이 문서는 법무 확인 전 초안이며 게시용이 아닙니다. This document is a draft pending legal review and is not final.

노란 표시의 "확인 필요" 항목은 게시 전에 채워야 합니다. Items marked "to be confirmed" must be completed before publication.

개인정보 및 보안 센터

MailPip이 어떤 정보에 접근하고, 무엇을 어디에 보관하며, 어떻게 지우는지를 자주 받는 질문으로 정리했습니다. 이 페이지는 지금 코드와 방침이 실제로 하는 일을 적은 것이며, 자세한 내용은 개인정보 처리방침에 있습니다.

버전
2026-09-28(초안)
시행일
확인 필요: 시행일

MailPip 직원이 제 메일 내용을 볼 수 있나요?

  • 메일 본문과 첨부는 발송이 끝나면 서버에 남지 않습니다. 발송 중에는 객체마다 다른 키로 암호화한 임시 보관소에 두며, 발송에 쓰이지 않은 업로드는 마지막 사용 15분 뒤(최대 24시간)에 지웁니다.
  • 서버는 받은편지함의 메일 목록과 본문을 읽거나 분석하거나 저장하지 않습니다.
  • 사람이 Google 사용자 데이터를 읽는 경우는 네 가지뿐입니다. 사용자의 명시적 동의가 있는 경우, 버그나 악용 조사 같은 보안 목적에 필요한 경우, 법령을 지키기 위해 필요한 경우, 관련 법에 따라 집계하거나 익명화한 데이터를 서비스 내부 운영에 쓰는 경우입니다.
  • 운영 데이터에 접근하는 사람은 운영자 본인으로 한정하고, 접근할 때마다 날짜, 사유, 범위를 기록해 1년 보관합니다.

왜 MailPip이 Gmail 권한을 필요로 하나요?

MailPip은 Google 로그인 때 아래 권한을 한 번에 요청합니다. 계정 비밀번호는 받지 않습니다.

  • 로그인과 계정 확인 (openid, email). Google이 확인한 이메일 주소와 계정 식별값을 MailPip 계정과 연결합니다.
  • 사용자를 대신한 발송 (Gmail 전체 메일 권한). 받는 사람이 둘 이상이면 MailPip 서버가 사용자의 Gmail로 수신자별 사본을 보내고, 사용자 본인에게 가는 사본을 먼저 보내 보낸편지함에 남깁니다. 같은 권한으로 보낸편지함 보호를 확인하고 숨김 라벨 1개를 관리합니다.
  • 자기 수신 사본 정리 (Gmail 기본 설정 권한). 자기 수신 사본이 받은편지함에 쌓이지 않게 하는 필터 1개만 만들고 지웁니다. 이 권한을 허용하지 않아도 연결은 되며 필터만 만들어지지 않습니다.

이 권한이 있어도 서버는 받은편지함의 메일을 읽지 않고, Gmail API로 메일을 만들거나 고치거나 지우지 않습니다. 권한마다 무엇을 하고 하지 않는지는 개인정보 처리방침 3절에 있습니다.

MailPip은 제 데이터를 판매하나요?

  • 아니요. 사용자 데이터를 판매하지 않고, 데이터 중개업체에 제공하지 않으며, 광고에 쓰지 않습니다. 일반 AI/ML 모델의 개발이나 학습에도 쓰지 않습니다.
  • Google API로 받은 정보는 사용자에게 보이는 기능(발송, 열람 신호 표시, 보호 확인)을 제공하고 개선하는 데만 씁니다. Limited Use 고지의 원문은 개인정보 처리방침 6절에 있습니다.

내 데이터는 어디에, 어떻게 보관되나요?

  • 서비스를 운영하는 호스팅은 Railway(Railway Corporation, 미국 회사)이며 서버는 Southeast Asia(싱가포르) 리전에 있습니다. Cloudflare는 mailpip.app의 도메인 등록과 mailpip.app·approxup.com의 DNS만 맡습니다.
  • MailPip 서버가 대한민국 밖에 있어 국외 이전 고지를 개인정보 처리방침에 표로 두었습니다. 개인정보 처리방침 12절 확인 필요: 법무 검토(국외 이전 고지)
  • 저장하는 refresh token은 AES-256-GCM으로 암호화하고, 세션과 확장 인증값 같은 비밀값은 원문 없이 해시만 저장합니다. Google API와 SMTP 연결은 TLS로 하며 인증서와 호스트 이름을 검증합니다.
  • 무엇을 얼마나 보관하는지는 개인정보 처리방침 4절의 표에 항목별 목적과 기간으로 있습니다.

Gmail 연결 해제, 계정 삭제, 데이터 삭제는 어떻게 하나요?

  • Gmail 연결 해제. 웹 앱의 발신자 연결에서 해제하면 서버의 refresh token 암호문을 먼저 지우고, 이어서 Gmail 필터와 라벨을 지운 뒤 토큰의 폐기를 Google에 요청합니다.
  • 계정 삭제. 웹 앱의 설정 및 계정에서 계정을 삭제하면 계정, 키와 세션, 확장 연결, Google 계정 연결, Gmail 권한, 메시지 정보를 바로 지우며 되돌릴 수 없습니다.
  • 메일 하나의 데이터 삭제. 이메일 추적에서 메일 줄 끝의 ⋯ 메뉴로 "이메일 데이터 삭제"를 고르면 그 메일의 추적 기록을 지웁니다. Gmail에 있는 메일은 지워지지 않습니다.
  • 내 데이터 내려받기. 설정 및 계정의 개인정보 구역에서 보낸 모든 이메일의 제목, 발송 시각, 수신자, 열람 신호 수, 마지막 신호를 CSV로 내려받을 수 있습니다.
  • Google 계정에서 직접 철회. Google 계정 설정의 "서드파티 앱 및 서비스"에서 MailPip의 접근 권한을 삭제할 수 있습니다.
  • 확장 제거. 확장을 제거하면 Gmail에서 새 메일의 추적이 켜지지 않습니다. 데이터까지 지우려면 웹 앱에서 계정을 삭제하십시오.

자세한 순서와 삭제 범위는 개인정보 처리방침 11절에 있습니다.

메일을 받은 사람은 어떻게 요청하나요?

  • MailPip은 수신자 데이터(수신자 주소, 제목, 발송 시각, 열람 신호)를 메일을 보낸 사용자를 대신해 처리하는 수탁자입니다. 처리 목적과 수신자는 보낸 사용자가 정합니다.
  • 그래서 열람, 삭제 같은 요청은 먼저 메일을 보낸 사람에게 하십시오. support@mailpip.app으로 받은 요청은 MailPip이 보낸 사용자에게 전달하고 처리를 돕습니다.
  • 보낸 사용자는 웹 앱에서 메일 하나의 데이터를 삭제할 수 있습니다.
  • 메일 앱에서 원격 이미지 불러오기를 끄면 열람 신호가 생기지 않습니다. 수신자에게 알리는 내용은 개인정보 처리방침 10절에 있습니다.
  • 보낸 사용자를 거치지 않고 MailPip에 직접 삭제를 요구할 때 MailPip이 직접 처리하는 범위와 기한은 확인 필요: 처리 범위와 기한.

보안 문제는 어디에 신고하나요?

보안 취약점이나 개인정보 침해, 서비스 악용을 발견하면 support@mailpip.app으로 알려 주십시오. 받은 신고는 확인하고 필요한 조치를 합니다. 신고할 때 지켜 주실 점과 선의의 신고자 보호 범위는 이용약관의 책임 있는 보안 취약점 신고에 있습니다.

Privacy and Security Center

Answers to frequently asked questions on which information MailPip accesses, what it keeps and where, and how it is deleted. This page describes what the code and the policy do today, and the details are in the Privacy Policy.

Version
2026-09-28 (draft)
Effective date
To be confirmed: effective date

Can MailPip staff see the content of my email?

  • Message bodies and attachments do not remain on the server once sending finishes. While sending, they are held in a temporary store encrypted with a different key per object, and uploads that are not used for sending are deleted 15 minutes after last use (24 hours at most).
  • The server does not read, analyze or store the message list or message contents of your inbox.
  • People read Google user data in only four cases. When you give explicit consent, when necessary for security purposes such as investigating bugs or abuse, when necessary to comply with law, and when data aggregated or anonymized in accordance with applicable law is used for internal operations of the service.
  • Only the operator personally has access to operating data, and every access is recorded with its date, reason and scope and kept for 1 year.

Why does MailPip need Gmail permissions?

MailPip requests the permissions below together when you sign in with Google. It never receives your account password.

  • Sign-in and account identification (openid, email). Your Google-verified email address and account identifier are linked to your MailPip account.
  • Sending on your behalf (full Gmail access). With two or more recipients, the MailPip server sends a separate copy per recipient through your Gmail, and first sends a copy addressed only to you so that it stays in your Sent folder. The same permission is used to check Sent-folder protection and to manage one hidden label.
  • Keeping self-addressed copies out of the inbox (Gmail basic settings). It creates and deletes only one filter. If you do not grant this permission, the connection still works and only the filter is not created.

Even with these permissions, the server does not read the messages in your inbox, and it does not create, edit or delete messages through the Gmail API. What each permission does and does not do is in section 3 of the Privacy Policy.

Does MailPip sell my data?

  • No. MailPip does not sell user data, does not provide it to data brokers, and does not use it for advertising. It does not use it to develop or train generalized AI or ML models either.
  • Information received from Google APIs is used only to provide and improve the user-facing features (sending, showing open signals, protection checks). The Limited Use disclosures, quoted word for word, are in section 6 of the Privacy Policy.

Where and how is my data kept?

  • The infrastructure that runs the service is hosted by Railway (Railway Corporation, a US company), and the server is in the Southeast Asia (Singapore) region. Cloudflare provides domain registration for mailpip.app and DNS for mailpip.app and approxup.com only.
  • The MailPip server is located outside the Republic of Korea, so the international transfer notice is given as a table in the Privacy Policy. Section 12 of the Privacy Policy To be confirmed: legal review (international transfer notice)
  • The stored refresh token is encrypted with AES-256-GCM, and secret values such as sessions and extension credentials are stored only as hashes, never as the original. Connections to Google APIs and SMTP use TLS with certificate and host name verification.
  • What is kept and for how long is listed item by item, with purpose and period, in the table in section 4 of the Privacy Policy.

How do I disconnect Gmail, delete my account or delete data?

  • Disconnect Gmail. Disconnecting on the sender connection screen of the web app first deletes the refresh token ciphertext on the server, then deletes the Gmail filter and label, and then asks Google to revoke the token.
  • Delete your account. Deleting your account in Settings and account of the web app immediately deletes your account, keys and sessions, extension connections, the link to your Google account, the Gmail authorization and your message information. It cannot be undone.
  • Delete the data of one email. In Email tracking, choose "Delete email data" from the ⋯ menu at the end of the email's row to delete that email's tracking record. The email in Gmail is not deleted.
  • Download your data. In the privacy section of Settings and account you can download the subject, send time, recipients, number of open signals and last signal of all your sent emails as CSV.
  • Withdraw from your Google Account. You can remove MailPip's access under "Third-party apps and services" in your Google Account settings.
  • Uninstall the extension. If you remove the extension, tracking is no longer turned on for new emails in Gmail. To delete your data as well, delete your account in the web app.

The exact order and the scope of deletion are in section 11 of the Privacy Policy.

How does someone who received an email make a request?

  • MailPip is the processor that handles recipient data (recipient address, subject, send time, open signals) on behalf of the user who sent the email. The purpose of the processing and the recipients are decided by the sending user.
  • So please first ask the person who sent you the email for access, deletion and similar requests. A request received at support@mailpip.app is forwarded by MailPip to the sending user, and MailPip helps with handling it.
  • The sending user can delete the data of one email in the web app.
  • If you turn off loading of remote images in your mail app, no open signal is generated. What recipients are told is in section 10 of the Privacy Policy.
  • The scope and time limit of what MailPip handles directly when someone asks it to delete data without going through the sending user is To be confirmed: scope and time limit.

Where do I report a security issue?

If you find a security vulnerability, a privacy violation or abuse of the service, please tell us at support@mailpip.app. We review the reports we receive and take the actions that are needed. What we ask of a reporter and the scope of protection for good-faith reporters are in responsible vulnerability disclosure in the Terms of Service.