이 문서는 법무 확인 전 초안이며 게시용이 아닙니다. This document is a draft pending legal review and is not final.

노란 표시의 "확인 필요" 항목은 게시 전에 채워야 합니다. Items marked "to be confirmed" must be completed before publication.

개인정보 처리방침

MailPip은 Gmail에서 보낸 메일의 수신자별 열람 신호를 보여 주는 Chrome 확장과 웹 서비스입니다. 이 문서는 MailPip이 어떤 정보에 접근하고, 무엇을 서버에 보관하며, 어떻게 삭제하는지 설명합니다.

버전
2026-09-28(초안)
시행일
확인 필요: 시행일

1. 운영자와 문의처

운영자
확인 필요: 운영자 명칭, 대표자, 주소
지원·개인정보 문의
확인 필요: 문의 이메일
개인정보 보호책임자
확인 필요: 성명과 연락처

안내 사이트는 https://mailpip.app 입니다. 로그인 후 쓰는 웹 앱과 API는 현재 approxup.com 아래의 주소에서 제공되며 확인 필요: 운영 이전 뒤 주소, 메일에 들어가는 추적 이미지도 approxup.com에서 제공됩니다.

2. MailPip이 하는 일

  • 사용자가 Gmail에서 보내기를 누르면 확장이 작성 중인 메일(수신자, 제목, 본문, 첨부)을 MailPip 서버에 전달하고, 서버가 사용자의 Google 권한으로 Gmail SMTP(smtp.gmail.com)를 통해 사용자를 대신해 메일을 보냅니다.
  • 수신자마다 별도 사본을 만들고, 각 사본에는 그 수신자 전용 추적 이미지(1x1 이미지)가 들어갑니다. 수신자의 메일 앱이 이 이미지를 불러오면 "열람 신호"가 기록되어 웹 앱에서 수신자별로 보입니다.
  • Gmail 비밀 모드나 수신자 50명 초과 같은 예외 상황에서는 확장이 작성 창에 추적 이미지만 넣고 Gmail이 직접 보냅니다. 이때 서버는 제목, 수신자 표시값, 추적 이미지 식별값(해시)만 받고 본문과 첨부는 받지 않습니다.

3. 접근하는 Google 사용자 데이터와 이유

MailPip은 Google 로그인 때 아래 권한을 한 번에 요청합니다. 계정 비밀번호는 받지 않습니다.

openid, email

사용 목적
로그인과 계정 확인
실제로 하는 일
Google이 확인한 이메일 주소와 계정 식별값(sub)을 받아 MailPip 계정과 연결합니다.
하지 않는 일
비밀번호를 받지 않습니다.

https://mail.google.com/ (Gmail 전체 메일)

사용 목적
사용자를 대신한 발송과 보낸편지함 보호 확인
실제로 하는 일
  • Gmail SMTP(XOAUTH2)로 발송합니다. 사용자 본인에게 가는 사본(추적 이미지 없음)을 먼저 보내 보낸편지함에 이 사본이 보관되게 하고, 이어서 수신자별 사본을 보냅니다.
  • 발송 직후, 방금 보낸 메일 하나를 Message-ID로 찾아 라벨 목록만 읽어 추적 이미지 없는 사본이 보관됐는지 확인합니다(읽기 전용, 본문과 헤더 원문은 읽지 않음). 결과(적용, 미적용, 불명) 외에 메시지 ID나 라벨은 저장하지 않습니다.
  • 숨김 라벨 "MailPip 자기 사본" 1개를 만들고, 연결 해제 때 지웁니다.
하지 않는 일
서버는 받은편지함의 메일 목록과 본문을 읽거나 분석하거나 저장하지 않습니다. 위 세 가지 외의 Gmail API 호출이 없으며, Gmail API로 메일을 만들거나 고치거나 지우지 않습니다.

https://www.googleapis.com/auth/gmail.settings.basic (Gmail 기본 설정)

사용 목적
자기 수신 사본이 받은편지함에 쌓이지 않게 하는 필터 1개 관리
실제로 하는 일
필터 1개를 만듭니다. 조건은 list:(self-copy.mailpip.approxup.com)이고 동작은 받은편지함 건너뛰기, 읽음 표시, 위 라벨 적용입니다. 필터 목록은 같은 필터가 이미 있는지 확인하는 데만 읽고 저장하지 않으며, 연결 해제와 계정 삭제 때 이 필터를 지웁니다.
하지 않는 일
다른 필터와 설정(전달, 부재중 응답, 서명 등)을 읽어 저장하거나 바꾸지 않습니다. 이 권한을 허용하지 않아도 연결은 되며 필터만 만들어지지 않습니다.

확장이 Gmail 화면에서 MailPip 서버로 보내는 정보는 사용자가 보내려는 메일의 발신 주소, 수신자, 제목, 본문, 첨부, 시간대 오프셋, 요청 식별값, 답장이나 전달일 때 원본 메시지의 Message-ID와 References 헤더 값뿐입니다. 서버는 정해진 항목 외의 입력을 거절합니다.

4. 서버에 보관하는 정보와 기간

보관 항목, 목적, 기간
정보목적보관 방식과 기간
Google 계정 식별값(sub), 확인된 이메일, 약관 동의 버전과 시각 계정 식별, 약관 동의 기록 계정을 삭제할 때까지 보관하고, 삭제하면 지웁니다.
Gmail 접근용 refresh token 사용자를 대신한 발송 AES-256-GCM으로 암호화해 저장합니다. 연결 해제나 계정 삭제 때 지우고 Google에 폐기를 요청하며, Google이 권한을 철회한 것이 확인되면 암호문을 비웁니다. access token은 저장하지 않습니다.
작성 원문(본문, 인라인 이미지)과 첨부 발송 완료까지의 임시 보관 객체마다 다른 키로 암호화한 임시 보관소에 둡니다. 발송이 끝나면 곧바로 지웁니다. 발송에 쓰이지 않은 업로드는 마지막 사용 15분 뒤(최대 24시간)에, 발송 접수 뒤 멈춘 작업의 원문은 1시간 안에 지우며, 내용이 없는 삭제 기록은 24시간 뒤 지웁니다.
메시지 정보(제목, 수신자 주소와 역할, 발신 주소, 보낸 시각, 발송 상태, 원문 SHA-256) 보낸 메일 목록과 열람 신호 표시 계정을 삭제할 때까지 보관합니다. 본문과 첨부 원문은 포함하지 않습니다. 자동 삭제 기한은 아직 정하지 않았습니다 확인 필요: 자동 보관·정리 범위.
열람 신호 기록(수신자별 식별값, 신호 시각, 요청 출처 분류값) 수신자별 열람 신호 표시 추적 이미지는 발급 후 7일이 지나면 더 이상 신호를 기록하지 않습니다. 기록은 계정을 삭제할 때까지 보관합니다. MailPip 수집기는 수신자의 IP 주소와 User-Agent를 출처 분류 계산에만 쓰고 저장하거나 로그에 남기지 않습니다.
계정, 세션, 확장 연결 정보 로그인 유지와 확장 연결 비밀값은 원문 없이 해시만 저장합니다. 웹 세션은 최대 8시간, 확장 인증값은 한 세대 30일(24시간마다 회전하며 쓰지 않으면 만료), 확장 연결용 1회용 코드는 120초, 로그인 진행 기록은 10분 동안 유효합니다. 만료된 기록의 자동 정리 범위는 정하는 중입니다 확인 필요: 자동 보관·정리 범위.
서버 로그 장애 대응 API는 접근 로그를 남기지 않고, 수집기와 API의 오류 로그는 고정 문구만 남깁니다(주소, 제목, 본문, 토큰 없음). 호스팅 제공자와 네트워크 계층의 연결 로그는 확인 필요: 보관 여부와 기간.

5. 쿠키와 브라우저 저장소

  • 이 안내 사이트(mailpip.app)는 쿠키를 설정하지 않고 분석이나 광고 스크립트를 쓰지 않습니다.
  • 웹 앱은 로그인 유지용 쿠키 __Host-MailPip(HttpOnly, Secure, SameSite=Strict, 최대 8시간)과 Google 로그인 진행 중에만 쓰는 __Host-MailPip-OAuth(10분)만 씁니다. 광고와 분석 쿠키는 없습니다.
  • 확장은 Chrome 확장 저장소(chrome.storage)에 Gmail 계정별 연결 기록과 인증값을 저장합니다. Chrome 동기화를 켠 경우 Chrome이 이 기록을 사용자의 다른 Chrome 기기로 동기화할 수 있습니다.

6. Google 사용자 데이터 정책(Limited Use)

MailPip's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

위 문장은 Google이 요구하는 영문 고지 문구입니다. 출처는 Google의 restricted scope 검증 안내와 위 정책 문서이며 확인 필요: 게시 전 현행 공식 문구와 글자 대조.

MailPip은 Google 사용자 데이터를 사용자에게 보이는 기능(발송, 열람 신호 표시, 보호 확인)을 제공하고 개선하는 데만 쓰며, 광고 게재나 광고 분석에 쓰지 않고, 일반 AI/ML 모델의 개발이나 학습에 쓰지 않으며, 판매하지 않습니다.

7. 제3자 제공, 위탁, 판매, 광고

  • 사용자 데이터를 판매하지 않고, 데이터 중개업체에 제공하지 않으며, 광고에 쓰지 않습니다.
  • 서비스 운영에 필요한 인프라는 다음 업체를 씁니다. 호스팅은 Railway, 첨부 임시 보관은 Railway Buckets, 도메인 등록과 DNS는 Cloudflare입니다. 호스팅과 첨부 보관은 운영 이전 계획에 따른 것이며 확정 전입니다 확인 필요: 이전 확정과 서버 위치.
  • 그 밖의 제3자에게는 사용자의 동의가 있거나 법령에 따른 요구가 있는 경우에만 제공합니다. 메일 자체는 사용자의 요청에 따라 Gmail과 수신자의 메일 서비스를 거쳐 전달됩니다.

8. 사람이 데이터를 읽는 경우

MailPip 운영자는 다음 경우를 빼고 Google 사용자 데이터(메일 내용, 수신자, 제목 등)를 사람이 읽지 않습니다. 첫째 사용자가 구체적으로 요청하거나 동의한 경우, 둘째 악용 조사 등 보안상 필요한 경우, 셋째 법령을 지키기 위해 필요한 경우, 넷째 개인을 알아볼 수 없게 집계하거나 익명화해 서비스 운영에 쓰는 경우입니다. 이 약속을 뒷받침하는 내부 접근 절차는 확인 필요: 운영 절차.

9. 보안 조치

  • Google API와 SMTP 연결은 TLS로 하며 인증서와 호스트 이름을 검증합니다.
  • 저장된 refresh token과 첨부·작성 원문 임시 보관소는 AES-256-GCM으로 암호화합니다.
  • 세션, 확장 인증값, 1회용 코드 같은 비밀값은 원문 없이 해시만 저장합니다.
  • Google 로그인은 PKCE, state, nonce와 ID 토큰 검증을 거칩니다.

10. 수신자 안내

MailPip 사용자가 보낸 메일에는 수신자 전용 추적 이미지가 들어 있을 수 있습니다. 메일 앱이 이 이미지를 불러오면 approxup.com 서버가 요청이 왔다는 사실과 시각을 기록합니다. MailPip은 수신자의 IP 주소와 브라우저 정보를 저장하지 않습니다(호스팅 계층의 연결 로그는 4절의 서버 로그 항목을 참고하십시오). 이 요청이 사람의 열람인지 메일 앱이나 보안 검사의 자동 요청인지는 확정할 수 없어 "열람 신호"로만 표시합니다. 메일 앱에서 원격 이미지 불러오기를 끄면 이 신호가 생기지 않습니다. 문의는 확인 필요: 문의 이메일로 받습니다.

11. 삭제, 연결 해제, 권리 행사

  • Gmail 연결 해제. 웹 앱의 발신자 연결 화면에서 해제하면 MailPip 서버의 refresh token 암호문을 먼저 지우고, 이어서 Gmail 필터와 라벨을 차례로 지운 뒤 refresh token의 폐기를 Google에 요청합니다. Google 쪽 정리는 실패하더라도 해제는 되돌려지지 않습니다.
  • 계정 삭제. 웹 앱의 "계정 삭제"는 MailPip 계정, 키와 세션, 확장 연결, Google 계정 연결, 연결된 Gmail 권한(필터와 라벨 정리, 토큰 폐기 포함), 추적 기록을 삭제하며 되돌릴 수 없습니다. Google 쪽 정리가 일부 실패하면 웹 앱이 알려 주고 Google 계정 설정에서 직접 확인하도록 안내합니다.
  • 보내는 중인 메일이 있으면 발송 취소를 요청하고 끝난 뒤 삭제를 마칩니다. 열람 신호 기록은 별도 정리 작업으로 지워지며 확인 필요: 정리 작업 주기.
  • Google 계정에서 직접 철회. Google 계정 설정의 "서드파티 앱 및 서비스"에서 MailPip의 접근 권한을 삭제할 수 있습니다. 이 경우 MailPip은 다음 발송 때 권한이 없음을 확인하고 저장된 refresh token 암호문을 비우며, 웹 앱이 다시 연결하도록 안내합니다.
  • 확장 제거. 확장을 제거하면 안내 페이지가 열립니다. 서버의 확장 인증값은 쓰지 않으면 30일 안에 만료됩니다. 데이터까지 지우려면 웹 앱에서 계정을 삭제하십시오.
  • 열람, 정정, 삭제, 처리정지 요청. 확인 필요: 문의 이메일로 요청할 수 있습니다.

13. 방침 변경

방침을 바꾸면 이 페이지의 버전과 시행일을 바꾸고, 웹 앱이 동의를 받을 때 기록하는 약관 버전과 맞춥니다.

Privacy Policy

MailPip is a Chrome extension and web service that shows per-recipient open signals for emails you send from Gmail. This document explains which information MailPip accesses, what it keeps on its servers, and how you can delete it.

Version
2026-09-28 (draft)
Effective date
To be confirmed: effective date

1. Operator and contact

Operator
To be confirmed: operator name, representative, address
Support and privacy contact
To be confirmed: contact email
Privacy officer
To be confirmed: name and contact

The information site is https://mailpip.app. The signed-in web app and API are currently served from a subdomain of approxup.com To be confirmed: address after the production move, and the tracking image inside emails is also served from approxup.com.

2. What MailPip does

  • When you click Send in Gmail, the extension passes the message you are writing (recipients, subject, body, attachments) to the MailPip server, and the server sends it on your behalf through Gmail SMTP (smtp.gmail.com) using your Google authorization.
  • MailPip creates a separate copy for each recipient, and each copy contains a tracking image (1x1) unique to that recipient. When the recipient's mail app loads the image, an "open signal" is recorded and shown per recipient in the web app.
  • In exceptional cases such as Gmail confidential mode or more than 50 recipients, the extension only inserts a tracking image into the compose window and Gmail sends the message itself. In that case the server receives only the subject, the recipient display value and a hashed tracking-image identifier, and does not receive the body or attachments.

3. Google user data we access, and why

MailPip requests the permissions below together when you sign in with Google. It never receives your account password.

openid, email

Purpose
Sign-in and account identification
What MailPip does
Receives your Google-verified email address and account identifier (sub) and links them to your MailPip account.
What MailPip does not do
Does not receive your password.

https://mail.google.com/ (full Gmail access)

Purpose
Sending on your behalf and checking Sent-folder protection
What MailPip does
  • Sends through Gmail SMTP (XOAUTH2). It first sends a copy addressed only to you (without a tracking image) so that this copy is the one kept in your Sent folder, then sends the per-recipient copies.
  • Right after sending, it finds the one message it just sent by Message-ID and reads only its label list to confirm that the copy without a tracking image was kept (read-only, without reading the body or raw headers). It stores only the result (applied, not applied, unknown), not message IDs or labels.
  • Creates one hidden label named "MailPip 자기 사본" and deletes it when you disconnect.
What MailPip does not do
The server does not read, analyze or store the message list or message contents of your inbox. There are no Gmail API calls other than these three, and MailPip does not create, edit or delete messages through the Gmail API.

https://www.googleapis.com/auth/gmail.settings.basic (Gmail basic settings)

Purpose
Managing one filter that keeps self-addressed copies out of your inbox
What MailPip does
Creates one filter. The criteria is list:(self-copy.mailpip.approxup.com), and the actions are skip the inbox, mark as read and apply the label above. MailPip reads the filter list only to check whether its own filter already exists and does not store it, and deletes the filter when you disconnect or delete your account.
What MailPip does not do
Does not read, store or change any other filter or setting (forwarding, vacation responder, signature and so on). If you do not grant this permission, the connection still works and only the filter is not created.

The only information the extension sends from the Gmail page to the MailPip server is the sender address, recipients, subject, body and attachments of the message you are sending, your time zone offset, request identifiers, and, for replies and forwards, the Message-ID and References header values of the original message. The server rejects any other input.

4. What we keep on our servers, and for how long

Stored items, purpose and retention
InformationPurposeHow it is kept, and for how long
Google account identifier (sub), verified email, terms version and acceptance time Account identification and a record of terms acceptance Kept until you delete your account, then deleted.
Refresh token for Gmail access Sending on your behalf Stored encrypted with AES-256-GCM. Deleted, and revocation requested from Google, when you disconnect or delete your account. If Google reports that you have withdrawn the permission, the ciphertext is cleared. Access tokens are not stored.
Message content as composed (body, inline images) and attachments Temporary holding until sending finishes Held in a temporary store encrypted with a different key per object. Deleted immediately once sending finishes. Uploads that are not used for sending are deleted 15 minutes after last use (24 hours at most), content of a job that stalls after being accepted is deleted within 1 hour, and the content-free deletion record is removed after 24 hours.
Message information (subject, recipient addresses and roles, sender address, send time, send status, SHA-256 of the original) Showing your sent-mail list and open signals Kept until you delete your account. It does not include the body or attachment content. No automatic deletion period has been set yet To be confirmed: automatic retention and cleanup scope.
Open signal records (per-recipient identifier, signal time, request-source classification) Showing per-recipient open signals A tracking image stops recording signals 7 days after it is issued. Records are kept until you delete your account. The MailPip collector uses the recipient's IP address and User-Agent only to compute the classification and neither stores nor logs them.
Account, session and extension connection data Keeping you signed in and connecting the extension Secret values are stored only as hashes, never as the original. A web session is valid for at most 8 hours, an extension credential generation for 30 days (rotated every 24 hours and expiring if unused), the one-time extension link code for 120 seconds, and a sign-in attempt record for 10 minutes. The scope of automatic cleanup of expired records is still being decided To be confirmed: automatic retention and cleanup scope.
Server logs Troubleshooting The API keeps no access log, and error logs from the collector and API contain only fixed messages (no addresses, subjects, bodies or tokens). Connection logs kept by the hosting provider and network layer: To be confirmed: whether they are kept and for how long.

5. Cookies and browser storage

  • This information site (mailpip.app) sets no cookies and uses no analytics or advertising scripts.
  • The web app uses only the sign-in cookie __Host-MailPip (HttpOnly, Secure, SameSite=Strict, up to 8 hours) and __Host-MailPip-OAuth (10 minutes), which is used only while Google sign-in is in progress. There are no advertising or analytics cookies.
  • The extension stores a per-Gmail-account connection record and credential in Chrome extension storage (chrome.storage). If Chrome Sync is on, Chrome may sync this record to your other Chrome devices.

6. Google user data policy (Limited Use)

MailPip's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

This is the disclosure statement Google requires. Sources are Google's restricted scope verification guidance and the policy above. To be confirmed: compare word for word with the current official text before publication.

MailPip uses Google user data only to provide and improve the user-facing features (sending, showing open signals, protection checks). It does not use it for serving or analyzing advertisements, does not use it to develop or train generalized AI or ML models, and does not sell it.

7. Sharing, processors, sale, advertising

  • MailPip does not sell user data, does not provide it to data brokers, and does not use it for advertising.
  • The infrastructure used to run the service is provided by the following companies. Hosting is Railway, temporary attachment storage is Railway Buckets, and domain registration and DNS is Cloudflare. Hosting and attachment storage follow the planned production move and are not yet final To be confirmed: move and server location.
  • MailPip provides data to any other third party only with your consent or when required by law. The email itself travels through Gmail and the recipient's mail service at your request.

8. When people read data

MailPip operators do not read Google user data (message content, recipients, subjects and so on) except in these cases. First, when you specifically ask or consent. Second, when necessary for security, such as investigating abuse. Third, when necessary to comply with law. Fourth, when the data is aggregated or anonymized so that no individual can be identified and used to operate the service. The internal access procedure that backs this commitment is To be confirmed: operating procedure.

9. Security measures

  • Connections to Google APIs and SMTP use TLS with certificate and host name verification.
  • The stored refresh token and the temporary store for message content and attachments are encrypted with AES-256-GCM.
  • Secret values such as sessions, extension credentials and one-time codes are stored only as hashes, never as the original.
  • Google sign-in uses PKCE, state, nonce and ID token verification.

10. Notice for email recipients

Emails sent by MailPip users may contain a tracking image unique to each recipient. When a mail app loads this image, the approxup.com server records that a request arrived and when. MailPip does not store the recipient's IP address or browser information (see the server logs row in section 4 for connection logs kept at the hosting layer). It cannot tell whether a request is a person opening the email or an automatic request from a mail app or security scan, so it shows only an "open signal". If you turn off loading of remote images in your mail app, no such signal is generated. Questions can be sent to To be confirmed: contact email.

11. Deletion, disconnecting, your rights

  • Disconnect Gmail. Disconnecting on the sender connection screen of the web app first deletes the refresh token ciphertext on the MailPip server, then deletes the Gmail filter and the label in that order, and then asks Google to revoke the refresh token. The disconnection is not undone if part of the Google-side cleanup fails.
  • Delete your account. "Delete account" in the web app deletes your MailPip account, keys and sessions, extension connections, the link to your Google account, the connected Gmail authorization (including filter and label cleanup and token revocation) and your tracking records. It cannot be undone. If part of the Google-side cleanup fails, the web app tells you and asks you to check in your Google Account settings.
  • If a message is being sent, MailPip requests that the send be cancelled and finishes the deletion afterwards. Open signal records are removed by a separate cleanup job To be confirmed: cleanup job schedule.
  • Withdraw from your Google Account. You can remove MailPip's access under "Third-party apps and services" in your Google Account settings. After that, MailPip finds out at the next send that the permission is gone, clears the stored refresh token ciphertext, and the web app asks you to reconnect.
  • Uninstall the extension. Removing the extension opens a goodbye page. Extension credentials on the server expire within 30 days if unused. To delete your data as well, delete your account in the web app.
  • Access, correction, deletion and suspension requests. You can make them at To be confirmed: contact email.

13. Changes to this policy

When this policy changes, the version and effective date on this page change too and are matched to the terms version the web app records when it asks for your consent.