MailHarbor information
Privacy notice
MailHarbor is a mailbox application maintained by Smet Software Solutions. This notice describes the current private deployment, which serves its owner and authorized devices. For cloud hosting and the arrangements for that deployment, contact Smet Software Solutions.
Mailbox access and saved labels
The application server connects to mailboxes separately authorized by the owner. Depending on the provider, these connections use a password, app password or mailbox OAuth authorization. MailHarbor reads message headers for unified folders and search, and retrieves bounded message text for requested previews, briefings or separately enabled automatic organization.
Saved labels retain bounded headers, labels and internal mailbox references on the application server. These can include sender, recipient, subject, date, account label and read or star status. Labeling leaves the source message in place. Explicit read, star or briefing cleanup actions can update the original mailbox. When the owner enables automatic organization, the application server also marks mail read and applies the owner's category retention and Junk-review rules.
Invoice processing and Google Drive
When the owner starts a scan or enables automatic filing, MailHarbor retrieves original PDF and supported XML attachments. Text extraction, customer matching and invoice-date routing run locally on the application server without invoking Agy or an AI service. Original bytes and extracted text are held during processing; the invoice worker does not keep a local document archive.
When filing succeeds, Google Drive receives the original document and associated file and folder metadata. That metadata includes its filename, destination business/year/quarter, content hash and app identifiers used to avoid duplicate uploads. The application server keeps an encrypted invoice history, derived routing details, source references and retry identifiers.
The separate Drive authorization requests only:
https://www.googleapis.com/auth/drive.file— permission for files created by the app or explicitly made available to it. MailHarbor's filing workflow uses its own app-created invoice folders and files.openidandemail— verification of the signed-in Google account and its email address.
The application restricts this connection to the owner's designated Google account. Its address is visible inside the authenticated application, rather than on these public pages. Drive authorization is separate from mailbox access.
MailHarbor’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Optional AI organization and briefings
With the owner's separate permission, automatic organization sends bounded message subjects, senders, recipients, dates, folder categories and plain text to Google Gemini through Agy. This can include historical mail in Inbox, Sent, Drafts, Junk, Trash and custom folders across the connected accounts. Each classification request contains at most 40 messages and at most 8,000 text characters per message. Attachments, mailbox credentials and encrypted message bodies are excluded from model input.
Gemini proposes categories, spam assessments and dates. The application server validates those results and applies the owner's retention rules. Expired deletable mail moves to the provider's Trash; other categories are archived. MailHarbor does not permanently purge mail, but a provider may empty Trash automatically. Junk with complete content that Gemini confidently identifies as legitimate can return to Inbox, including mail from new senders; uncertain mail stays in place. The owner can pause automatic processing in the private application.
The application server retains bounded headers, classification results, derived dates, internal references and processing checkpoints. Saved classifications are reused for later retention checks; the organizer does not keep message bodies or an attachment archive. A preview may analyze a small sample and save its result without changing source mail. Appointment downloads contain a calendar file for the owner to review and import; they do not grant access to a calendar account.
A separately requested briefing sends selected account labels, senders, subjects, dates and bounded plain email text to Google through Agy for summarization. Briefing inputs also exclude attachments and encrypted message bodies. Ordinary inbox browsing and local invoice-document extraction do not invoke an AI service.
Agy may retain provider state or transcripts in its separate profile on the application server. Google's handling of information sent to its services also depends on the applicable Google terms, account settings and Google Privacy Policy. Device read-aloud uses the voices or speech service available on that device.
Storage, access and retention
Mailbox credentials, OAuth client secrets, access and refresh tokens, saved label data, classification payloads and invoice records are encrypted at rest on the application server. The processing database also indexes scheduling state and due times, with protected lookup tokens for labels and account identities. The server holds the key needed to use encrypted data. The current private deployment uses Tailscale and an authenticated session for application access.
Temporary browsing references and application briefing results remain in server memory for up to 15 minutes and are cleared on restart. Saved labels, classification history, processing checkpoints, invoice queues and history, credentials and Drive retry records persist until changed or removed by the owner. These local records do not have an automatic time-based deletion period, even when the corresponding source email is archived or moved to Trash. Separate Agy profile data and server backups require their own owner-managed cleanup.
The private web app uses an essential session cookie and may cache static assets for installation. Its service worker does not cache email content or authenticated API responses. MailHarbor does not use mailbox or Drive data for advertising or sell that data.
Disconnecting and deleting data
The owner can pause automatic mail organization, disable automatic invoice scanning and disconnect mailbox or Drive connections in Accounts. Disconnecting Drive removes its local connection tokens while retaining registration settings, filing history and retry metadata. Existing files remain in Google Drive, where the owner can manage or delete them. Google access can also be withdrawn through the owner's Google Account settings.
Disconnecting a mailbox removes its saved connection; it does not erase retained label, classification, processing or invoice history. To request deletion of locally saved records, registration data, Agy profile data or relevant backups, contact the maintainer at info@smetsoftwaresolutions.be. The owner handles this through server administration. Deleting local data does not automatically delete source mail or copies held by Google.
These public pages
The public MailHarbor overview records page visits and contact-link clicks in page memory only. These events contain no form values, are not saved in cookies or browser storage, and are not sent to an analytics service. The public pages contain no forms or remotely loaded assets. Hosting and network infrastructure receive the ordinary request information needed to deliver a page. Contact by email is handled through the email service used by the sender and maintainer.
Contact and updates
Questions about this notice or MailHarbor data handling can be sent to Smet Software Solutions at info@smetsoftwaresolutions.be. Changes to this notice will be published here with an updated date.