. You can confirm this at myaccount.google.com/permissions — ICARUS Mail Organizer will not be listed.

The labels and filters stay in your Google account and keep working with nothing installed.

What we do store

We keep a small record of each invitation so the person who sent your link can see whether it worked:

We do not store your emails, your message content, your contacts, your existing labels or filters, or any Google credential or token.

This record is held in a Cloudflare D1 database and is visible only to the account holder who sent your invitation.

Limited Use disclosure

ICARUS Mail Organizer's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties, do not use it for advertising, and do not allow humans to read it, except as required for security or to comply with applicable law.

Removing what was set up

The labels and filters are yours. To remove them, delete the ICARUS labels in Gmail's label settings and delete the ICARUS rules under Settings → Filters and Blocked Addresses. No contact with us is required.

To have your invitation record deleted, contact the address on the support page.

Changes

Material changes to this policy will be reflected in the effective date above.