Untangle

Your Data

This is a plain-language description of exactly what this system does today, written from the actual code — not a substitute for our Privacy Policy.

What we collect

When you run a scan: only the aggregated result per sender — the sending domain, a display name, how many emails they sent you, our best-guess category, the most recent date we saw, and an unsubscribe link (marked honestly as confirmed or guessed).

What we never see or store

Your .mbox file itself, full email bodies, attachments, and the individual addresses of people who emailed you (beyond the domain they emailed from) are never stored, and never leave your browser in the first place. If you use the app-password scan option, the app password itself is never stored either — it exists in server memory only for the length of that one connection, then is discarded.

How scanning actually works

There are two ways to scan, and they work differently. Uploading a Gmail export (from Google Takeout) is read and parsed entirely client-side, in your browser, using the File API — the raw file is never sent to any server. Connecting with a one-time app password instead has our server log in to your inbox over IMAP once, read only message headers (sender, subject, date, unsubscribe headers — never email bodies), then disconnect. Either way, only the small aggregated summary above is saved, and only if you're signed in.

Who else touches your data

Clerk handles authentication (sign-up, sign-in, sessions) — we never see or store your password. Convex stores the aggregated scan data described above. Neither is used to sell or share your data for advertising.

Your controls

You can permanently delete every saved scan (and any earlier waitlist signup, for early users) at any time, right here.

This deletes your Untangle data, not your sign-in account itself. To close your account entirely, use Clerk's account settings.

Contact

support@untangleinbox.com

Legal documents

Read the full Terms of Service.