Privacy Policy

mail.roud.cz · last updated 30 September 2026

mail.roud.cz is a private, non-commercial web application that lets a small circle of family members and friends read and archive e-mail from several of their own mailboxes in one place. It is run by one person (the administrator, reachable at tomas@roud.cz) and is not offered to the public.

What data we process

  • Your e-mail. Messages, their headers and attachments from the mailboxes you (or the administrator on your behalf) connect, downloaded over IMAP.
  • Mailbox credentials. An IMAP password or, for Gmail, an OAuth refresh and access token. They are stored encrypted and used only to connect to your mailbox.
  • Your Google account e-mail address, to know which mailbox a Google authorization belongs to.
  • Account details – your name and e-mail addresses used for signing in.
  • Technical logs – IP address, browser user agent and time of sign-ins and requests, kept for security.

How we use it

Only to provide the service to you: to synchronise your mailboxes, keep a local archive, and let you read and search your mail. We do not use your data for advertising, profiling, selling, or training of any AI or machine-learning models, and we do not share it with anyone except as described below.

Google user data

When you connect a Gmail account, the app requests access to your mailbox (https://mail.google.com/) plus your e-mail address (openid, email). This access is used solely to download your messages over IMAP into your private archive and, in future versions, to send e-mail that you write in the app. No human reads your messages except you, unless you ask the administrator for help, it is needed for security reasons or required by law.

mail.roud.cz's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Where it is stored and who can see it

Data is stored on a server operated by the administrator. Credentials and tokens are encrypted; the whole connection is served over HTTPS. Each user sees only the mail assigned to them. The administrator has technical access to the server. Sign-in links and notices are sent by e-mail through the administrator's own mail service; the administrator may receive a push notification (Pushover) that a sign-in happened. No other third parties receive your data.

Cookies

Only strictly necessary cookies: a session cookie that keeps you signed in and a short-lived cookie that protects the Google authorization flow. No analytics or tracking.

Retention and deletion

Your archive is kept until you ask for its deletion – the purpose of the app is to keep mail even after it is removed from the original server. Sign-in records are deleted after 90 days. You can revoke the app's access to Google at any time at myaccount.google.com/permissions, and you can ask the administrator to disconnect a mailbox and delete your account, archive and tokens. This is done without undue delay.

Your rights

You may ask for access to, correction, export or deletion of your data, or object to its processing, by writing to tomas@roud.cz. You may also contact your data protection authority.

Changes

If this policy changes, the new version will be published on this page with a new date.

Privacy Policy · Terms of Service · Sign in