How POP3 for Gmail Protects Your Data
Limited access, encrypted data, and total control. We only request the minimal permissions required to deliver your messages into Gmail.
Google OAuth
You authenticate directly via Google. POP3 for Gmail receives an expiring revocable token, never your Google account password.
Encrypted Credentials
When third-party providers require standard credentials, they are encrypted at rest using AES-256-GCM authenticated encryption.
Direct delivery to Gmail
Emails are streamed and inserted into Gmail via official APIs. POP3 for Gmail never creates a permanent secondary mailbox store.
You decide when to disconnect
You can pause synchronization, revoke access, delete a mailbox or purge all account metadata at any time with one click.
Technical Details of Our Security Model
1. Google OAuth 2.0 Authorization
When connecting your destination Gmail account, authentication is performed directly on Google servers. POP3 for Gmail receives an expiring, restricted access token for message ingestion. We never see or store your Google password.
2. AES-256-GCM Credential Encryption
For traditional POP3/IMAP credentials, data is encrypted at rest using AES-256-GCM with regularly rotated master encryption keys.
3. Zero Permanent Secondary Storage
Messages are streamed in-memory from your origin host to the Gmail API. We do not store permanent copies of your emails or attachments once delivery is confirmed.
4. Right to Erasure
Deleting or pausing a mailbox immediately purges all associated tokens, credentials, and logs from our database.
Keep using Gmail. Only change how your mail arrives.
Connect your first mailbox, verify your settings, and let POP3 for Gmail maintain seamless background synchronization.
No DNS modifications · Guided setup wizard · Disconnect anytime