Privacy Policy
Effective April 12, 2026
This Privacy Policy describes how Fwalla ("Fwalla," "we," "us") collects, uses, stores, and protects information when you use the Fwalla service at fwalla.com (the "Service").
Fwalla is operated as an individual developer project. The data controller is the individual operator of Fwalla and can be reached at support@fwalla.com.
1. Information we collect
We collect only what is needed to operate the Service:
- Account information. When you sign in with Google, we receive your Google account ID, email address, verified-email flag, and display name (from the
openid,email, andprofilescopes). We store these to identify your Fwalla account. - Gmail account connection. When you connect a Gmail mailbox for sending, we receive a refresh token scoped to
https://www.googleapis.com/auth/gmail.compose. This token lets Fwalla create and send emails on your behalf from that mailbox. It does not grant any access to read your inbox, sent folder, labels, or any other mailbox contents. - Messages you compose. The recipient name, email, company, subject, body, and attachments you enter into Fwalla are stored so the Service can send or schedule the message.
- Sending metadata. Timestamps, status, provider message IDs, and send-attempt outcomes for each message you queue through Fwalla.
- Usage and security logs. IP address, user agent, request timestamps, and audit entries for security and abuse prevention.
2. How we use your information
- To authenticate you and maintain your session.
- To compose, schedule, and send the emails you explicitly queue through the Service, using the connected Gmail mailbox you chose.
- To operate safety features such as daily send caps, rate limits, and kill switches.
- To provide audit trails and diagnose support issues.
- To detect and prevent abuse of the Service.
We do not use your data to train machine-learning models, serve advertising, or develop features unrelated to the Service.
3. Google API Services User Data Policy — Limited Use disclosure
Fwalla's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data to provide or improve user-facing features that are prominent in the Fwalla user interface.
- We do not transfer Google user data except as necessary to provide or improve user-facing features.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless (a) you have given explicit consent for specific messages, (b) it is necessary for security purposes, (c) it is necessary to comply with applicable law, or (d) the data is aggregated and used for internal operations in compliance with applicable policies.
4. Storage, security, and retention
- Encryption in transit. All traffic between your browser and Fwalla uses TLS 1.2+.
- Encryption at rest. Gmail refresh tokens are stored using envelope encryption (per-row AES-256-GCM data key, wrapped by a key-encryption key held in a managed key service).
- Retention. Messages you compose are retained in Fwalla for up to 12 months after sending or cancellation so you can audit your own outreach history; after that they may be purged. Audit logs are retained for up to 24 months. You may delete your account at any time (see Section 7), which triggers deletion of all associated data.
- Access. Access to production data is restricted to the Fwalla operator for purposes of operating and maintaining the Service. We never read the contents of your emails except as required to render, send, or debug a message you explicitly queued.
5. Sharing
We do not sell your data. We share data only with:
- Infrastructure providers that host Fwalla (hosting, managed database, managed key service). These providers process data solely on our behalf under their own security commitments.
- Google, when Fwalla sends an email on your behalf through the Gmail API using the mailbox you connected.
- Law enforcement, where required by valid legal process.
6. International users
Fwalla is operated from the United States. If you use the Service from outside the United States, your data will be processed in the United States. We apply the same protections to data from all users regardless of origin.
7. Your rights and how to exercise them
- Access, export, correction. Email support@fwalla.com and we will respond within 30 days.
- Deletion. You may disconnect any Gmail mailbox from the Service at any time from the "Accounts" page, which deletes its stored refresh token. You may request full deletion of your Fwalla account by emailing support@fwalla.com. We will delete your account and all associated data within 30 days.
- Revoke Google access directly. You can revoke Fwalla's access to your Google account at any time via myaccount.google.com/permissions. Revocation from Google stops all further sending from that mailbox immediately.
8. Children's privacy
Fwalla is not directed to children under 13, and we do not knowingly collect data from children under 13. If you believe a child has provided us with personal information, contact support@fwalla.com and we will delete it.
9. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify you by email and/or in-app notice before the change takes effect. The "Effective" date at the top of this page reflects the current version.
10. Contact
For any privacy question or request, email support@fwalla.com.