Français · English
Privacy Policy — Inkletter.app
Last updated: August 2026
Who we are
Inkletter.app is an Android newsletter reader designed for E-Ink e-readers. Contact:
admin@inkletter.app.
Gmail data
- Email address of your Google account (identification of the connected account).
-
Metadata and content of emails identified as newsletters (presence of the
List-Unsubscribe header), via the Gmail API in read-only mode
(scope gmail.readonly).
Analytics and usage measurement
Inkletter uses Firebase Analytics and Google Analytics 4,
configured via Google Tag Manager, to measure app usage (e.g. launches,
screens viewed, interaction events). This data is collected and processed by
Google. It does not include the content of your Gmail messages.
- Purpose: aggregated usage statistics and product improvement.
- No targeted advertising based on your newsletter content.
-
Learn more:
Google Privacy Policy.
Use of Google data (Limited Use)
Inkletter.app's use of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements. Specifically:
-
Gmail data is used solely to display your newsletters in the app and is processed locally on
your device (cache).
-
App usage data (analytics) is transmitted to Google (Firebase Analytics / GA4) as described
above.
- No Gmail data is sold or used for targeted advertising.
- No human reads your data.
Data protection mechanisms for sensitive data
Inkletter treats Gmail message content, newsletter metadata, your Google account email, and
OAuth credentials as sensitive user data. We apply the following technical and
organizational protections:
-
Encryption in transit: all network calls to Google OAuth, Gmail API, and
analytics endpoints use HTTPS / TLS only. No plaintext HTTP for user data.
-
Encryption at rest (OAuth tokens): access and refresh tokens are stored in
Expo SecureStore, backed by the Android
Keystore / hardware-backed keystore when available, with accessibility
limited to
WHEN_UNLOCKED_THIS_DEVICE_ONLY (tokens are not backed up off-device via
this API).
-
On-device processing: newsletter listing, filtering
(
List-Unsubscribe), and reading happen on the user’s device. Inkletter does
not operate a backend that stores Gmail message bodies or newsletter content.
-
Least privilege OAuth: the app requests only
gmail.readonly and userinfo.email. It never sends, modifies, or
deletes Gmail messages.
-
Access control: Gmail API calls require a valid user OAuth bearer token.
There is no shared service account reading user mailboxes. Signing out revokes the token
with Google (best effort) and deletes local session + cache.
-
Separation from analytics: Firebase / GA4 events do not include Gmail
message content or newsletter bodies — only aggregated product usage signals.
-
No sale / no ads use of Gmail data: Gmail data is not sold, not used for
advertising, and not transferred to unrelated third parties (Limited Use).
Storage
-
OAuth tokens: encrypted on the device (Android Keystore via Expo
SecureStore), as described above.
- Reading cache and preferences: local device storage only.
- No remote database for your newsletter content.
-
Analytics usage data: sent to Google (Firebase Analytics / GA4 via Google Tag Manager).
Sharing
Your newsletter content is not shared with third parties. Network communications include
Google's official APIs (Gmail, OAuth) and Google Analytics / Firebase services for app usage
measurement (HTTPS only).
Retention and deletion
Data remains on your device. Signing out (Settings → Sign out) or uninstalling the app removes
tokens and local cache. You can also revoke app access from your Google account:
myaccount.google.com/permissions.
Changes
Any changes to this policy will be published on this page with a new update date.
Terms of Service
See also our Terms of Service.