Last updated: May 2026 · NZ Privacy Act 2020 compliant
We do not store your emails, email content, or personal data. Everything is processed in real-time and discarded the moment your session ends. We have nothing to sell and nothing to leak.
When you sign in with Google, we request read-only OAuth access to your Gmail account. We access only two email headers per message:
We never read the body, subject line, or any other part of your emails. We never access your attachments, contacts, calendar, Google Drive, or any other Google service.
We also store a short-lived, encrypted session token in your browser (via a secure cookie) so you stay signed in during your visit.
The header data we access is used solely to:
We do not use your data for advertising, profiling, or any purpose beyond providing the inbox-cleaning service you signed up for.
UnsubSpam has no database. We do not write any of the following to disk or any storage system:
Scan results exist only in your browser's memory for the duration of your session. When you close the tab or sign out, that data is gone — permanently, because it was never persisted anywhere.
We use the following third parties to operate the service:
We do not use advertising networks, tracking pixels, or analytics SDKs of any kind.
Because we store nothing, our retention policy is simple: there is nothing to retain.
Your session token (the encrypted cookie) is cleared when you sign out or when your browser session expires. You can also revoke our access entirely at any time from your Google account permissions page, which immediately invalidates any token we hold.
Under the New Zealand Privacy Act 2020, you have the right to:
To exercise any of these rights or to raise a privacy concern, contact us at hello@unsubspam.com. We aim to respond within 5 business days.
If you are not satisfied with our response, you may contact the New Zealand Office of the Privacy Commissioner at privacy.org.nz.
UnsubSpam is operated from New Zealand and complies with the Privacy Act 2020. Our privacy practices are designed around the 13 Information Privacy Principles (IPPs) set out in that Act, including purpose limitation, data minimisation, and security safeguards.
Because we process data only in-memory and do not retain it, many of the traditional compliance obligations (such as data breach notification for stored records) do not apply to us in practice.
If we make material changes to this policy, we will update the date at the top of this page. We will make reasonable efforts to notify users of significant changes — for example by displaying a notice within the app.
Continued use of UnsubSpam after changes are posted constitutes acceptance of the updated policy.
Questions about privacy? Reach us at hello@unsubspam.com. We respond as humans, not bots.