openid, email
- 사용 목적
- 로그인과 계정 확인
- 실제로 하는 일
- Google이 확인한 이메일 주소와 계정 식별값(sub)을 받아 MailPip 계정과 연결합니다.
- 하지 않는 일
- 비밀번호를 받지 않습니다.
이 문서는 법무 확인 전 초안이며 게시용이 아닙니다. This document is a draft pending legal review and is not final.
노란 표시의 "확인 필요" 항목은 게시 전에 채워야 합니다. Items marked "to be confirmed" must be completed before publication.
MailPip은 Gmail에서 보낸 메일의 수신자별 열람 신호를 보여 주는 Chrome 확장과 웹 서비스입니다. 이 문서는 MailPip이 어떤 정보에 접근하고, 무엇을 서버에 보관하며, 어떻게 삭제하는지 설명합니다.
안내 사이트는 https://mailpip.app 입니다. 로그인 후 쓰는 웹 앱과 API는 현재 approxup.com 아래의 주소에서 제공되며 확인 필요: 운영 이전 뒤 주소, 메일에 들어가는 추적 이미지도 approxup.com에서 제공됩니다.
MailPip은 Google 로그인 때 아래 권한을 한 번에 요청합니다. 계정 비밀번호는 받지 않습니다.
openid, emailhttps://mail.google.com/ (Gmail 전체 메일)https://www.googleapis.com/auth/gmail.settings.basic (Gmail 기본 설정)list:(self-copy.mailpip.approxup.com)이고 동작은 받은편지함 건너뛰기, 읽음 표시, 위 라벨 적용입니다. 필터 목록은 같은 필터가 이미 있는지 확인하는 데만 읽고 저장하지 않으며, 연결 해제와 계정 삭제 때 이 필터를 지웁니다.확장이 Gmail 화면에서 MailPip 서버로 보내는 정보는 사용자가 보내려는 메일의 발신 주소, 수신자, 제목, 본문, 첨부, 시간대 오프셋, 요청 식별값, 답장이나 전달일 때 원본 메시지의 Message-ID와 References 헤더 값뿐입니다. 서버는 정해진 항목 외의 입력을 거절합니다.
| 정보 | 목적 | 보관 방식과 기간 |
|---|---|---|
| Google 계정 식별값(sub), 확인된 이메일, 약관 동의 버전과 시각 | 계정 식별, 약관 동의 기록 | 계정을 삭제할 때까지 보관하고, 삭제하면 지웁니다. |
| Gmail 접근용 refresh token | 사용자를 대신한 발송 | AES-256-GCM으로 암호화해 저장합니다. 연결 해제나 계정 삭제 때 지우고 Google에 폐기를 요청하며, Google이 권한을 철회한 것이 확인되면 암호문을 비웁니다. access token은 저장하지 않습니다. |
| 작성 원문(본문, 인라인 이미지)과 첨부 | 발송 완료까지의 임시 보관 | 객체마다 다른 키로 암호화한 임시 보관소에 둡니다. 발송이 끝나면 곧바로 지웁니다. 발송에 쓰이지 않은 업로드는 마지막 사용 15분 뒤(최대 24시간)에, 발송 접수 뒤 멈춘 작업의 원문은 1시간 안에 지우며, 내용이 없는 삭제 기록은 24시간 뒤 지웁니다. |
| 메시지 정보(제목, 수신자 주소와 역할, 발신 주소, 보낸 시각, 발송 상태, 원문 SHA-256) | 보낸 메일 목록과 열람 신호 표시 | 계정을 삭제할 때까지 보관합니다. 본문과 첨부 원문은 포함하지 않습니다. 자동 삭제 기한은 아직 정하지 않았습니다 확인 필요: 자동 보관·정리 범위. |
| 열람 신호 기록(수신자별 식별값, 신호 시각, 요청 출처 분류값) | 수신자별 열람 신호 표시 | 추적 이미지는 발급 후 7일이 지나면 더 이상 신호를 기록하지 않습니다. 기록은 계정을 삭제할 때까지 보관합니다. MailPip 수집기는 수신자의 IP 주소와 User-Agent를 출처 분류 계산에만 쓰고 저장하거나 로그에 남기지 않습니다. |
| 계정, 세션, 확장 연결 정보 | 로그인 유지와 확장 연결 | 비밀값은 원문 없이 해시만 저장합니다. 웹 세션은 최대 8시간, 확장 인증값은 한 세대 30일(24시간마다 회전하며 쓰지 않으면 만료), 확장 연결용 1회용 코드는 120초, 로그인 진행 기록은 10분 동안 유효합니다. 만료된 기록의 자동 정리 범위는 정하는 중입니다 확인 필요: 자동 보관·정리 범위. |
| 서버 로그 | 장애 대응 | API는 접근 로그를 남기지 않고, 수집기와 API의 오류 로그는 고정 문구만 남깁니다(주소, 제목, 본문, 토큰 없음). 호스팅 제공자와 네트워크 계층의 연결 로그는 확인 필요: 보관 여부와 기간. |
MailPip's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
위 문장은 Google이 요구하는 영문 고지 문구입니다. 출처는 Google의 restricted scope 검증 안내와 위 정책 문서이며 확인 필요: 게시 전 현행 공식 문구와 글자 대조.
MailPip은 Google 사용자 데이터를 사용자에게 보이는 기능(발송, 열람 신호 표시, 보호 확인)을 제공하고 개선하는 데만 쓰며, 광고 게재나 광고 분석에 쓰지 않고, 일반 AI/ML 모델의 개발이나 학습에 쓰지 않으며, 판매하지 않습니다.
MailPip 운영자는 다음 경우를 빼고 Google 사용자 데이터(메일 내용, 수신자, 제목 등)를 사람이 읽지 않습니다. 첫째 사용자가 구체적으로 요청하거나 동의한 경우, 둘째 악용 조사 등 보안상 필요한 경우, 셋째 법령을 지키기 위해 필요한 경우, 넷째 개인을 알아볼 수 없게 집계하거나 익명화해 서비스 운영에 쓰는 경우입니다. 이 약속을 뒷받침하는 내부 접근 절차는 확인 필요: 운영 절차.
MailPip 사용자가 보낸 메일에는 수신자 전용 추적 이미지가 들어 있을 수 있습니다. 메일 앱이 이 이미지를 불러오면 approxup.com 서버가 요청이 왔다는 사실과 시각을 기록합니다. MailPip은 수신자의 IP 주소와 브라우저 정보를 저장하지 않습니다(호스팅 계층의 연결 로그는 4절의 서버 로그 항목을 참고하십시오). 이 요청이 사람의 열람인지 메일 앱이나 보안 검사의 자동 요청인지는 확정할 수 없어 "열람 신호"로만 표시합니다. 메일 앱에서 원격 이미지 불러오기를 끄면 이 신호가 생기지 않습니다. 문의는 확인 필요: 문의 이메일로 받습니다.
서버가 대한민국 밖에 있는 경우 개인정보의 국외 이전 해당 여부와 고지 항목은 확인 필요: 이전 확정과 서버 위치에서 정합니다. 만 14세 미만 아동에 관한 문구는 확인 필요: 법무 검토.
방침을 바꾸면 이 페이지의 버전과 시행일을 바꾸고, 웹 앱이 동의를 받을 때 기록하는 약관 버전과 맞춥니다.
MailPip is a Chrome extension and web service that shows per-recipient open signals for emails you send from Gmail. This document explains which information MailPip accesses, what it keeps on its servers, and how you can delete it.
The information site is https://mailpip.app. The signed-in web app and API are currently served from a subdomain of approxup.com To be confirmed: address after the production move, and the tracking image inside emails is also served from approxup.com.
MailPip requests the permissions below together when you sign in with Google. It never receives your account password.
openid, emailhttps://mail.google.com/ (full Gmail access)https://www.googleapis.com/auth/gmail.settings.basic (Gmail basic settings)list:(self-copy.mailpip.approxup.com), and the actions are skip the inbox, mark as read and apply the label above. MailPip reads the filter list only to check whether its own filter already exists and does not store it, and deletes the filter when you disconnect or delete your account.The only information the extension sends from the Gmail page to the MailPip server is the sender address, recipients, subject, body and attachments of the message you are sending, your time zone offset, request identifiers, and, for replies and forwards, the Message-ID and References header values of the original message. The server rejects any other input.
| Information | Purpose | How it is kept, and for how long |
|---|---|---|
| Google account identifier (sub), verified email, terms version and acceptance time | Account identification and a record of terms acceptance | Kept until you delete your account, then deleted. |
| Refresh token for Gmail access | Sending on your behalf | Stored encrypted with AES-256-GCM. Deleted, and revocation requested from Google, when you disconnect or delete your account. If Google reports that you have withdrawn the permission, the ciphertext is cleared. Access tokens are not stored. |
| Message content as composed (body, inline images) and attachments | Temporary holding until sending finishes | Held in a temporary store encrypted with a different key per object. Deleted immediately once sending finishes. Uploads that are not used for sending are deleted 15 minutes after last use (24 hours at most), content of a job that stalls after being accepted is deleted within 1 hour, and the content-free deletion record is removed after 24 hours. |
| Message information (subject, recipient addresses and roles, sender address, send time, send status, SHA-256 of the original) | Showing your sent-mail list and open signals | Kept until you delete your account. It does not include the body or attachment content. No automatic deletion period has been set yet To be confirmed: automatic retention and cleanup scope. |
| Open signal records (per-recipient identifier, signal time, request-source classification) | Showing per-recipient open signals | A tracking image stops recording signals 7 days after it is issued. Records are kept until you delete your account. The MailPip collector uses the recipient's IP address and User-Agent only to compute the classification and neither stores nor logs them. |
| Account, session and extension connection data | Keeping you signed in and connecting the extension | Secret values are stored only as hashes, never as the original. A web session is valid for at most 8 hours, an extension credential generation for 30 days (rotated every 24 hours and expiring if unused), the one-time extension link code for 120 seconds, and a sign-in attempt record for 10 minutes. The scope of automatic cleanup of expired records is still being decided To be confirmed: automatic retention and cleanup scope. |
| Server logs | Troubleshooting | The API keeps no access log, and error logs from the collector and API contain only fixed messages (no addresses, subjects, bodies or tokens). Connection logs kept by the hosting provider and network layer: To be confirmed: whether they are kept and for how long. |
MailPip's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
This is the disclosure statement Google requires. Sources are Google's restricted scope verification guidance and the policy above. To be confirmed: compare word for word with the current official text before publication.
MailPip uses Google user data only to provide and improve the user-facing features (sending, showing open signals, protection checks). It does not use it for serving or analyzing advertisements, does not use it to develop or train generalized AI or ML models, and does not sell it.
MailPip operators do not read Google user data (message content, recipients, subjects and so on) except in these cases. First, when you specifically ask or consent. Second, when necessary for security, such as investigating abuse. Third, when necessary to comply with law. Fourth, when the data is aggregated or anonymized so that no individual can be identified and used to operate the service. The internal access procedure that backs this commitment is To be confirmed: operating procedure.
Emails sent by MailPip users may contain a tracking image unique to each recipient. When a mail app loads this image, the approxup.com server records that a request arrived and when. MailPip does not store the recipient's IP address or browser information (see the server logs row in section 4 for connection logs kept at the hosting layer). It cannot tell whether a request is a person opening the email or an automatic request from a mail app or security scan, so it shows only an "open signal". If you turn off loading of remote images in your mail app, no such signal is generated. Questions can be sent to To be confirmed: contact email.
If servers are located outside the Republic of Korea, whether an international transfer of personal information applies and what must be disclosed will be settled under To be confirmed: move and server location. Wording about children under 14 is To be confirmed: legal review.
When this policy changes, the version and effective date on this page change too and are matched to the terms version the web app records when it asks for your consent.