Security

Last updated: February 15, 2026

Security-First Design

We never store your email content. All emails are fetched in real-time with read-only access. Your data security is our top priority.

1. Data Protection

1.1 What We Store

MailChrono stores minimal data to provide our service:

  • Account Information: Name, email address, and profile picture URL (from OAuth providers)
  • OAuth Tokens: Encrypted access and refresh tokens for connecting to your email accounts
  • Usage Metrics: Daily thread view counts and workspace settings

1.2 What We Never Store

We are committed to never storing:

  • Email Content: Message bodies, subjects, or metadata
  • Attachments: Any files attached to your emails
  • Contacts: Email addresses from your address book
  • Passwords: We use OAuth 2.0; we never see your passwords

2. Encryption

2.1 Data at Rest

All sensitive data stored in our databases is encrypted:

  • OAuth Tokens: AES-256-GCM encryption with unique initialization vectors
  • Encryption Keys: Stored securely in Cloudflare's encrypted environment variables
  • Database: All data is stored in Cloudflare D1 with encryption at rest

2.2 Data in Transit

All data transmitted to and from MailChrono is encrypted:

  • HTTPS/TLS 1.3: All connections use modern TLS encryption
  • OAuth 2.0: Secure authorization flow with state verification
  • API Calls: All email provider API calls use HTTPS

3. Access Control

3.1 OAuth 2.0 Authentication

We use industry-standard OAuth 2.0 to access your email accounts. This means:

  • We never see or store your email password
  • You authorize access through Google or Microsoft's secure login
  • You can revoke access at any time from your account settings
  • Tokens automatically expire and are refreshed securely

3.2 Read-Only Permissions

MailChrono requests only read-only access to your emails:

  • Gmail: gmail.readonly scope only
  • Microsoft: Mail.Read permission only
  • We cannot send, delete, or modify your emails
  • We cannot access your contacts or calendar

3.3 Session Management

User sessions are managed securely:

  • Session tokens stored in secure, HTTP-only cookies
  • Automatic session expiration after inactivity
  • Secure logout invalidates all tokens

4. Infrastructure Security

4.1 Cloudflare Platform

MailChrono is built on Cloudflare's enterprise-grade infrastructure:

  • Global Edge Network: Data served from 300+ locations worldwide
  • DDoS Protection: Built-in protection against distributed attacks
  • WAF (Web Application Firewall): Protection against common web vulnerabilities
  • ISO 27001 Certified: Cloudflare maintains rigorous security standards

4.2 Zero-Trust Architecture

Our application follows zero-trust principles:

  • Every request is authenticated and authorized
  • Minimal privilege access for all operations
  • No persistent connections to email servers
  • All data access is logged and audited

5. Security Best Practices

5.1 Development Practices

  • Regular security audits and vulnerability assessments
  • Dependency scanning for known vulnerabilities
  • Code reviews with security focus
  • Principle of least privilege for all system access

5.2 Monitoring & Incident Response

  • 24/7 monitoring of system health and security events
  • Automated alerts for suspicious activity
  • Incident response plan with defined escalation procedures
  • Regular backup and disaster recovery testing

6. Third-Party Services

We carefully vet all third-party services we use:

  • Google OAuth: Industry-standard authentication
  • Microsoft OAuth: Enterprise-grade authorization
  • Paddle: PCI-compliant payment processing (we never handle credit cards)
  • Cloudflare: ISO 27001 certified infrastructure provider

7. Compliance

MailChrono is committed to compliance with:

  • GDPR: European data protection regulations
  • CCPA: California Consumer Privacy Act
  • OAuth 2.0: RFC 6749 and RFC 6750 compliance

8. Data Deletion

When you delete your account:

  • All personal data is permanently deleted within 30 days
  • OAuth tokens are immediately revoked and deleted
  • Since we don't store email content, there's no email data to delete
  • Workspace data is removed or anonymized based on team settings

9. User Responsibilities

To maintain security, we recommend that you:

  • Use strong, unique passwords for your email accounts
  • Enable two-factor authentication on your Google/Microsoft accounts
  • Keep your devices and browsers up to date
  • Review connected applications regularly in your account settings
  • Immediately revoke access if you suspect unauthorized activity

10. Vulnerability Disclosure

We appreciate security researchers and users who help us keep MailChrono secure.

Reporting Security Issues

If you discover a security vulnerability, please report it to:

  • Email: security@mailchrono.com
  • Response Time: We aim to respond within 24 hours
  • Disclosure: Please allow us 90 days to address the issue before public disclosure

What to Include

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Any proof-of-concept code (if applicable)

11. Security Updates

We regularly update this security page to reflect our current practices. For questions about our security measures, please contact us at security@mailchrono.com.

Questions?

If you have any questions about our security practices, please don't hesitate to reach out at security@mailchrono.com.