re4box

Türkçe

Privacy Policy — re4box

Last updated: August 26, 2026

This Privacy Policy explains how Emre Space (“we”, “us”, or “our”) collects, uses, stores, and protects information when you use the re4box application (Android package name: com.emrespace.re4box), including iOS and desktop builds of the same product. re4box helps you manage connected mailboxes — Outlook / Microsoft 365, Exchange, and IMAP brands (Gmail, Yahoo / AOL, iCloud, Yandex, Fastmail) — with rules, bulk mailbox actions, sender discovery, and optional premium features.

1. Who we are

re4box is developed and published by Emre Space (emrespace.com). This policy applies only to the re4box app and the backend services we operate for that product.

This policy does not cover third-party websites, stores, or services that we do not control, including Google, Microsoft, Apple, Google Play, or the App Store outside the app. The emrespace.com marketing website is separate from the re4box app.

2. Privacy summary

In short:

  • We access your mailbox so we can list mail, apply the rules you create, run bulk actions you confirm, scan senders, and (where supported) unsubscribe using one-click headers or an in-app web view of the sender’s page.
  • We do not keep a long-term archive of full email bodies. List views use metadata and short snippets; the full body is fetched when you open a message.
  • We do not sell your personal data. We do not use Gmail, Outlook, Exchange, or IMAP mailbox content to train AI models or to personalize ads.
  • Google user data is used only to provide and improve user-facing features of re4box, in line with the Google API Services User Data Policy, including Limited Use requirements.
  • Free users on Android and iOS may see AdMob native ads. Premium turns ads off. Desktop builds do not show ads. Android and iOS include Firebase Analytics (product events, not mailbox content) and Firebase Crashlytics (crash reports). Desktop builds do not.

3. Information we collect and process

Depending on how you use re4box, we may process the following categories of information.

  • Account information: email address, name, and profile picture from Microsoft OAuth, or the mailbox address you enter for Exchange or IMAP (including Gmail), plus provider identifiers needed to keep your account linked.
  • Exchange credentials: username, mailbox password, and EWS URL when you connect an Exchange account. The password is stored encrypted on our servers so we can act on that mailbox on your behalf.
  • IMAP app-specific passwords: when you connect Gmail, Yahoo / AOL, iCloud, Yandex, or Fastmail, we store the app-specific password you create for re4box (encrypted on our servers) so rules can run when the app is closed. For Gmail this is a Google App Password, not your Google account password. It is not your Apple ID password and not the password you use to sign in to Yahoo, Yandex, or Fastmail on the web. We do not store Outlook account passwords; Outlook uses OAuth tokens.
  • Email metadata: sender, subject, date, read state, and label/folder information needed to list mail, match rules, scan senders, and run bulk actions.
  • Email snippets: a short preview used in the inbox list. Full message body is requested on demand when you open a mail and is not retained as a long-term archive.
  • Rules and preferences: conditions and actions you create, theme, language, trusted or hidden senders, and similar app settings.
  • Sender scan data: unique senders found in your mailbox, domain, mail counts, List-Unsubscribe headers, and whether you have unsubscribed, trusted, or hidden a sender.
  • Job snapshots: provider message IDs (not full bodies) for background jobs such as sender scan, apply-rules, and bulk actions, plus progress and result status.
  • OAuth tokens: Microsoft refresh/access tokens for Outlook / Microsoft 365, stored encrypted, so we can act on that mailbox on your behalf. Production Gmail does not use Google OAuth or the Gmail API.
  • Session and device data: device-bound session tokens, device identifiers, platform information, and encrypted push tokens when notifications are enabled.
  • Play Integrity signals (Android): a device integrity token may be sent at sign-in for monitoring. We do not currently block access based on that check.
  • App interaction events (Android and iOS): Firebase Analytics records product events such as screens, rules, Discover swipes, and purchases, with non-personal parameters. We do not send email addresses or mail content in those events. Desktop builds do not include Firebase Analytics.
  • Crash diagnostics (Android and iOS): Firebase Crashlytics may collect stack traces and device model when the app crashes. We do not send email addresses or mail content in crash reports. Desktop builds do not include Firebase Crashlytics.
  • Advertising consent (Android and iOS): Google User Messaging Platform (UMP) may record your ad-consent choice in the European Economic Area, the United Kingdom, and Switzerland.
  • Feedback: messages you submit from Settings.
  • Subscription data: which connected account is marked as the premium owner, and entitlement status verified through RevenueCat and the app stores.

4. Mailbox access and Limited Use

To provide re4box we request mailbox permissions from the provider you connect.

For Outlook / Microsoft 365 we request Mail.ReadWrite and MailboxSettings.ReadWrite, plus identity and offline access. For Exchange we use the credentials you enter to call Exchange Web Services. For Gmail, Yahoo / AOL, iCloud, Yandex, and Fastmail we sign in over IMAP (Gmail: imap.gmail.com) with the app-specific password you provide. We do not request Gmail API scopes (gmail.modify, gmail.settings.basic, or mail.google.com), we do not write a native Gmail filter, and we do not permanently delete Gmail messages.

We use this access only to provide features you request, including:

  • Listing mail and showing metadata in the app
  • Creating, updating, and applying rules (Outlook / Exchange inbox rules; IMAP rules including Gmail are stored only in re4box and applied on our servers)
  • Inbox actions such as archive, trash, move, star, and mark as read
  • Bulk Actions jobs you confirm (trash, archive, mark as read, one-click unsubscribe; permanent delete on Outlook / Exchange / non-Gmail IMAP only)
  • Scanning senders and storing unsubscribe / trust / hide preferences
  • Receiving provider push notifications so new mail can trigger matching rules (Outlook). Exchange and IMAP accounts, including Gmail, do not receive mailbox push in re4box; IMAP mailboxes are checked once per day at 00:00 UTC for new mail that matches your rules.

5. Google Limited Use and Microsoft API commitments

Production Gmail is accessed over IMAP with an App Password, not through the Gmail API. When we access Google user data through Google APIs (for example ads, Play, Cloud Messaging, Analytics, or Crashlytics), we comply with the Google API Services User Data Policy, including the Limited Use requirements. The same commitments apply to Gmail mailbox data we process over IMAP:

  • We use Gmail data only to provide and improve user-facing features of re4box.
  • We do not transfer Gmail data to third parties except as needed to run the service (for example our hosting and database providers), to comply with law, or with your direction (for example posting a one-click unsubscribe request to a sender’s listed URL).
  • We do not use Gmail data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Gmail data unless you give us permission, it is necessary for security or legal reasons, or the data is aggregated and no longer associated with you.
  • We do not use Gmail data to train generalized AI or machine-learning models.

6. Microsoft mailbox data

When you connect Outlook / Microsoft 365, we access Microsoft Graph in line with Microsoft’s API terms and your grant. When you connect Exchange, we call Exchange Web Services with the credentials you provide. When you connect Gmail, Yahoo / AOL, iCloud, Yandex, or Fastmail, we use IMAP LOGIN with your app-specific password on that provider’s IMAP host (Gmail: imap.gmail.com).

We do not use Outlook, Exchange, or IMAP mailbox content to train AI models, to serve or personalize ads, or for any purpose other than providing the re4box features you request.

7. Rules and automatic processing

Rules you create may move, archive, trash, star, or mark as read matching mail. On Outlook and Exchange those actions are stored as the provider’s own inbox rules. On IMAP brands (Gmail, Yahoo / AOL, iCloud, Yandex, Fastmail) there is no native inbox filter: the rule is stored only in re4box and applied when you save it and once per day for new mail (00:00 UTC). re4box does not offer a Gmail permanent-delete rule.

You remain responsible for the rules you enable. Deleting your re4box account does not remove Outlook or Exchange inbox rules already created there, or any Gmail filters left from an older version of re4box. IMAP-only rules we stored are deleted with your re4box account.

8. Bulk Actions and other mailbox changes

Bulk Actions is a Premium feature. It lets you apply a one-time job to predefined groups (for example spam/junk, older mail, unread mail, or one-click unsubscribe). After you confirm, we analyze matching message IDs, then apply the action in batches. The job can continue on our servers after you close the app. Stopping a job does not undo batches already sent to the provider. There is no rollback.

You can also change individual or selected messages from the inbox (for example archive, trash, move, star, or mark as read).

On Outlook / Exchange / non-Gmail IMAP, Bulk Actions may include permanent delete, which cannot be undone. Organizational retention or hold policies may still keep a copy on the provider’s side; re4box does not bypass those policies. Gmail bulk and rule actions use Trash, which remains recoverable in Gmail until Gmail expires it.

9. Unsubscribe

Where a message advertises RFC 8058 one-click unsubscribe (List-Unsubscribe plus List-Unsubscribe-Post over HTTPS), you can ask re4box to send that unsubscribe request. We POST only to the HTTPS URL provided by the sender.

Where a sender provides a web unsubscribe page instead, re4box may open that page in an in-app web view. That page is operated by the sender, not by Emre Space. Their cookies, scripts, and privacy practices apply while the page is displayed. You can also open the same URL in your browser.

The sender is a third party; we cannot guarantee they will remove you from their list. Unsubscribe actions are not available on Exchange accounts. IMAP brands can use one-click unsubscribe when the message advertises it.

10. Subscriptions and payments

Optional re4box Premium is billed through Google Play or the Apple App Store on Android and iOS, and verified with RevenueCat. We store which connected account is the premium owner and whether the entitlement is active so we can unlock premium features on devices where that owner is signed in.

The desktop app does not sell in-app subscriptions. Premium on desktop follows the premium-owner mailbox already recorded on our servers when that owner is signed in.

Payment card details are handled by Apple or Google, not by Emre Space. Purchase history needed to restore or verify a subscription may be processed by RevenueCat and the store. Cancelling a store subscription is done in your Apple or Google account settings; deleting re4box data does not by itself cancel a paid subscription.

11. Advertising

On Android and iOS, free users may see native ads from Google AdMob in the inbox and rules lists. Ads are turned off for premium users. Desktop builds do not show ads.

In the European Economic Area, the United Kingdom, and Switzerland, Google User Messaging Platform (UMP) may ask for advertising consent before ads are requested. Where Google requires it, you can reopen those privacy options from Settings.

AdMob may collect device and advertising signals according to Google’s advertising SDK and your consent choices. On Android we do not collect the Advertising ID. On iOS we do not request App Tracking Transparency or IDFA; attribution may use SKAdNetwork only. We do not send Gmail, Outlook, Exchange, or IMAP mailbox content, message bodies, or rule contents to AdMob to personalize those ads.

12. Push notifications

With your permission, we may send operational push notifications (for example new mail, sender scan completed, or bulk-action status) using Firebase Cloud Messaging. Encrypted push tokens are stored so we can reach devices where you enabled notifications.

Outlook may receive mailbox push. Exchange and IMAP accounts, including Gmail, do not receive mailbox push in re4box. IMAP mailboxes are checked once per day at 00:00 UTC for new mail that matches your rules. We do not use push for marketing campaigns.

13. Analytics and diagnostics

On Android and iOS, re4box uses Firebase Analytics to record product events (for example login, screens, rules, Discover swipe, and purchase). Events use event names and non-personal parameters. We do not include email addresses, message bodies, or rule contents. Advertising-identifier collection is off in the app, and analytics is not used to personalize ads. Desktop builds do not include Firebase Analytics.

On Android and iOS, re4box uses Firebase Crashlytics to report crashes (stack traces and device model) so we can fix bugs. Crash reports do not include email addresses or mail content. Desktop builds do not include Firebase Crashlytics.

We may process technical logs needed to operate and secure the API (for example redacted request logs on our hosting provider). Play Integrity signals on Android are used for monitoring as described above. The emrespace.com website may use its own analytics; that is not part of the re4box app.

14. How we share information

We do not sell your personal information. We share or disclose information only in these limited ways:

  • Microsoft (Graph API, OAuth, or Exchange Web Services) and IMAP hosts for Gmail (imap.gmail.com), Yahoo / AOL, iCloud, Yandex, and Fastmail — to access and change the mailbox you connected.
  • Vercel — to host the re4box API.
  • Neon — to store accounts, encrypted tokens, rules, jobs, and related data.
  • Upstash QStash — to pace long-running jobs (sender scan, apply-rules, bulk actions).
  • Firebase Cloud Messaging — to deliver push notifications.
  • Firebase Analytics — product-usage events on Android and iOS, as described above.
  • Firebase Crashlytics — crash reports on Android and iOS, as described above.
  • RevenueCat, Google Play, and the Apple App Store — to process and verify subscriptions.
  • Google AdMob and Google UMP — ads and advertising consent for free users on Android and iOS, as described above.
  • Brandfetch or logo.dev — domain-based logos for senders (we send a domain, not mail content).
  • Legal requirements: we may disclose information if required by law, legal process, or to protect rights, safety, and integrity.
  • Business changes: if Emre Space or re4box is involved in a merger, acquisition, or asset transfer, information may be transferred as part of that transaction, subject to appropriate privacy protections.

15. Storage, security, and retention

OAuth tokens, Exchange passwords, and IMAP app-specific passwords are encrypted at rest (AES-256-GCM). Communications with our API use HTTPS/TLS. On mobile, local mail metadata cache uses an encrypted on-device database. Session tokens are stored in platform secure storage.

We keep account, rule, job, and token data while your re4box account exists and as needed to operate the service. When you permanently delete a re4box account we wipe associated data we store (profile, tokens including Exchange credentials and IMAP app-specific passwords, re4box rules, devices, sender cache, jobs, and feedback).

Deleting re4box does not delete emails, labels, folders, or Outlook / Exchange inbox rules that remain in your provider mailbox, or Gmail filters left from an older version of re4box. Uninstalling the app without deleting the account leaves server-side data in place until you delete the account.

16. Children’s privacy

re4box is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the app, contact us and we will take appropriate steps.

17. Your choices and rights

If the EU General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK), or similar laws apply to you, you may have rights to access, correct, delete, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority (in Türkiye, the Kişisel Verileri Koruma Kurumu). To exercise these rights for data we hold, contact [email protected].

You can also:

  • Revoke a Gmail App Password at myaccount.google.com/apppasswords, or revoke Outlook access in your Microsoft account permissions.
  • Remove an account from this device in Settings (signs that mailbox out of the app on this device without deleting the re4box account).
  • Permanently delete a re4box account from Settings (all connected providers). The web page at https://re4box.emrespace.com/delete-account currently verifies identity with Google only; Outlook, Exchange, and IMAP accounts (including Gmail) should be deleted in the app.
  • Review or sign out linked devices in Settings.
  • Turn push notifications off in Settings or system settings.
  • Where Google requires it, reopen advertising privacy options from Settings (typically EEA, UK, and Switzerland).
  • Cancel a Premium subscription in Google Play or App Store account settings.

18. International processing

Our processors (including Vercel, Neon, Google, Microsoft, Firebase, RevenueCat, and Upstash) may process data in the United States or other countries where they operate infrastructure. If you use re4box from another country, information may be transferred internationally subject to those providers’ safeguards and applicable law, including KVKK and GDPR where they apply.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date on this page. For material changes, we may provide additional notice in the app or on emrespace.com.

20. App stores and platform permissions

When you download re4box from Google Play or the App Store, that store’s own privacy practices also apply to download, billing, reviews, and account management. Platform permission dialogs are controlled by the operating system vendor.

Contact us

If you have questions about this Privacy Policy, your data, or privacy rights related to re4box (including KVKK and GDPR requests), contact us at:

[email protected]