Privacy Policy
Your privacy is important to us. It is our policy to respect your privacy regarding any information we may collect from you across our website, https://leavemealone.com, and any other sites we own and operate.
1. Personal information
We only ask for personal information when we truly need it to provide the service to you. We collect it by fair and lawful means, with your knowledge and consent. We also let you know why we're collecting it and how it will be used.
We only retain collected information for as long as necessary to provide you with your requested service. What data we store, we protect within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use or modification.
You are free to refuse our request for your personal information, with the understanding that we may be unable to provide you with some or all of our service.
All personal records, including your keys, email metadata The information around an email rather than the message itself. Who it came from, who it was sent to, the subject line, and when it arrived. It does not include the body of the email. , and any email content, is encrypted at rest Scrambled while it's stored, so the data is unreadable to anyone who got hold of the raw database files without also having our keys. in our database.
2. GDPR
If you are an EU resident then you have the right at any time to request all the personal information we have for you as dictated by the General Data Protection Regulation (GDPR). Under the same regulation, we will also delete any or all of this information at your request.
If you are not an EU resident then we will still provide this information to you if you ask for it, because we believe you should have these rights regardless of where in the world you live.
You can also delete your account yourself from our settings page. That happens immediately. Your mail data, your connected accounts and their credentials, your Rollups, Screener data, and your user record are all removed there and then, we log you out of every device, and you won't be able to sign in again.
Three things outlast that, and we'd rather name them than let "delete" imply a clean wipe:
-
A copy of your user record is kept for 3 days in case a deletion turns out to be a mistake or needs looking into. After that it's destroyed.
-
Our database backups are the one thing we can't reach into. They're encrypted, and they're kept for a maximum of 90 days. If you were in our system when a backup was taken, your data stays in that backup until it's deleted along with it.
-
If you had Spam Blocker turned on, samples of your mail collected to train our classifiers are deleted on their own schedule rather than with your account. That's explained under AI and automated processing.
3. The Service
a. Retrieving email data
In order to present a list of your mailing lists, we fetch your email data from your email provider and parse it into a localized format.
i. Gmail or Google Workspace
When you connect your Gmail or Google Workspace (formerly G Suite) account to the service we need the following OAuth scope A specific permission you grant us when you connect a mailbox, without ever giving us your password. Each scope allows one narrow thing, you can see the full list before you agree, and you can revoke them at any time from your email provider. :
-
gmail.modify - allows us to view and modify but not delete your email.
- View - We use this scope to search mailing list emails in your inbox and display their metadata to you. If you use our Rollups feature, we also use this scope to retrieve the content of emails for your Rollup. If you use our Screener feature, we fetch metadata of all senders who email you.
- Modify - We use this to move emails to a specified folder (if enabled). We do not create or send emails, and we cannot delete your mail.
-
gmail.settings.basic - allows us to manage basic mail settings.
- Filters - We use this scope to create filters for emails we cannot unsubscribe from, to move them out of your inbox automatically. We don't retrieve any settings data other than the filters we create.
You can view your Google App permissions or revoke access to Leave Me Alone at any time here
ii. Outlook/Exchange/Office365
When you connect your Outlook, Exchange, or Office365 account to the service then we need the following OAuth scopes:
-
Mail.ReadWrite - allows us to view and modify your emails.
- View - We use this to identify subscription emails and display them to you.
- Modify - We use this to move emails to a specified folder (if enabled). We do not create or send emails, and we cannot delete your mail.
iii. Yahoo
When you connect your Yahoo account to the service then we need the following OAuth scopes:
-
mail-r - allows us to read your mail.
- We use this to identify subscription emails and display them to you, and to fetch content for the Rollups and Screener features if you have them turned on.
-
mail-w - allows us to modify your mail.
- We use this to move emails to a specified folder (if enabled). We do not create or send emails, and we cannot delete your mail.
-
openid - allows us to identify your account.
- We use this to know which Yahoo account you have connected. We never see or store your Yahoo password.
iv. Other/IMAP
When you connect your IMAP account to the service we do not need any extra permissions.
b. Storing email data
i. Unsubscribing
For users only using the service to unsubscribe, we store metadata of the emails that we find in order to sync unsubscribes between devices. This includes the email envelope (to and from addresses), so that we can identify if you have unsubscribed from a subscription previously.
We do not store any content, or other information of these emails and if you delete your account this information is deleted irrevocably.
Some senders only accept unsubscribes by email. For those we send a formal unsubscribe and data removal request on your behalf, which names your email address and asks them to remove it under your data protection rights. It goes from our own address, not yours, so replies come to us rather than landing back in your inbox. The sender already has your address, since they've been emailing you with it.
We are dedicated to upholding the privacy of your information and agree to never do anything with this email metadata except provide you an excellent service through this website.
ii. Rollups
For our Rollups feature, when you add an email sender to a Rollup (and that Rollup is enabled), we fetch the content for emails that you have received from that sender in the last 7 days (maximum).
Until the Rollup is disabled, deleted, or the sender is removed, we fetch and store the content of emails that you receive from that sender, as you receive them into your connected email account(s).
This email content is only used to build your Rollup, and is retained should you wish to view the Rollup at a later date. It is not used for any other purpose than to provide you with the Rollups service.
As part of the Rollups process we only fetch content from the senders you have added to a Rollup. No other sender in your mailbox is touched by it, and all email content is encrypted at rest in our database.
Three months after a Rollup is sent to you, any metadata, images, or contents associated with the Rollup are removed from our servers, with the exception of email counts and statistics.
If you delete your account, delete the Rollup, or remove a sender from the Rollup, then any email content or metadata we store related to the Rollup or the sender is deleted permanently.
iii. Screener
The Screener watches mail as it arrives so you can decide who's allowed to reach you. For this to work we fetch metadata of each sender who emails you live as the email is received.
The metadata includes to and from email addresses, subject line, dates and counts of how many times that sender has emailed you since you enabled the functionality.
If the Screener feature is disabled, this metadata is retained (along with the action you asked us to perform on this sender), in case you would like to re-enable it in the future.
iv. Spam Blocker
When enabled the Spam Blocker watches mail as it arrives in your inbox, determines which emails are spam, and then moves those emails out of your inbox. To do this it needs the body text of the emails, and not just the metadata. In some instances the only way to identify spam is to match the content against other known spam emails.
The classifiers we use to identify spam are owned by us, and processed by our own spam detection engine.
To improve the spam classification for everyone, we sometimes retain a corpus of spam emails to use for further training. This is explained further in the AI and automated processing section.
The Spam Blocker is turned off unless you turn it on. Turn it off and we stop reading the content of your incoming mail for it. We will never read email content without your permission.
v. Priority senders, Do-Not-Disturb schedules, and snoozing
These features change when mail reaches you rather than whether it does. Each one works using email metadata:
- Priority senders; a list of senders you've marked as always important, so their mail always hits your inbox. If you turn on the option to always let one-time passcodes through, we check the sender and subject line of incoming mail to spot login codes and let those through too.
- Do-Not-Disturb schedules; we hold mail that arrives during the hours you choose and release it afterwards. We store the schedule you set and the list of held messages until they're released.
- Snoozing and bulk actions; when you snooze a sender or action a batch of them from the Screener, we store which senders and what you asked us to do, so we can carry out the action at the right time.
If you've turned on our email digest, we email you a summary of what's been held. That digest contains sender names and subject lines from your own mailbox, sent to your own address.
You can read more about the above on our security page.
4. AI and automated processing
We use AI in a few places to save you time, mostly for summarising mail and working out what's junk.
We believe that AI should never be used as a stand-in for something that can be done without it, so we use it sparingly and with caution.
We also think with AI specifically, you deserve to know exactly where it runs, what it sees, and how it's being trained, so here's all of it.
a. What we use AI for
-
Rollup and Screener summaries. We send the sender names and subject lines of the emails in your Rollup or Screener digest so we can summarise them for you. We do not send the body of those emails. This is on by default and you can turn it off with the "summarise with AI" setting.
-
Spam and cold email classification. If you have Spam Blocker turned on, we sample some incoming mail to improve the classifier over time and keep up with changing spam trends.
This sample includes the sender, the subject line, and a truncated portion of the email content. This is sent to our AI model to be classified.
-
The Unsubscriber. When we unsubscribe you from something that has no simple unsubscribe link, an AI agent works through the sender's unsubscribe page on your behalf. It reads the content of that page, takes screenshots of it, and where the form asks for it, types in your email address. That is the address the sender already has, and is the most effective way an unsubscribe can be completed.
b. The AI models we use for this
We use open-weight model An AI model whose weights (the trained 'brain' of it) are published for anyone to download and run. Because we run it on our own rented machines, nothing we send it leaves our infrastructure, and there's no AI company on the other end to collect it or learn from it. , hosted by our main infrastructure provider DigitalOcean. We do not use any private AI companies (such as OpenAI or Anthropic) to classify emails or create summaries.
This way we can ensure no email data is every used for training proprietry AI models, and that all your data is kept within our infrastrcuture.
c. AI and customer support
Our customer support is run by humans, but because we're a small team our humans sometimes need a little help from AI.
In these cases we use Anthropic's Claude to help us out. When you email us, the content of your message and the address you sent it from may be processed by Anthropic as part of that. If you'd rather your support conversation never touched an AI model, say so in your email subject and it will only ever be seen by a human.
d. Training our own classifiers
We use real email content to train our own spam and cold email classifiers. This is the part people most want to know about, so to be completely clear:
- This only happens if you have Spam Blocker turned on. It is off unless you turn it on, and turning it off stops it.
- What's stored is the message itself, compressed and encrypted with AES-256 A very strong, widely used encryption standard. The 256 refers to the size of the key needed to unscramble the data. It's the same class of encryption used by banks and governments, and it is not realistically breakable by guessing. on our own infrastructure.
- It is used to improve our own classification, and nothing else. We do not sell it, we do not share it, and we do not hand it to any AI company to train their models on.
- Samples are deleted automatically after a limited period. It's a rolling window, not a permanent archive.
- Deleting your account doesn't immediately remove samples already collected from your mail. They're deleted when that window expires. If you'd like them gone sooner, email us and we'll remove them by hand.
e. What AI never does
As stated, we utilise AI in a very restricted and controlled manner.
AI models will never get access to your mailbox. They don't get your credentials, your OAuth tokens, or the ability to read, send, or delete your mail. AI will only ever see the specific text we send them, for the specific tasks described above.
5. Third parties
We don't sell user data, and we don't share it publicly or with anyone except the companies listed below, or when required to by law. To date no legal request has ever been made.
Some of the companies below do receive personal data, because they can't do their job without it.
a. Running the service
-
DigitalOcean - our infrastructure. Servers, object storage, background functions, and the AI gateway described above. In practice this means everything we store sits on DigitalOcean, including some storage in the United States.
-
Google - beyond being a mailbox provider, we use Google for a few specific jobs: Document AI to find and redact personal information in unsubscribe screenshots (processed in the United States), Web Risk to check whether an unsubscribe link is dangerous before we visit it, Pub/Sub to receive new mail notifications, and OAuth to sign you in. Google Ads is covered under Cookies and advertising below.
-
Mailgun - sends and receives our email. This includes your Rollup and Screener emails, so Mailgun handles the content of the mail inside them on its way to your inbox. Our Private Emails feature is also routed via Mailgun.
-
Backblaze B2 - stores our database backups. Those backups are encrypted and kept for a maximum of 90 days.
b. Support
-
Missive - our support inbox. Receives your email address, the full content of your ticket and any files you attach, and which plan you're on so we can help you properly.
-
Anthropic - AI models, as described above. Sometimes receives the content of support conversations.
c. Payments and licensing
-
Stripe - card payments.
-
Google Play Billing - purchases made through our Android app.
-
AppSumo, Setapp, and Mailbird - if you came to us through one of these, they handle your sign-in and confirm your licence is valid. Setapp also receives a regular check that your subscription is still active.
-
Yahoo - sign-in, if you connect a Yahoo mailbox.
d. Analytics and monitoring
-
Simple Analytics - EU Data Residency only - page view analytics for our website. Privacy-first by design, no cookies, and we proxy it through our own domain.
-
Mixpanel - EU Data Residency only - product analytics, so we can see which features get used. This one does receive personal data: when you sign up we send the mail provider your address points at, so we know which providers to support.
-
Datadog - EU Data Residency only - server monitoring and error tracking. Our Android app also sends Datadog usage data about how the app itself is performing and being used.
e. Unsubscribing on your behalf
We occasionally route unsubscribe requests through third-party proxy networks. The unsubscribe link and the pages it leads to pass through those networks.
f. What we host ourselves
A lot of things a company our size would normally outsource, we run on our own servers instead. Our spam engine, our marketing email, and our team chat are all self-hosted, so no other company sees the data behind them. All of this is a deliberate choice rather than an accident.
We have ensured that the respective privacy policies of all the companies above align with our own values.
6. Cookies and advertising
We don't run any third-party advertising or tracking scripts on our website. No Facebook pixel, no ad network tags, nothing following you around the internet.
We do set one first-party cookie, called lma_attr. If you arrive from one of our Google ads, it stores the click ID from that ad along with any campaign parameters in the link. It lasts 90 days, it's only readable by our own servers, and it contains nothing about you personally.
If you then buy a subscription, we tell Google Ads that the click resulted in a purchase, along with the value. That upload includes your email address as a SHA-256 hash A one-way scramble of a piece of text into a fixed string of characters. The same input always gives the same output, but the output can't be turned back into the original. It lets a platform check whether two people match without either side handing over the actual address. rather than the address itself, which is how Google matches the conversion up without us handing the address over.
Beyond that we use ordinary cookies to keep you logged in, which are necessary for the service to work at all.
7. How long we keep things
The short version is that we keep data for as long as we need it to run the service for you, and no longer. The specific windows worth knowing:
- Accounts that are never verified are deleted after 7 days.
- Deleting your account happens immediately. A copy of your user record is kept for 3 days, as described under the GDPR section above.
- Rollup email content goes back a maximum of 7 days when you first add a sender, and is removed 3 months after the Rollup is sent to you.
- The lma_attr cookie lasts 90 days.
- Backups are encrypted and kept for a maximum of 90 days.
- Statistics, such as counts of emails scanned or unsubscribed from, are kept indefinitely. They contain nothing that identifies you.
8. External sources
Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and practices of these sites, and cannot accept responsibility or liability for their respective privacy policies.
To provide the unsubscription service we take screenshots of the sender's unsubscribe page, so we can show you whether a particular unsubscribe actually worked. We have no control over what's on those pages and cannot accept responsibility or liability for their content.
These screenshots are taken by our system. They're pictures of a third party's web page that our own service captured, and we use them to check that unsubscribes are working and to improve the service.
We use some of these images to improve our system and to help other visitors get through the unsubscribe process. We never disclose personal information from these images. Before they're stored, they're processed by Google's Document AI to detect and redact personal information that appears in them.
If you'd like us to remove a specific screenshot from our systems, let us know and we will.
To provide the Rollup service, we store and display email content that has been sent to you from an external source. This email content may contain images and hyperlinks that direct you to external websites. We are only displaying this information as it was received into your inbox, and cannot accept responsibility or liability for it's content, or any content of linked websites.
9. Open Startup statistics
We collect statistical information such as the total quantity of emails we have scanned and the total number of subscriptions that have been unsubscribed from. As well as various financial details.
This data does not contain any personal identifying information and is only stored as counts or percentages.
We periodically share this information publicly with our followers on social media for the sole purpose of documenting and sharing our successes and failures as an "open startup", for the benefit of others and to keep ourselves accountable.
We believe that by following these rules we can keep your data as safe as possible, but if you have any suggestions on how we can improve then let us know!
Your continued use of our website will be regarded as acceptance of our practices around privacy and personal information. If you have any questions about how we handle any of our data, feel free to contact us.
This policy was last updated on the 8th August 2026.
10. Previous versions:
For accountability we keep the old versions of our privacy policy around to view here.
