Privacy Policy
Last updated: August 2026
The short version
Your mbox file never leaves your device. All parsing, viewing, searching, CSV export and PDF generation happen locally in your browser. Our servers never receive the file, any message, any email address from it, or anything you search for.
What we do NOT collect
- Your mbox file — it is read in small chunks by JavaScript running in your browser tab and is never uploaded.
- Message content — subjects, senders, bodies, attachments and search queries stay in your browser's memory and are discarded when you close the tab.
- Accounts and cookies — the site has no signup, and it sets no cookies.
What is stored on your device
If you purchase and activate a license, a signed activation token (not the key itself) and its
timestamp are stored in your browser's localStorage (key mboxconvert_license)
so you don't have to re-enter it. The site also stores one anonymous random ID (key vid)
used only for usage statistics — it contains no personal data. Clear your browser's site data at any
time to remove both. Nothing else is persisted.
What is sent over the network
- Page & library loads. The site is static files, and all libraries it uses (jsPDF, html2canvas) are served from our own domain by our hosting provider (Vercel). Like any web request, the provider may log your IP address and user agent per its own privacy policy.
- Anonymous usage statistics. We use Vercel Web Analytics, which counts page views and referrers without cookies and without collecting any file or personal data.
- Anonymous usage counters. Our server keeps running counts of tool events: a file was indexed (message count and file size only), a PDF was exported (message count), and client-side error codes. Events carry the anonymous random ID from your browser, used only to estimate unique visitors and to split free vs licensed usage — no personal data, and your files never leave the browser. These are bare numbers — they never include message content, email addresses, file names, or search queries.
- License validation (paid users only). When you enter a license key, the key — and only the key — is sent to our serverless endpoint, which forwards it to Gumroad's license API to confirm validity. No mailbox data is ever attached to this request.
- Checkout (paid users only). If you buy a license, the transaction is handled by Gumroad under their privacy policy. We receive only an order confirmation and your email address for license delivery.
- Feedback you choose to send. The Feedback link opens a form delivered by Web3Forms: only the text you type and, if you fill it in, your reply email address are sent. Never attach or paste your mailbox content — we cannot use it and do not want it.
Data retention
Your mailbox data is never sent to us, so there is nothing for us to retain or delete. Anonymous usage counters (numbers only, as described above) are kept as daily aggregates and lifetime totals. License and order records are retained by Gumroad as required for accounting purposes.
Changes to this policy
If we ever change how data is handled, we will update this page. Any feature that would require sending file content to a server (we have none planned) would be opt-in and clearly marked before it affects you.
Contact
Questions about privacy? Email hello@mboxconvert.com or reply to your Gumroad receipt.