Last updated: 18 September 2026
Who is responsible
IMAP Migrator is the data controller for this service.
Privacy questions and requests: [email protected].
What we collect
- Account: email address, password hash, language, two-step verification status and notification settings you choose.
- Migrations: server addresses, mailbox addresses, folder names, message counts and an action log. Mailbox passwords are encrypted while a run is active and deleted within 24 hours after it ends, or, if you set up an ongoing sync, when that sync ends (30 days at most).
- Message contents: not stored during a migration: messages pass through our server in memory on their way from the source to the target server. Only when you use the file tools do messages sit on our server for a short time: a PST or MBOX file you upload for import, and the MBOX archive of an export, both kept in a private directory that only the service can read, and deleted as listed below.
- Payments: amount, date, plan, payment reference and billing email. Card and PayPal details are handled by Stripe and PayPal; we never see them.
- Sign-ins: IP address, browser and time, to protect your account.
- Support: the messages you send us.
Why we use it
- To provide the service you signed up for (contract, UK GDPR art. 6(1)(b)).
- To keep invoices as tax law requires (legal obligation, art. 6(1)(c)).
- To keep accounts secure, prevent abuse and send service emails such as receipts and expiry reminders (legitimate interests, art. 6(1)(f)).
- To send at most one reminder when you leave checkout or check mailboxes without starting (legitimate interests; switch it off in Account → Notifications or with the link in the email).
We do not sell data, show ads, build marketing profiles or use your data to train AI models.
How long we keep it
| Data | Kept for |
|---|---|
| Mailbox passwords | up to 24 hours after a run ends; for an ongoing sync, until it ends (30 days at most) |
| Uploaded PST/MBOX files | deleted within 15 minutes after the import ends; unused uploads after 24 hours |
| MBOX export archives | 24 hours, then deleted |
| Detailed action logs | 90 days |
| Migration summaries and reports | 365 days |
| Sign-in history | 365 days |
| Unverified accounts | 30 days |
| Invoices | 6 years (UK tax law), also after account deletion |
| Everything else | until you delete your account |
Who processes it for us
- Cloudflare — network delivery and protection against attacks.
- Stripe, PayPal — payments, only when you buy a plan.
- Email provider — delivery of account and receipt emails.
- Hosting provider — the servers that run the service.
- Google, Microsoft — only if you connect a mailbox with their sign-in.
Where a provider handles data outside the UK, the transfer is covered by UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.
Cookies
We only use cookies that the site needs to work, so we do not ask for consent:
| Name | Purpose | Duration |
|---|---|---|
| wmi_laravel_session | keeps you signed in | 7 days |
| XSRF-TOKEN | protects forms against cross-site requests | 7 days |
| locale | remembers your language | 1 year |
| __cf_bm | Cloudflare bot protection | 30 minutes |
Your light/dark theme choice is stored in your browser only. PayPal sets its own cookies when you open its checkout. We use no analytics or advertising cookies.
Your rights
You can ask to access, correct, delete, restrict or port your data, and object to how we use it.
- Download or delete everything yourself under Account → Privacy.
- Or write to [email protected]. We reply within one month.
- If you are unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.
Security
Traffic is encrypted with TLS. Credentials and API keys are encrypted at rest. Admin access requires two-step verification, and every admin action is logged.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect.