Skip to content

OneTally Mail Privacy Policy

Effective date: September 27, 2026

This policy describes how OneTally LC handles information in OneTally Mail, a private email archive at https://mail.onetally.app. It is specific to Mail. The separate OneTally Money policy at https://onetally.app/privacy does not describe Mail’s access to Gmail.

Who operates Mail

OneTally LC, a Maryland limited liability company, operates the service. Questions and privacy requests may be sent to hello@onetally.app.

Information Mail accesses

When you connect a Google account, Mail receives the account’s email address and Google account identifier. With your consent, it can read Gmail message history and new mail, including headers, message bodies, sent mail and attachments. It can read labels and read state, change mailbox state when you request an action, and send a message you compose. It does not ask for or store your Google password. You can also import EML or MBOX files or configure forwarding; those routes bring in the messages and attachments you choose to provide.

The service also processes account and sign-in identifiers, your mailbox and alias settings, archive searches and actions, and technical request data needed for authentication, security and troubleshooting. It does not request your Google contacts or Google account settings.

How Mail uses Google data

Mail uses Gmail data only to provide the features you request: synchronize and display mail, search and organize your private archive, preserve original messages and attachments, export or remove archived data, update Gmail state when you use a mailbox action, and send a message you compose. It does not use Gmail data for advertising, sell it, or share it with data brokers. Mail does not currently send message content to an AI provider or use it to train AI models.

OneTally Mail’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Human access to Google user data is limited to what is necessary to provide user-requested support, investigate a security incident, comply with law, or operate the service, with appropriate access controls.

Storage and service providers

Mail currently stores structured archive data and connection records in Cloudflare D1, and original messages and attachments in private Cloudflare R2 storage. Cloudflare Workers process synchronization and requests. Google supplies the connected mailbox and processes messages you choose to send. OpenAI and Cloudflare may process sign-in or access-control information needed to restrict the application to its owner. A move to another database provider will be reflected here when it is actually deployed; this policy does not claim that Mail currently stores its archive in Supabase.

OAuth refresh tokens are encrypted before storage and are used server-side to access the connected account. They are not sent to the browser. Archived messages are not end-to-end encrypted; authorized server components must be able to read them to provide search, display and export. Providers may process technical logs and request metadata as needed to run the service. We do not provide mailbox content to third-party advertising or analytics services.

Cookies and tracking

Mail and its access providers use cookies or similar session mechanisms necessary to sign you in, keep the private app protected and prevent abuse. The public informational pages at onetally.app may use cookieless product analytics described in the OneTally site policy. We do not use advertising cookies in Mail and do not run session recording of mailbox content.

Your control and retention

You can disconnect a Google account from Mail. Disconnecting removes its stored authorization and attempts to revoke it at Google; already archived mail remains until you remove it separately. You can also revoke access from your Google Account. Private exports expire after seven days. An archive removal request has a seven-day cancellation period before its processing; backup copies may remain until their limited retention period ends. Mail does not delete messages from your original Gmail account when you remove an archived copy unless you separately request a Gmail mailbox action.

You may request access, correction, export or deletion by writing to hello@onetally.app. We may retain limited records where required for security, legal compliance or dispute resolution. We will update this page if Mail’s data practices change materially.

Security and contact

We use access restrictions, encrypted transport and encrypted stored OAuth tokens, but no online service can guarantee absolute security. Mail is currently an owner-only, pre-release application, not a public customer service. Contact OneTally LC at hello@onetally.app or 1190 Winterson Rd, Suite 200 PMB 1049, Linthicum Heights, MD 21090, United States.