Skip to main content
POP3 for Gmail POP3 for Gmail

Privacy Policy

Last updated: September 1, 2026

1. Who operates the service

POP3 for Gmail is operated by the POP3 for Gmail team. For privacy questions, requests, or security concerns, contact [email protected].

2. What the service does

POP3 for Gmail is an independent mailbox bridge. When you choose to use it, the service connects a mailbox that you own or are authorized to use through POP3, IMAP, or a supported provider authorization and imports messages into the Gmail account you selected. The service does not replace Gmail and is not affiliated with Google LLC.

3. Information we process

We process the following information only to authenticate your account, connect the mailboxes you configure, synchronize messages, and operate the service:

4. Google API data and permissions

When you sign in with Google or connect a Gmail mailbox, Google asks you to authorize specific permissions. Depending on the features you use, POP3 for Gmail requests:

We use Google API data solely to provide the mailbox connection, synchronization, labeling, and related features that you request. We do not request the broad https://mail.google.com/, gmail.labels, or gmail.metadata permissions. We do not sell Google data, use it for advertising or profiling, or use it to train generalized artificial-intelligence or machine-learning models. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

5. How messages are handled

During a synchronization, a message may be held temporarily in memory or in a temporary processing file so it can be delivered reliably to Gmail. After processing finishes, temporary message files are removed. We do not maintain a separate webmail archive or use message content for an unrelated purpose. Message identifiers and synchronization records may remain so the service can recognize already imported messages, retry a delivery, and report the result.

Messages successfully imported into Gmail are stored by Google under your Gmail account and are then subject to Google's own policies and controls. POP3 for Gmail does not delete those Gmail messages when you disconnect or delete service data.

6. Sharing and service providers

We do not sell or rent personal information. Data is shared only as necessary to provide the feature you selected: with Google APIs to authenticate and deliver messages to Gmail, with the source email provider to retrieve messages, and with the infrastructure used to host POP3 for Gmail. We do not send mailbox content to advertising networks, data brokers, or unrelated analytics services.

7. Retention

Encrypted OAuth tokens, mailbox credentials, and account configuration are retained while the relevant connection is active. Message identifiers, quarantine state, and synchronization logs are retained while needed for deduplication, retries, account status, and service operation. Temporary copies of message content and attachments are removed after processing and are not retained as a message archive. When you delete a mailbox or all service data, the related active credentials, account configuration, identifiers, and logs are deleted from the active service database; encrypted backups may persist until their normal rotation.

8. Your controls and deletion

From the dashboard or extension you can pause a mailbox, change synchronization settings, disconnect a mailbox, clear activity history, and delete all service data. You can also revoke POP3 for Gmail from your Google Account's third-party access page. Deleting service data removes our stored connection data and invalidates active sessions; it does not remove messages already delivered to Gmail or from the original mailbox.

For step-by-step instructions, see our user data deletion instructions. You can also email [email protected]; requests are verified and normally processed within 48 hours.

9. Security

The service is served over HTTPS. Mailbox passwords, application passwords, and OAuth refresh tokens are encrypted at rest using authenticated encryption. Credentials and message content are not intentionally written to application logs. Source-provider transport security depends on the SSL/TLS or STARTTLS option selected in the mailbox configuration, and providers may impose their own security, filtering, or availability rules.

10. Essential cookies

The authenticated dashboard uses an essential, secure session cookie. The public website does not use third-party behavioral advertising cookies. See our Cookie Policy for details.

11. Changes and contact

We may update this policy when the service or its data practices change. The date at the top of this page shows when it was last revised. If you have a question about your information or want to exercise a privacy right, contact [email protected].