NonnaMail ("us", "we", or "our") operates the website, mobile deployment structures, and cloud-to-cloud automated data processing infrastructure located at nonnamail.app (the "Service"). This page informs you of our policies regarding the collection, use, transit, and disclosure of personal data when you use our Service and the choices you have associated with that data.
We utilize your data solely to provide and improve the automated travel itinerary dashboard. By using the Service, you agree to the collection and use of information in accordance with this policy.
To initialize your automated travel dashboard, NonnaMail requests limited access to your third-party email provider (such as Google Gmail or Microsoft Outlook) using secure OpenID Connect and OAuth authorization flows.
Account Identity Data: During account creation, we collect your primary account email address, full name, unique platform account identifier (such as Google's sub claim or Microsoft's id object identifier), and your profile picture URL. This data is utilized strictly to provision your user profile and manage your dashboard session.
Authentication Tokens: We collect and securely encrypt long-lived OAuth Refresh Tokens and transient Access Tokens. NonnaMail never collects, views, or stores your master account password. You maintain total control and may revoke our security tokens at any time via your email provider's account dashboard or in your user settings where you can disconnect email. If a user disconnects the email, we revoke entire read access and are no longer listening for new emails.
Integration Metadata: We collect automated platform system sync markers (such as Google History IDs) to track incremental incoming webhook data streams, ensuring your itinerary coordinates stay dynamically up-to-date without continuously scanning your historic mailbox state.
Because NonnaMail uses a cloud-to-cloud server-to-server architecture to automate your dashboard tracking, we enforce strict Data Minimization rules to handle incoming email streams.
Transient Inbound Webhooks: When an inbound travel message hits your account, your email provider sends a secure notification (such as a Google Pub/Sub webhook) to our server backend. Our server programmatically fetches the metadata envelope of the specific message.
Manual Inbound Emails: If you choose to utilize the Service via manual forwarding rather than OAuth integration, we process the full payload of the specific communication emails you intentionally transmit to our designated ingestion mailbox.
On-Demand Search Ingestion: If you choose to utilize our on-demand historical lookup feature, our server initiates an active API call to your connected email provider using your specified search inputs. The email payloads matching your parameter constraints are processed dynamically through our extraction pipeline. The search terms you enter are stored as described in section 6.
The Isolation Protocol (Transient RAM Processing): For automated webhook connections and historical domain search lookups, our server isolates the metadata markers of the message.
If an automated webhook notification does not originate from a recognized travel supplier domain, or if an unmatched historical search query is executed, any unparsed or unrelated email body text is instantly dropped from our server's volatile memory (RAM). Unrelated data is never saved, never logged, never reviewed by humans, and never written to our persistent databases.
If the sender matches travel criteria, or if the email is processed via your explicit manual forwarding or user-initiated domain search parameters, the email text payload is temporarily passed to our programmatic extraction engine to isolate the unstructured booking parameters.
Persistent Analytics Data Stored: Once parsed, the raw email content is discarded. NonnaMail writes only the unique third-party email messageId (to deduplicate incoming webhook streams) and the final structured travel metrics (e.g., flight numbers, check-in dates, lodging names, reservation windows, confirmation references) to our persistent application database to maintain your visual Dashboard.
If you subscribe to our Pro subscription plan, all transactional processing is delegated securely to our third-party payment infrastructure manager, Stripe. NonnaMail does not collect, process, or store your credit card numbers, CVV codes, or raw bank details. Stripe provides us solely with transient payment confirmations, subscription renewal timestamps, and a secure customer ID token to enable your premium access surfaces.
No Commercial Data Sale: NonnaMail does not sell, rent, trade, or monetize your personal communications or extracted travel itineraries to data brokers, advertising agencies, or marketing companies under any circumstances.
Private Third-Party AI Processing: To extract unstructured travel metrics from confirmation emails, NonnaMail securely transmits filtered text payloads to our dedicated API sub-processor, Anthropic (Claude API), over encrypted Transport Layer Security (TLS) pipelines.
Zero Model Training Guarantee: All third-party AI processing utilizes secure, commercial developer-tier interfaces. Your raw email data is contractually prohibited from being utilized by us or our sub-processors to train generative AI or Large Language Models (LLMs), and transient text history is permanently purged by our API provider within thirty (30) days.
Legal Disclosures: We may disclose your stored travel metadata only if required to do so by applicable law, subpoena, or valid governmental mandate.
NonnaMail's use and transfer to any other app of information received from Google APIs will strictly adhere to the Google API Services User Data Policy, including its strict Limited Use requirements. We enforce an absolute ban on using Gmail read.only data for serving advertisements, building target profiles, or extending raw visibility to external entities outside your designated travel view.
We retain your structured itinerary indicators only for as long as necessary to provide your travel summary interfaces.
NonnaMail infrastructure is managed primarily over secure cloud servers located within the United States. If you are accessing our dashboard surfaces from Europe, the United Kingdom, or alternative international regulatory districts, please note that your account profile markers and extracted itinerary records will be transferred to and securely stored within United States data nodes.
The security of your personal tracking nodes is an absolute priority. We utilize industry-standard Transport Layer Security (TLS/SSL) encryption protocols for all data traveling between your email provider, our webhook targets, and your user dashboard browsers. Stored application tokens are kept under high-tier database encryption layouts to mitigate unauthorized extraction vector threats.
We may update our Privacy Policy dynamically as platform compliance rules shift. We will notify you of any structural modifications by posting the revised text layout directly on this path and updating our "Last Updated" timestamp. For major policy reclassifications, an explicit email notice will be pushed to your registered primary account identifier.
For concerns, clarification requests, or immediate data purge mandates regarding your processed travel metrics, contact us directly:
By Email: support@nonnamail.app