Legal
Privacy Policy.
Last updated · 2026-05-21
Who we are
HazyMails (“the Service”) is an invite-only outreach tool that lets you connect your own mailboxes and send personalized email campaigns through them. The Service is operated as a personal project; there is no separate company entity. References to “we” or “us” mean the operator of HazyMails.
What we collect
- Account data: the profile name, password hash, and display name you create at sign-up.
- Connected mailbox data: OAuth refresh and access tokens for Google and Microsoft mailboxes you authorize, plus the email address and display name returned by the provider. Tokens are encrypted at rest using AES-256-GCM before being written to the database.
- Campaign data: the recipient lists, variables, subject lines, body copy, and attachments you upload, plus per-recipient send / open / click / reply status.
- Inbox data: for accounts you connect, we read incoming messages only to the extent needed to detect replies to your campaigns and surface them in the in-app inbox.
- Operational logs: audit log entries for meaningful actions (mailbox connect / disconnect, campaign start, profile changes, login attempts), plus standard server logs from our hosting provider.
How we use it
- To authenticate you and keep your session active.
- To send the emails you instruct us to send, on your behalf, through the mailbox you authorized.
- To poll your inbox for replies to those campaigns and show you per-recipient open / click / reply state.
- To enforce per-mailbox daily caps and rate limits that protect deliverability.
- To investigate abuse, incidents, or bugs.
We do not sell your data, use it to train AI models, or share it with advertisers.
Google API services
HazyMails’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Gmail data only to provide the user-facing features the user has explicitly enabled (sending campaigns, detecting replies), and we do not transfer it to third parties except as needed to provide those features or comply with applicable law.
Where it lives
Application data is stored in a managed PostgreSQL database (Supabase, currently in the Sydney region) and served via Vercel. Object storage for attachments and message artifacts is provided by Supabase Storage. Encryption-at-rest keys are managed by the respective providers; per-mailbox OAuth tokens are additionally encrypted by us before insert.
How long we keep it
- Mailbox connections: until you remove the mailbox from the Mailboxes page or revoke access at the provider. Removal deletes the stored tokens and disconnects the mailbox from the Service.
- Campaigns and recipients: until you delete them.
- Audit logs: retained for operational purposes; not exposed to other users.
Your choices
- Disconnect a mailbox at any time from /mailboxes. This also removes any campaigns associated with that mailbox unless you reassign them first.
- Revoke OAuth accessdirectly with the provider — Google account settings or Microsoft account → Apps & services you’ve granted access to.
- Delete your account by asking your workspace admin, or by contacting us at the email below.
- Export — campaigns and recipient lists can be exported as CSV from the campaign view.
Cookies
We set a small number of strictly necessary cookies: a session cookie used by NextAuth.js to keep you signed in, and a workspace cookie used when a workspace is shared with you so we know which workspace you’re currently viewing. We do not use third-party analytics or advertising cookies.
Children
HazyMails is not directed at children under 16. Don’t use it if you are.
Changes to this policy
We’ll update the “Last updated” date at the top of this page when material changes are made. Continued use of the Service after an update constitutes acceptance of the revised policy.
Contact
Questions or requests (access, correction, deletion): email hasantoprak28@gmail.com.