Privacy Policy

Effective August 9, 2026

AccountHound audits, cleans and secures your email account. Doing that job requires access to your mailbox — so this policy is deliberately specific about what we read, what we store, what we never touch, and how you take it all back.

The short version

  • We read message headers only — sender, subject, date, size and unsubscribe links. We never download message bodies or attachments.
  • We only scan folders you select. Anything unselected is off-limits.
  • Nothing is deleted, moved or unsubscribed without your explicit per-item approval.
  • We never sell your data, show ads, or use your data for marketing to others.
  • Disconnecting your mailbox deletes your credentials; you can delete all scanned data at any time.

What we access and store

When you connect a mailbox, AccountHound reads message headers from the folders you approve: the sender's name and address, subject line, date, message size, read status, and standard unsubscribe headers. From these we build your dashboard — sender census, category breakdown, account detection, and cleanup recommendations. This metadata is stored in our database, associated with your account, for as long as you keep your account.

Your mailbox credential (app password or OAuth token) is encrypted with AES-256-GCM before it is stored. It is decrypted only in memory at the moment we connect to your mail provider, is never shown in any interface, never written to logs, and never returned by any API.

What we never access

  • Message bodies and attachments — we do not fetch them, so we cannot store them.
  • Folders you have not selected. Sent, Drafts and Trash are excluded by default.
  • Your contacts, calendar, or any non-mail data.

Third-party processing

Anthropic (AI categorization). To sort your senders into categories (shopping, finance, travel, and so on), we send Anthropic's API a compact profile of each sender domain: the domain name, sender names and addresses seen for it, a handful of sample subject lines, and message counts. Anthropic does not train its models on this data. We cache results, so each sender is analyzed once — not once per email.

Have I Been Pwned (breach awareness). Breach information shown in AccountHound comes from the public Have I Been Pwned breach catalog (CC BY 4.0). We download the catalog and cross-reference it locallynone of your data is ever sent to Have I Been Pwned.

Your mail provider. We connect to your provider (e.g. Yahoo Mail) over encrypted IMAP using credentials you supply. We act only on your instructions, subject to your provider's terms.

We share data with no one else. We do not sell, rent, or trade your information.

Actions on your mailbox

AccountHound is read-only by default. Deleting messages, unsubscribing from senders, moving mail into archive folders — each action runs only after you have individually elected it. There is no bulk action we take on our own initiative.

Security

  • All connections to your mail provider and to our servers use TLS encryption.
  • Mailbox credentials are encrypted at rest (AES-256-GCM); the encryption key is held outside the database, so a database copy alone is useless.
  • Access to production systems is limited to what operating the service requires.

Deleting your data

  • Disconnect mailbox — immediately and permanently deletes your stored credential.
  • Delete account — removes your scanned metadata, elections, and account records from our database.

Changes

If this policy changes in a way that affects how your data is handled, we will show a notice in the product before the change takes effect. The effective date above always reflects the current version.

Contact

Questions about this policy or your data: support@accounthound.io

Breach data sourced from Have I Been Pwned, licensed under CC BY 4.0.