Security
Last updated: February 15, 2026
Security-First Design
We never store your email content. All emails are fetched in real-time with read-only access. Your data security is our top priority.
1. Data Protection
1.1 What We Store
MailChrono stores minimal data to provide our service:
- Account Information: Name, email address, and profile picture URL (from OAuth providers)
- OAuth Tokens: Encrypted access and refresh tokens for connecting to your email accounts
- Usage Metrics: Daily thread view counts and workspace settings
1.2 What We Never Store
We are committed to never storing:
- Email Content: Message bodies, subjects, or metadata
- Attachments: Any files attached to your emails
- Contacts: Email addresses from your address book
- Passwords: We use OAuth 2.0; we never see your passwords
2. Encryption
2.1 Data at Rest
All sensitive data stored in our databases is encrypted:
- OAuth Tokens: AES-256-GCM encryption with unique initialization vectors
- Encryption Keys: Stored securely in Cloudflare's encrypted environment variables
- Database: All data is stored in Cloudflare D1 with encryption at rest
2.2 Data in Transit
All data transmitted to and from MailChrono is encrypted:
- HTTPS/TLS 1.3: All connections use modern TLS encryption
- OAuth 2.0: Secure authorization flow with state verification
- API Calls: All email provider API calls use HTTPS
3. Access Control
3.1 OAuth 2.0 Authentication
We use industry-standard OAuth 2.0 to access your email accounts. This means:
- We never see or store your email password
- You authorize access through Google or Microsoft's secure login
- You can revoke access at any time from your account settings
- Tokens automatically expire and are refreshed securely
3.2 Read-Only Permissions
MailChrono requests only read-only access to your emails:
- Gmail:
gmail.readonlyscope only - Microsoft:
Mail.Readpermission only - We cannot send, delete, or modify your emails
- We cannot access your contacts or calendar
3.3 Session Management
User sessions are managed securely:
- Session tokens stored in secure, HTTP-only cookies
- Automatic session expiration after inactivity
- Secure logout invalidates all tokens
4. Infrastructure Security
4.1 Cloudflare Platform
MailChrono is built on Cloudflare's enterprise-grade infrastructure:
- Global Edge Network: Data served from 300+ locations worldwide
- DDoS Protection: Built-in protection against distributed attacks
- WAF (Web Application Firewall): Protection against common web vulnerabilities
- ISO 27001 Certified: Cloudflare maintains rigorous security standards
4.2 Zero-Trust Architecture
Our application follows zero-trust principles:
- Every request is authenticated and authorized
- Minimal privilege access for all operations
- No persistent connections to email servers
- All data access is logged and audited
5. Security Best Practices
5.1 Development Practices
- Regular security audits and vulnerability assessments
- Dependency scanning for known vulnerabilities
- Code reviews with security focus
- Principle of least privilege for all system access
5.2 Monitoring & Incident Response
- 24/7 monitoring of system health and security events
- Automated alerts for suspicious activity
- Incident response plan with defined escalation procedures
- Regular backup and disaster recovery testing
6. Third-Party Services
We carefully vet all third-party services we use:
- Google OAuth: Industry-standard authentication
- Microsoft OAuth: Enterprise-grade authorization
- Paddle: PCI-compliant payment processing (we never handle credit cards)
- Cloudflare: ISO 27001 certified infrastructure provider
7. Compliance
MailChrono is committed to compliance with:
- GDPR: European data protection regulations
- CCPA: California Consumer Privacy Act
- OAuth 2.0: RFC 6749 and RFC 6750 compliance
8. Data Deletion
When you delete your account:
- All personal data is permanently deleted within 30 days
- OAuth tokens are immediately revoked and deleted
- Since we don't store email content, there's no email data to delete
- Workspace data is removed or anonymized based on team settings
9. User Responsibilities
To maintain security, we recommend that you:
- Use strong, unique passwords for your email accounts
- Enable two-factor authentication on your Google/Microsoft accounts
- Keep your devices and browsers up to date
- Review connected applications regularly in your account settings
- Immediately revoke access if you suspect unauthorized activity
10. Vulnerability Disclosure
We appreciate security researchers and users who help us keep MailChrono secure.
Reporting Security Issues
If you discover a security vulnerability, please report it to:
- Email: security@mailchrono.com
- Response Time: We aim to respond within 24 hours
- Disclosure: Please allow us 90 days to address the issue before public disclosure
What to Include
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any proof-of-concept code (if applicable)
11. Security Updates
We regularly update this security page to reflect our current practices. For questions about our security measures, please contact us at security@mailchrono.com.
Questions?
If you have any questions about our security practices, please don't hesitate to reach out at security@mailchrono.com.