This document explains what data the MailSharks service
(https://mailsharks.org) processes, why, on what legal basis, and for how
long. By using the service you agree to the terms below.
The service is operated by an individual developer. The contact point for any data protection enquiry is mailsharks.support@gmail.com; enquiries are answered within 30 days.
Allocation of roles. For your data (Telegram account, connected Google account, your sheets, templates and campaigns) the service acts as the controller. For the data of the recipients of your messages — addresses, names, delivery and open events — you are the controller: you compile the list and decide the purpose of the mailing, while the service acts as a processor on your instructions. Recipient requests about their data are addressed to you as the sender.
| Data | Purpose |
|---|---|
| Telegram chat identifier, name and username | To separate your data from other users' and to confirm sign-in |
| Your Google account email address | To show which account is connected |
| Google access and refresh tokens | To send mail and read spreadsheets on your behalf |
| Spreadsheet ID, sheet name, column names | To read your recipient list |
| Recipient email addresses and names from your sheet | To send and personalise messages |
| Subject and body of the draft you select | To compose the campaign messages |
| Templates created in the composer (name, subject, body) | To keep your drafts between sessions |
| Delivery and open status, message identifiers, unsubscribes | To display statistics and to never mail people who opted out |
| Chat settings and the chosen interface language | To remember your preferences |
| Subscription and payment data (plan, term, amount, currency, payment method, status, payer's email address, contract identifier) | Enabling the paid plan, renewing and cancelling the subscription, issuing refunds |
| Server logs (IP address, request time, requested path) | Fault diagnosis and abuse protection |
The service neither collects nor requests special categories of personal data. There is no automated decision-making producing legal effects.
The service requests the following scopes and uses them strictly for the stated purpose:
| Scope | How it is used |
|---|---|
gmail.send | To send the campaign messages on your behalf |
drive.file | To read the spreadsheet you picked yourself in the Google window. The application sees no other files on your Drive and writes nothing |
userinfo.email | To show which account is connected |
Limited Use disclosure. MailSharks' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, transferred to third parties, used for advertising, or used to train machine learning models.
The service uses two cookies. Both are strictly necessary for it to function and therefore require no separate consent:
| Cookie | Purpose and lifetime |
|---|---|
ms_session | Set only after you confirm sign-in in the bot. Contains your Telegram chat identifier and a signature, lives for 30 days and serves one purpose: not asking you to sign in on every visit |
ms_lang | Set only if you switch the page language yourself. Contains the chosen language (ru or en) and lives for a year |
The service also keeps your chosen colour theme — light or dark — in your browser's localStorage. That is not a cookie: it is never transmitted and stays on your device.
You can delete all of the above in your browser, and the session also with the “Sign out” button in the app. There are no analytics or advertising cookies, counters or third-party trackers on this site.
A transparent 1×1 pixel image is added to outgoing messages. Loading it indicates the message was opened; the fact and time of the first open are recorded. Message content, replies and link clicks are not tracked. Tracking is enabled by the sender, and the sender is responsible for its lawfulness in their jurisdiction.
Data is stored in a Supabase (PostgreSQL) database reachable only from the application server; connections are protected with TLS. Google tokens are stored in the database and used solely to call Google APIs on your behalf.
Data is not sold or disclosed to third parties, except for the infrastructure providers the service cannot operate without, and where required by law:
| Provider | Role |
|---|---|
| Google LLC | Mail delivery, spreadsheet access, authorisation |
| Supabase Inc. | Database hosting |
| Telegram Messenger Inc. | Bot interface and sign-in confirmation |
| lava.top | Subscription payments. Card details are entered on the payment provider's side and are never passed to the service |
International transfers. These providers host servers outside your country of residence. The service's database is located in the Asia-Pacific region (Republic of Korea); the servers of Google, Telegram and the payment provider are in other countries, including the United States and the EU. Transfers happen on those providers' terms and are necessary for the service to work.
At any time you may:
Only the application server can reach the database, using a service key; connections are protected with TLS. Each user's data is separated by chat identifier and every request verifies record ownership. Identity is proven by a Telegram signature — a chat identifier supplied in a request is never trusted. No protection is absolute, and the service cannot guarantee safety if your Telegram or Google account itself is compromised.
The service is not intended for people under 16 and does not knowingly collect their data. If such data has reached the service, write to mailsharks.support@gmail.com and it will be deleted.
The current version is always available at
https://mailsharks.org/privacy. The effective date is shown at the top of
this page. Material changes will be announced in the bot.