Last updated: June 2026 (v1.0)
In plain English, DataTrail collects:
We do not sell your data or share it for advertising. The only third party that receives any data is RevenueCat, which processes your subscription purchase on our behalf. Breach checks use a public, domain-level catalogue only — your email address is never sent to any breach-lookup service. All traffic is encrypted over HTTPS, and you can delete everything at any time from the Profile tab.
When you create an account, we receive your name and email address (and your profile picture if you sign in with Google or Apple). When you run an inbox scan, we process email metadata only: sender addresses, email dates, and unsubscribe headers. We never read, store, or transmit the body content of your emails.
We use email metadata solely to build your list of companies, estimate which privacy laws may apply to you, and power the Inbox Cleanup feature. We do not sell your data, share it with third parties for marketing, or use it for advertising.
We store your profile information, your derived company list (domain, name, email count, most recent email date), your selected jurisdiction, and encrypted credentials used to run the scans you request — an OAuth refresh token for Gmail or Outlook, or an app-specific password for IMAP providers. Encryption keys are managed server-side and credentials are never exposed to your device.
DataTrail's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the gmail.readonly scope only, and only to provide user-facing features you explicitly trigger.
You can disconnect your mailbox at any time from the Profile tab, which deletes your stored credentials and your entire scanned company list from our servers. You may also delete your account entirely from the Profile tab. For Gmail or Outlook, you can additionally revoke access from your Google or Microsoft account settings at any time. See our account & data deletion page for step-by-step instructions.
Refresh tokens are encrypted at rest, all traffic is served over HTTPS, and access to your data requires your authenticated session. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard measures.
DataTrail is not directed to children under 13, and we do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Material changes will be presented to you for review before you continue using the Service.
DataTrail · Questions? Contact support@datatrail.app.