쿠키 정책
MailPip의 공개 페이지는 쿠키를 쓰지 않고, 로그인 후 쓰는 웹 앱은 쿠키 두 개만 씁니다. 이 문서는 쓰는 것과 쓰지 않는 것을 이름과 기간까지 알려 드립니다.
1. 쿠키란 무엇인가요
쿠키는 웹사이트가 사용자의 브라우저에 남기는 작은 글자 정보입니다. 로그인 상태를 기억하는 데 흔히 쓰입니다. 이 문서는 쿠키와 비슷하게 브라우저에 정보를 남기는 기능도 함께 구분해 설명합니다.
2. 공개 페이지
- 이 안내 사이트의 페이지(홈, 개인정보 처리방침, 이용약관, 쿠키 정책, 개인정보 및 보안 센터)는 쿠키를 설정하지 않고 분석이나 광고 스크립트를 쓰지 않습니다. 쿠키 동의를 묻는 창이 없는 이유입니다.
3. 웹 앱이 쓰는 쿠키
로그인 후 쓰는 웹 앱은 아래 쿠키 두 개만 씁니다. 둘 다 JavaScript가 읽지 못하는 HttpOnly 쿠키이고 암호화된 연결(Secure)로만 전송됩니다.
| 이름 | 목적 | 속성 | 기간 |
|---|---|---|---|
__Host-MailPip |
로그인 유지(웹 세션) | HttpOnly, Secure, SameSite=Strict | 최대 8시간. 로그아웃하면 서버가 이 쿠키를 지우라고 응답합니다. |
__Host-MailPip-OAuth |
Google 로그인이 진행되는 동안 요청이 같은 로그인에서 온 것인지 확인(state 값) | HttpOnly, Secure, SameSite=Lax | 10분. Google에서 돌아와 로그인 절차가 끝나면 서버가 이 쿠키를 지우라고 응답합니다. |
이름의 __Host- 접두어는 브라우저가 Secure 전송, 경로 /, 도메인 속성 없음을 요구하는 형식입니다. 두 쿠키는 로그인에 필요한 것이라 브라우저가 이를 막으면 웹 앱에 로그인할 수 없습니다.
4. 쿠키가 아닌 브라우저 저장소
- 웹 앱이 요청을 확인하려고 쓰는 CSRF 방지 값은 쿠키가 아니라 요청 헤더(
X-CSRF-Token)로 보내며, 화면이 열려 있는 동안 메모리에만 둡니다. 웹 앱은localStorage,sessionStorage,IndexedDB를 쓰지 않습니다. - Chrome 확장은 Chrome 확장 저장소(
chrome.storage)에 Gmail 계정별 연결 기록과 인증값을 저장합니다. 쿠키가 아니며, Chrome 동기화를 켠 경우 Chrome이 이 기록을 사용자의 다른 Chrome 기기로 동기화할 수 있습니다. - 확장은 쿠키 권한을 요청하지 않고 코드에도 쿠키를 읽거나 쓰는 부분이 없습니다.
5. 쓰지 않는 것
- 광고 쿠키, 분석(통계) 쿠키, 제3자 쿠키를 쓰지 않습니다.
- 메일에 들어가는 추적 이미지를 내려주는 서버도 수신자의 브라우저나 메일 앱에 쿠키를 설정하지 않습니다. 수신자에게 알리는 내용은 개인정보 처리방침 10절에 있습니다.
6. 쿠키를 지우는 방법
- 웹 앱에서 로그아웃하거나 계정을 삭제하면 서버가
__Host-MailPip쿠키를 지우라고 응답합니다. - 브라우저 설정의 쿠키 또는 사이트 데이터 메뉴에서 mailpip.app의 쿠키를 직접 지울 수도 있습니다. 메뉴 이름과 위치는 브라우저마다 다릅니다.
- 쿠키를 지우면 웹 앱에서 로그아웃됩니다. 계정과 보낸 메일의 기록은 남으며, 그것을 지우는 방법은 개인정보 처리방침 11절에 있습니다.
7. 변경과 문의
쓰는 쿠키가 바뀌면 이 페이지의 버전과 시행일을 바꿉니다. 문의는 support@mailpip.app으로 받습니다. 개인정보 처리 전반은 개인정보 처리방침을 보십시오.
Cookie Policy
MailPip's public pages use no cookies, and the web app you use after signing in uses only two. This document tells you what is used and what is not, down to the names and lifetimes.
1. What is a cookie
A cookie is a small piece of text that a website leaves in your browser. It is commonly used to remember that you are signed in. This document also separates out features that keep information in the browser in a similar way.
2. The public pages
- The pages of this information site (home, privacy policy, terms, cookie policy, privacy and security center) set no cookies and use no analytics or advertising scripts. That is why there is no window asking for cookie consent.
3. Cookies used by the web app
The web app you use after signing in uses only the two cookies below. Both are HttpOnly cookies that JavaScript cannot read, and both are sent only over an encrypted connection (Secure).
| Name | Purpose | Attributes | Lifetime |
|---|---|---|---|
__Host-MailPip |
Keeping you signed in (web session) | HttpOnly, Secure, SameSite=Strict | Up to 8 hours. When you sign out, the server responds by asking the browser to delete this cookie. |
__Host-MailPip-OAuth |
While Google sign-in is in progress, confirming that the request comes from the same sign-in (the state value) | HttpOnly, Secure, SameSite=Lax | 10 minutes. When you return from Google and the sign-in step ends, the server responds by asking the browser to delete this cookie. |
The __Host- prefix in the names is a form that browsers accept only with Secure transfer, the path / and no domain attribute. Both cookies are needed to sign in, so if your browser blocks them you cannot sign in to the web app.
4. Browser storage that is not a cookie
- The CSRF protection value that the web app uses to check requests is sent in a request header (
X-CSRF-Token), not in a cookie, and it is kept only in memory while the page is open. The web app does not uselocalStorage,sessionStorageorIndexedDB. - The Chrome extension stores a per-Gmail-account connection record and credential in Chrome extension storage (
chrome.storage). It is not a cookie, and if Chrome Sync is on, Chrome may sync this record to your other Chrome devices. - The extension does not request the cookies permission, and its code has no part that reads or writes cookies.
5. What we do not use
- No advertising cookies, no analytics (statistics) cookies and no third-party cookies.
- The server that serves the tracking image inside emails does not set a cookie in the recipient's browser or mail app either. What recipients are told is in section 10 of the Privacy Policy.
6. How to delete cookies
- When you sign out of the web app or delete your account, the server responds by asking the browser to delete the
__Host-MailPipcookie. - You can also delete the cookies of mailpip.app yourself in the cookie or site data menu of your browser settings. The name and location of that menu differ by browser.
- Deleting the cookies signs you out of the web app. Your account and the records of sent emails stay, and how to delete them is in section 11 of the Privacy Policy.
7. Changes and contact
If the cookies we use change, the version and effective date on this page change too. Questions can be sent to support@mailpip.app. For personal information handling in general, see the Privacy Policy.