This Privacy Policy describes how iConnect (“we,” “us,” or “the Service”) handles information when you use the Gmail campaign platform, including the web application and optional Chrome extension. iConnect is typically operated by you or your organization on infrastructure you control (for example, a private deployment or your own cloud account).
1. Who is responsible
The party that deploys and administers your iConnect instance (the “Operator”) is responsible for this Service and for fulfilling privacy obligations toward end users. If you have questions about how your data is handled, contact your Operator. This policy describes what the software does by design.
2. Information we collect
Account and authentication
- Email address and password (password stored using a one-way hash)
- Session cookies managed by NextAuth for sign-in
Gmail connection
- OAuth tokens and related metadata for Gmail accounts you connect (tokens are encrypted at rest using your deployment’s encryption key)
- Connected Gmail address and account settings (for example, daily send limits)
- If you opt in to delivery monitoring: headers from Mail Delivery Subsystem / bounce messages (failed recipient address and status snippets only — not full inbox content or message bodies)
Campaign and recipient data
- Campaign names, subjects, HTML bodies, schedules, and send settings
- Recipient information you import or enter (such as email addresses, names, and custom merge fields)
- Send job status, errors, and delivery-related logs
Email tracking
- Open and click events when tracking is enabled, including timestamps and recipient identifiers linked to campaigns
- Technical data needed to serve tracking pixels and redirect links (for example, IP address and user agent, as received by your tracking endpoint)
Chrome extension
- If you use the extension: API tokens you generate, Gmail compose content you choose to export, and connection state between the extension and your iConnect API URL
Premium billing (optional)
- If you top up Premium with a crypto wallet: your connected wallet address, transaction hash, chain id, and a cryptographic signature proving you control that wallet (used only to match your payment to your account)
- Subscription records (provider, amount, plan length, activation dates) stored in your deployment’s database
We do not run identity verification (KYC) or collect government IDs for payments. Wallet top-up requires only your iConnect account sign-in and a wallet signature.
3. How we use information
We use collected information to:
- Authenticate you and operate the dashboard
- Send email on your behalf through connected Gmail accounts
- Optionally detect delivery failures from Gmail bounce notifications when you enable delivery monitoring
- Apply merge tags, throttling, work schedules, and per-account rotation
- Record campaign progress and optional open/click analytics
- Support the Chrome extension’s account linking and draft export features
- Verify on-chain Premium payments and activate or extend your subscription when billing is enabled
We do not sell your personal information. We do not use your data for third-party advertising.
4. Third-party services
Depending on your configuration, data may be processed by:
- Google / Gmail API — to send mail, manage OAuth for connected accounts, and (if you opt in) read bounce message headers for delivery status (subject to Google’s Privacy Policy)
- Hosting and database providers — for example, Vercel (web app) and Turso (database), if you deploy there
- BTCPay Server — if you enable Bitcoin/Lightning billing, payment metadata (such as your account email and user id) is sent to your configured BTCPay instance to create invoices; we do not store card numbers
- WalletConnect / RainbowKit — if you enable EVM wallet billing, your browser connects to WalletConnect to link a crypto wallet; we do not receive your wallet’s private keys
- Phantom — if you enable Solana billing, the Phantom browser extension (via Phantom Connect) signs USDC transfers and verification messages; we do not receive your private keys
- Public blockchains — wallet payments are verified by reading public transaction data (for example via RPC providers you configure). On-chain transfers are public by nature
Your Operator chooses these providers and is responsible for their agreements and data processing terms.
5. Storage and security
Data is stored in the database configured for your deployment (SQLite locally or Turso in production). Gmail OAuth tokens are encrypted with the ENCRYPTION_KEY set in your environment. You are responsible for protecting secrets, access to the server, and backups.
6. Retention
Campaign, recipient, and tracking data are retained until deleted by an authorized user or until your Operator removes or resets the database. Session data expires according to your authentication configuration.
7. Your choices and rights
Depending on applicable law and your role, you may be able to:
- Access or correct account information through the Service or your Operator
- Disconnect Gmail accounts from the Accounts page
- Delete campaigns and associated recipient data from the dashboard
- Request deletion or export of your data from your Operator
If you are a recipient of emails sent through iConnect, contact the sender or their organization directly regarding list removal or privacy requests.
8. Email recipients
If you import contacts or send campaigns, you are responsible for having a lawful basis to process recipient data, providing required notices, and honoring opt-out requests. Tracking pixels and links should be disclosed where required by law.
9. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal information.
10. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact
For privacy questions, email akiranakao.dev@gmail.com.