Privacy Policy
Last updated October 4, 2026
This policy explains what data Airletter – the website, the dashboard and the Chrome extension (together, the “service”) – processes, why, where it is stored, who it is shared with and how to delete it. A separate section covers data received from Google.
1. Who we are
Data controller: Parkhomenko Alexey Alexandrovich, self-employed (Russian Federation), taxpayer ID 920162449661. Address: Saint Petersburg, Russia. For any question about your data: airlettercontact@gmail.com.
2. Data we receive
Your Airletter account
- The email address and name you enter when you sign up.
- Your password, stored only as an irreversible bcrypt hash; we never store or see the password itself.
Google data – only when you connect Gmail
Airletter requests the following scopes and receives only this through them:
- openid, userinfo.email, userinfo.profile – your Google account email address, name and profile picture. Used to show which address your emails are sent from and to fill in the “From” field.
- gmail.send – permission to send email on your behalf. Airletter only sends the emails you have written and launched yourself. We do not read your inbox or sent mail, do not receive your message list, contacts or mailbox metadata, and do not modify or delete anything – this scope does not grant such access.
- spreadsheets.readonly – reading the Google Sheet you point to when importing recipients. We read only the range you specify, at the moment of import, and keep only the email addresses from its first column. The rest of the spreadsheet is not stored. We do not open any of your other files.
- Google OAuth tokens that allow the actions above. Stored encrypted.
Campaigns
- Subject, body (HTML or plain text), attachments and inline images, recipient addresses, schedule.
- Delivery log: status per recipient, time, the Gmail ID of the sent message, and the error text if a message failed.
Payments
- Plan, amount, currency, payment status and ID. We never receive or store card details – YooKassa and Stripe process them on their own pages.
Technical data
- Server logs: IP address, request time and path, response code – for security and troubleshooting.
- The extension keeps your Airletter sign-in tokens and imported recipient lists in Chrome extension storage on your device.
3. How we use data
Only to provide the features you see in the service:
- signing you in and protecting your account;
- sending your campaigns through your Gmail within daily limits;
- importing recipients from the spreadsheet you choose;
- showing campaign status and statistics in the dashboard and extension;
- processing payments, tracking your plan and meeting tax obligations;
- answering your support requests.
We do not use data for advertising, do not profile users and do not sell data. We never send our own messages to your recipients.
4. Google user data and Limited Use
Airletter’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
In particular:
- Google user data is used only to provide the Airletter features described above and visible to you;
- Google user data is never used to serve ads, including personalized ads and retargeting;
- Google user data is never sold and never shared with data brokers or advertising platforms;
- Google user data is transferred to third parties only as needed to provide the service (see section 7), to comply with the law, or as part of a merger, acquisition or sale of the service – and only with your prior consent;
- no human reads your Google user data unless you have given explicit consent for a specific case (for example, a support request), it is needed to investigate abuse or for security, it is required by law, or the data is aggregated and anonymized for internal operations;
- Airletter does not use data obtained through Google Workspace APIs to develop, improve or train generalized artificial intelligence or machine learning models (Google Workspace API User Data and Developer Policy).
5. Legal bases (GDPR)
- performance of a contract (our Terms of Service): your account, sending campaigns, payments;
- consent: connecting Gmail and granting Google permissions – you can withdraw it at any time;
- legitimate interests: security of the service and abuse prevention (server logs);
- legal obligations: keeping payment and tax records.
6. Where and how data is stored
- Backend server and database: Selfhosted, bare metal. The website is hosted on Vercel.
- All connections use HTTPS (TLS) only.
- Google OAuth tokens are encrypted at rest (AES-256-GCM), passwords are stored as bcrypt hashes, and session tokens live in cookies that page scripts cannot read.
- Only the operator has access to the servers and the database.
Retention
- account, campaigns and delivery log – while your account exists, or until you ask us to delete them;
- Google tokens – until you disconnect Gmail in the dashboard or revoke access in your Google account; on disconnect the token is revoked with Google and deleted immediately;
- payment records – for the period required by tax law;
- server logs – for the limited time needed for security and troubleshooting.
7. Who we share data with
Only with providers the service cannot work without, and only to the extent their task requires:
- backend and database hosting – Selfhosted, bare metal;
- Vercel Inc. (USA) – website hosting;
- Google LLC (USA) – sending email via the Gmail API and reading the spreadsheets you choose, on your instruction;
- YooMoney LLC (YooKassa, Russia) – payments in rubles;
- Stripe, Inc. (USA) and Stripe Payments Europe, Ltd. (Ireland) – payments in US dollars.
Google user data is never shared with payment providers or other third parties. The service uses no analytics or advertising services.
8. International transfers
Some providers (Google, Vercel, Stripe) are located outside the EU and Russia. Data is transferred only to provide the service, and these providers protect it under their own safeguards and contractual commitments, including the EU Standard Contractual Clauses.
9. Cookies
The website uses only essential cookies: the sign-in session (secure httpOnly cookies), a signed-in marker for the interface, your language, and a short-lived cookie while you connect Gmail. There are no advertising or analytics cookies, so no consent banner is shown.
10. Deleting data and revoking access
- Disconnect Gmail with the “Disconnect” button in the dashboard. The token is revoked with Google and deleted on our side immediately.
- Revoke access on Google’s side at myaccount.google.com/permissions: select Airletter and remove access.
- Delete your account and all data by emailing airlettercontact@gmail.com from your account address. We delete the account, campaigns, attachments, delivery log and tokens within 30 days and confirm the deletion. Payment records are kept as long as the law requires.
- Data in your browser is removed with the extension or when you sign out in it.
11. Your rights
You can request access to your data and a copy in a machine-readable format, rectification, erasure, restriction of processing, object to processing and withdraw consent. Send requests to airlettercontact@gmail.com; we respond within 30 days. You also have the right to lodge a complaint with the data protection authority in your country of residence.
12. Age
The service is not intended for anyone under 16. We do not knowingly collect their data.
13. Changes to this policy
The date of the latest version is shown at the top of this page. We will notify you by email in advance of material changes. If a change affects how we use Google user data, we will ask for your consent again.