Privacy Policy
Last updated: 12 September 2026
nmail by soaq is an email workspace provided by Soaq AB at nmail.io. This policy covers the nmail website, web app and native iOS app. Contact us about privacy or your data at sebastian@scopeapp.io.
What nmail accesses and why
Google sign-in gives nmail your Google account identifier, verified email address and profile information, including your name. We use these to identify you, maintain your account and check team membership. Connecting a Gmail or Google Workspace inbox is a separate authorization step.
When you connect an inbox, you authorize nmail to read messages and attachments, search email history, manage drafts, send email and change message labels. nmail uses that access to show conversations, compose and reply, schedule sends, and move conversations between Inbox, Archived, Trash and Spam. Scheduled messages can be sent while the app is closed. We do not request access to Google Drive, Calendar, Contacts or your Google password.
We also process the information you and your teammates provide in nmail: inbox invitations and permissions, display names and usernames, internal comments and mentions, assignments, personal read/star/snooze markers, preferences and support requests.
What is stored
Your mailbox and email drafts remain with the connected email provider (Gmail or Microsoft). nmail fetches email bodies, subjects, previews, recipient headers and attachment contents through its server into memory for display, editing or sending. It does not maintain a durable copy of your real mailbox or an email-content search index.
nmail stores account and mailbox identifiers, encrypted Google and Microsoft authorization tokens, team memberships, inbox grants, invitations, thread/message references, internal comments, mentions and notifications. It also stores conversation state, draft references and versions, scheduling instructions, send confirmations, preferences and open-event records. Internal comments are stored separately from email; anything you paste into a comment becomes part of that stored comment.
Web sessions use an essential sign-in cookie. Your browser may retain interface preferences, such as column widths and recent emoji choices. The iOS app keeps a nmail sign-in credential in the device Keychain; email content remains transient. If you deliberately export an attachment, the copy is saved to the destination you choose.
Our web server processes technical request information, such as IP addresses, request times, requested paths and response status, for operation and security. These logs are separate from the application’s email and open-event records.
Sharing and other recipients
A newly connected inbox is private to its owner in nmail. An owner can explicitly share an inbox with invited teammates on the same domain. Sharing grants those members access to the inbox’s email history, new messages and internal comments, and allows them to reply and perform inbox actions. A matching domain alone does not provide access. Removing a grant stops that member’s access through nmail.
Email you send is delivered through your connected mail provider to your chosen recipients. nmail’s saved email drafts exist in the provider mailbox, so anyone who independently has access to that mailbox may be able to see them there. Internal comments are not sent to email recipients.
We use service providers to host and operate nmail. They process data needed to deliver the service on our behalf. Google or Microsoft processes its connected mailbox data under its own terms and policies. When an email displays a remote image, the image host or Google’s image proxy may receive a request from your device. Exported files and copies already received by other people are outside nmail’s access controls.
Microsoft Outlook and Microsoft 365
You can also sign in with Microsoft and connect Outlook.com, Hotmail, Live.com or Microsoft 365 inboxes. We use your Microsoft tenant/account identifiers, verified email-domain information and profile to identify your nmail account. Mail access is requested separately when you connect an inbox. The delegated permissions allow reading/searching messages, managing drafts and attachments, sending email, and moving conversations to Archive, Deleted Items or Junk Email. Offline access enables token renewal and scheduled sends.
For these inboxes, Microsoft remains the mailbox and draft store. Message content and attachments pass through nmail temporarily to provide the features you select. We store encrypted Microsoft authorization tokens, expiry and mailbox identifiers alongside the same access, collaboration and scheduling records described above. We do not sell Microsoft mailbox data, use it for advertising or credit decisions, or use it to train AI models. Internal comments remain separate from email, and sharing requires the same explicit permissions.
Disconnecting an Outlook inbox deletes its stored Microsoft access and refresh tokens from nmail. It does not delete Microsoft messages or nmail collaboration records, or revoke access for other applications. You can also remove nmail's consent in your Microsoft account or organization's application settings. Microsoft processes your connected mailbox under its own terms and privacy policies. Contact us to request deletion of your nmail records as described below.
Limited use of Google data
nmail follows the Google API Services User Data Policy and its Limited Use requirements for Google data. We use this data to provide nmail’s visible email and collaboration features. We do not sell it, use it for advertising or credit decisions, or use it to train AI models.
Service staff do not read your email for routine review. Access to specific data for support requires your permission, except when necessary to investigate security issues or comply with law. Access by teammates follows the inbox permissions you authorize. Other disclosures are limited to providing the service with your authorization, protecting security or meeting legal obligations. A transfer in a business sale would require your prior explicit consent where Google’s rules require it.
Optional email-open tracking
nmail can add a small image to an outgoing email to estimate when it is opened. The setting is visible in the composer and can be turned off per email or in Settings. Tracking is currently enabled by default for new messages; previously saved drafts without a tracking choice remain off.
The application records message references, aggregate counts and the first, last and up to 100 recent image-load times. It does not attach recipient IP addresses or user-agent strings to those application records. Ordinary server logs can still contain request information. Multiple recipients share a message’s tracking image, so nmail cannot reliably identify which person opened it. Image blocking, caching and privacy features can hide or generate loads.
Retention, disconnection and deletion
Email content fetched for reading or editing is temporary. Your mail provider controls retention of the underlying mailbox and drafts. nmail retains its account, authorization and collaboration records while needed for the workspace, until deletion is requested and processed, or where retention is required for security or legal obligations. There is currently no automatic age-based expiry for workspace comments or conversation references.
Disconnecting an inbox in nmail stops its use through the app, but does not erase collaboration records or revoke Google permission. Google connection tokens remain stored until deletion is requested; Microsoft connection tokens are erased on disconnect. To revoke Google access, remove nmail in your Google Account’s third-party connections. To request deletion of stored nmail data, email sebastian@scopeapp.io from the account concerned, or explain how we can verify your request.
We verify your identity and the scope of the request before removing data. Shared workspace records may also involve your organization and other users; we will explain any records that must be retained and why. Deleting nmail data does not delete your provider mailbox. Operational logs and backup copies are retained only as needed for recovery, security and legal obligations, and are handled separately from active workspace records.
Your choices and rights
You choose which inboxes to connect, which teammates to invite and whether to enable open tracking. You can revoke provider access, disconnect an inbox, change sharing permissions or contact us to close your account. Signing out ends that device’s nmail session; it does not delete the account.
For account administration, we process data to provide the service you request. Security and abuse prevention support our legitimate interest in operating the service safely. Your organization controls the purposes of its shared mailbox and workspace content, which we process to carry out its instructions. Where processing relies on consent, you may withdraw it.
Depending on applicable law, you may request access, correction, deletion, portability or restriction of your personal data, and may object to certain processing. Contact us using the address above. You may also complain to your local data-protection authority, including the Swedish Authority for Privacy Protection (IMY).
Security and policy changes
nmail uses HTTPS, encrypts stored Google and Microsoft authorization tokens and checks account, team and inbox permissions on server requests. Access is limited to operating and supporting the service. No online service can eliminate every security risk.
We will update this page when our practices change and make material changes visible in the service or notify affected users where appropriate. We will obtain additional authorization before using Google data for a new purpose when required.