CATALOGUE

APPLICATION INFORMATION

Privacy notice

How Catalogue Distributor Mailbox handles the information in individually connected accounts.

Operator and purpose

Luke Michael Browning operates this private application for his own mailbox and distributor accounts. Mail access is used for distributor account operations, connection monitoring and supported account recovery. There is no public sign-up, advertising service or mailbox resale.

Information accessed and stored

When an account is connected, the application verifies its mailbox address and stores the credentials required for continued authorized access: OAuth credentials for Google and Microsoft, or a Hostinger mailbox password. It may read message identifiers, timestamps, sender and recipient headers, subjects and message content needed for its account operations.

Routine catchup targets recent mail, currently a 30-day window. Checkpoints, selected diagnostic evidence and account bindings can be retained separately. A limited recent-mail window is not a guarantee that every stored copy is automatically deleted after 30 days.

Credentials and mailbox data stay in protected server storage. Tokens, passwords and login codes are excluded from shared status responses. The private Catalogue interface receives account bindings, connection health and sync results rather than mailbox credentials or raw email.

Use and disclosure

Mailbox data is used only for the connected account’s requested functions. A login code, when an account’s verified recovery feature is enabled, is used only with the distributor challenge it matches. Reading email does not authorize sending email.

The application does not sell mailbox data, use it for advertising or use it to train generalized AI models. Human access to particular mailbox contents requires the owner’s affirmative agreement, except where necessary for security or applicable legal requirements. Normal monitoring uses connection health rather than message contents. Server infrastructure is provided by Hetzner; Google, Microsoft or Hostinger continue to process their own account data under their respective policies.

Google API data is used under the Google API Services User Data Policy, including its Limited Use requirements.

Protection, retention and removal

Provider connections use TLS. File permissions separate mailbox credentials from the distributor worker and public information pages. Administrators responsible for the server can access protected files for authorized maintenance; the application does not claim protection against its own server administrators.

Credentials are kept while needed for an authorized connection. Messages, checkpoints and diagnostic records remain subject to server cleanup and any retained backups. Revoking provider permission stops future authorized access but does not automatically erase previously stored server records.

You can review or revoke Google access through your Google Account connections. For disconnection, removal of stored data or questions about retention, contact the operator at luke.michael.browning@gmail.com.

Changes

This notice will be updated if the application’s data use changes. A future sending capability requires a separate owner decision and any additional provider consent before use.