Privacy Policy

Effective August 17, 2026

This document explains what data the MailSharks service (https://mailsharks.org) processes, why, on what legal basis, and for how long. By using the service you agree to the terms below.

1. Who processes the data

The service is operated by an individual developer. The contact point for any data protection enquiry is mailsharks.support@gmail.com; enquiries are answered within 30 days.

Allocation of roles. For your data (Telegram account, connected Google account, your sheets, templates and campaigns) the service acts as the controller. For the data of the recipients of your messages — addresses, names, delivery and open events — you are the controller: you compile the list and decide the purpose of the mailing, while the service acts as a processor on your instructions. Recipient requests about their data are addressed to you as the sender.

2. Data processed

DataPurpose
Telegram chat identifier, name and usernameTo separate your data from other users' and to confirm sign-in
Your Google account email addressTo show which account is connected
Google access and refresh tokensTo send mail and read spreadsheets on your behalf
Spreadsheet ID, sheet name, column namesTo read your recipient list
Recipient email addresses and names from your sheetTo send and personalise messages
Subject and body of the draft you selectTo compose the campaign messages
Templates created in the composer (name, subject, body)To keep your drafts between sessions
Delivery and open status, message identifiers, unsubscribesTo display statistics and to never mail people who opted out
Chat settings and the chosen interface languageTo remember your preferences
Subscription and payment data (plan, term, amount, currency, payment method, status, payer's email address, contract identifier)Enabling the paid plan, renewing and cancelling the subscription, issuing refunds
Server logs (IP address, request time, requested path)Fault diagnosis and abuse protection

The service neither collects nor requests special categories of personal data. There is no automated decision-making producing legal effects.

3. Legal bases

4. Access to Google user data

The service requests the following scopes and uses them strictly for the stated purpose:

ScopeHow it is used
gmail.sendTo send the campaign messages on your behalf
drive.fileTo read the spreadsheet you picked yourself in the Google window. The application sees no other files on your Drive and writes nothing
userinfo.emailTo show which account is connected

Limited Use disclosure. MailSharks' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, transferred to third parties, used for advertising, or used to train machine learning models.

5. Cookies

The service uses two cookies. Both are strictly necessary for it to function and therefore require no separate consent:

CookiePurpose and lifetime
ms_sessionSet only after you confirm sign-in in the bot. Contains your Telegram chat identifier and a signature, lives for 30 days and serves one purpose: not asking you to sign in on every visit
ms_langSet only if you switch the page language yourself. Contains the chosen language (ru or en) and lives for a year

The service also keeps your chosen colour theme — light or dark — in your browser's localStorage. That is not a cookie: it is never transmitted and stays on your device.

You can delete all of the above in your browser, and the session also with the “Sign out” button in the app. There are no analytics or advertising cookies, counters or third-party trackers on this site.

6. Open tracking

A transparent 1×1 pixel image is added to outgoing messages. Loading it indicates the message was opened; the fact and time of the first open are recorded. Message content, replies and link clicks are not tracked. Tracking is enabled by the sender, and the sender is responsible for its lawfulness in their jurisdiction.

7. Where data is stored and with whom it is shared

Data is stored in a Supabase (PostgreSQL) database reachable only from the application server; connections are protected with TLS. Google tokens are stored in the database and used solely to call Google APIs on your behalf.

Data is not sold or disclosed to third parties, except for the infrastructure providers the service cannot operate without, and where required by law:

ProviderRole
Google LLCMail delivery, spreadsheet access, authorisation
Supabase Inc.Database hosting
Telegram Messenger Inc.Bot interface and sign-in confirmation
lava.topSubscription payments. Card details are entered on the payment provider's side and are never passed to the service

International transfers. These providers host servers outside your country of residence. The service's database is located in the Asia-Pacific region (Republic of Korea); the servers of Google, Telegram and the payment provider are in other countries, including the United States and the EU. Transfers happen on those providers' terms and are necessary for the service to work.

8. Retention

9. Your rights

At any time you may:

10. Security

Only the application server can reach the database, using a service key; connections are protected with TLS. Each user's data is separated by chat identifier and every request verifies record ownership. Identity is proven by a Telegram signature — a chat identifier supplied in a request is never trusted. No protection is absolute, and the service cannot guarantee safety if your Telegram or Google account itself is compromised.

11. Children

The service is not intended for people under 16 and does not knowingly collect their data. If such data has reached the service, write to mailsharks.support@gmail.com and it will be deleted.

12. Changes

The current version is always available at https://mailsharks.org/privacy. The effective date is shown at the top of this page. Material changes will be announced in the bot.

13. Contact

mailsharks.support@gmail.com

MailSharks