Privacy Policy
Effective September 13, 2026. Spam Squirrel is operated by Prism Data Group, LLC ("we", "us").
The short version
- We read email headers (sender, date, subject line, List-Unsubscribe) to find unsubscribe mechanisms. We do not read, transmit, or store message bodies or attachments.
- We store a per-sender summary of your inbox, the actions you chose, their results, your safe-contacts list, and your subscription status.
- We do not sell, rent, or share your data with advertisers or data brokers. We have no advertising.
- Nothing is sent from your mailbox without your explicit choice and confirmation.
- You can delete everything by asking us at the address at the bottom of this page.
1. What we collect and why
Account identity. When you sign in with your mail provider (Microsoft or Google), or connect an iCloud mailbox with an app-specific password, we receive your email address and, where the provider supplies it, your display name. We use the address to identify your mailbox and bind all of your data to it. We check it with your mail provider on every request so no other user can reach your data.
Message headers. With your permission, the app reads up to 500 recent Inbox messages through your mail provider's interface, using only these fields: sender name and address, received date, subject line, and the List-Unsubscribe / List-Unsubscribe-Post headers. Message bodies and attachments are not requested.
Sender summary. From those headers we build and store one row per sender: address, display name, domain, message count, first and last seen dates, whether an unsubscribe mechanism exists, the unsubscribe URL or mailto address the sender published, our recommended action, and the action you chose. Subject lines are not stored.
Actions and results. For every action you apply, we store the sender, the method used, the time, whether it succeeded, and the response we received (for one-click unsubscribes, the HTTP status code returned by the sender's server). This is your audit trail.
Safe contacts. The addresses and domains you add to your allowlist.
Billing. Payment is handled by a PCI-compliant payment processor. We store the customer and subscription identifiers it issues, your plan, status, trial and renewal dates, and the number of unsubscribes used during a trial. We do not see or store card numbers.
Usage analytics. The public website uses Google Analytics to measure visits and which pages people read. This does not include anything from your mailbox.
2. Mail provider permissions and what we do with them
Microsoft accounts (Outlook.com, Hotmail, Live, Microsoft 365). Spam Squirrel requests these permissions. Each is used only for the purpose stated.
User.Read: confirm who you are on every request.Mail.Read: read the header fields listed above.Mail.Send: send an email from your mailbox only when you choose an action that requires one for a specific sender and click Apply. The current release sends one-click unsubscribes from our servers and does not use this permission; it is reserved for email-based actions in future releases.MailboxSettings.ReadWrite: create an Outlook inbox rule if you choose a Block action for a sender. Not offered in the current release; reserved for a future one.
You can revoke these permissions at any time at myapps.microsoft.com or through your organization's administrator. Revoking stops the app from accessing your mailbox immediately.
Google accounts (Gmail, Google Workspace). Spam Squirrel requests the Gmail metadata scope, which lets it list messages and read their headers and structurally cannot return message bodies, plus the send and basic-settings scopes reserved for actions in future releases. Spam Squirrel's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time at myaccount.google.com/permissions.
iCloud Mail. You provide an app-specific password generated in your Apple ID settings. We store it encrypted and use it only to read the header fields above over IMAP. Revoke it at any time from your Apple ID settings; we delete our copy when you disconnect the mailbox.
3. What we do not do
- We do not read, store, or analyze message bodies or attachments.
- We do not sell, rent, license, or share your data with advertisers, data brokers, or market-research companies.
- We do not use your data to train models or build products for third parties.
- We do not send anything from your mailbox automatically. Every send requires your per-sender choice and a click on Apply.
- We do not store your mail account password. Microsoft and Google sign-in happen on their own pages and we receive only a short-lived token. An iCloud app-specific password is stored encrypted and is not your Apple ID password.
4. Who processes your data
We use these service providers to run the product. Each receives only what it needs.
- Your mail provider (Microsoft, Google, or Apple: identity and mailbox access, under your own account's terms).
- A cloud application hosting provider (United States).
- A managed database provider (United States).
- A PCI-compliant payment processor (receives your email address and the payment details you enter directly on its checkout page).
- A transactional email provider (delivers service emails we send you, such as receipts).
- Google Analytics (website traffic measurement on public pages only; disclosed as Google's terms require).
When you choose an action, the sender's own systems receive your unsubscribe request and handle it under their own policies. If a future release lets you forward an email, it goes only to the recipient shown beside that action.
5. Where data is stored and international transfers
Our servers and database are in the United States. If you use Spam Squirrel from outside the United States, your data is transferred to and processed there. For users in the European Economic Area, United Kingdom, and Switzerland, we rely on our providers' standard contractual clauses and equivalent safeguards for those transfers.
6. How long we keep it
- Sender summaries, actions, and safe contacts: for as long as your account exists, so that repeat-offender tracking and your audit history keep working.
- Billing records: as long as required for tax and accounting purposes, typically seven years.
- Identity verification cache: five minutes.
- Everything else is deleted within 30 days of a deletion request.
7. Your rights
Wherever you live, you can ask us to show you the data we hold about you, correct it, export it, or delete it, and you can object to or restrict our processing. Residents of the EEA, UK, and Switzerland have these rights under the GDPR; California residents have them under the CCPA/CPRA, and we do not "sell" or "share" personal information as those laws define it. To exercise any right, email the address below from the mailbox you used to sign in. We respond within 30 days. You may also lodge a complaint with your local data-protection authority.
Deleting your account removes your sender summaries, actions, safe contacts, and subscription record from our database. It does not undo unsubscribe requests already sent, and it does not remove records our payment processor must keep for payment compliance.
8. Cookies and local storage
The app stores your sign-in session in your browser's local storage so you stay signed in; clearing site data signs you out. The public website sets Google Analytics cookies to measure traffic. We do not use advertising cookies.
9. Security
All traffic is encrypted in transit. Your identity is checked with your mail provider on every API request. Database access is restricted to the application with row-level security as a second barrier, and message bodies do not enter our systems. No method is perfect; if we learn of a breach affecting your data we will notify you without undue delay.
10. Children
Spam Squirrel is not directed to children under 16 and we do not knowingly collect their data. Work and school accounts are provided by organizations, which control eligibility.
11. Changes
We may change this policy at any time. Changes take effect when the updated policy is posted on this page with a new effective date. Posting here is notice to you; we may also announce changes in the app or by email, but are not required to. Your continued use of Spam Squirrel after a change is posted means you accept the updated policy.
12. Contact
Prism Data Group, LLC · privacy@prismdatagroup.com · prismdatagroup.com