Privacy notice
NSMBL Mail privacy
NSMBL Mail is a private, owner-managed service for connected business and project mailboxes.
Privacy notice
Effective September 25, 2026
Access and purpose
NSMBL.IO operates this private service. Google authorization identifies the connected account and permits mailbox operations. The requested Gmail permission allows reading, composing, sending, and permanently deleting email. Authorization does not itself send or delete a message. Account enrollment and connection checks require owner sign-in. Controlled pilot operations run only when explicitly initiated through authenticated tools. General-purpose agent access is not enabled.
Data handled
The service processes account identity, OAuth credentials, owner sessions, connection status, account-management activity, and, during controlled tests, message identifiers and generated test messages and attachments. It records operation status and recovery evidence. Mailbox providers remain the source of truth; the pilot does not continuously synchronize or index inboxes.
Storage and sharing
Static credentials and encryption keys are stored in Infisical and supplied to the private Cloudflare service. Google credentials enrolled through the dashboard are encrypted with authenticated encryption in private Cloudflare storage. Operation records and test-message files are stored in private Cloudflare storage. Local enrollment temporarily stores a refresh token in an access-restricted file until it has been imported and verified. Data is shared with these infrastructure providers and the connected email provider as needed to perform authorized operations. Credentials are not returned to agent clients.
Retention and control
Completed test-message files become eligible for cleanup after 24 hours. Uncertain operations retain recovery evidence to prevent accidental resending. Account-management activity is retained for up to 90 days. Pilot operation records remain until the owner removes them. Disconnecting a dashboard account removes its stored mailbox credential without deleting email. Owner sessions expire after 12 hours. Test messages delivered to an inbox remain subject to that mailbox's controls. To revoke Google access, use your Google Account connections. Revocation stops future authorized access but does not recall messages already sent. Contact the owner to remove stored credentials and pilot data.
Limited use
NSMBL Mail does not sell email data, use it for advertising, or use it to train generalized AI models. The pilot does not send mailbox content to an AI model. Its use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. Changes to how connected-account data is used will be disclosed before that use begins, with renewed consent where required.
Contact
For questions, disconnection, or data deletion, email maddox@nsmbl.io.