Privacy Policy

We copy mail between servers. We never keep the messages, we delete your mailbox passwords within a day, and you can take or erase your data at any time.

Last updated: 18 September 2026

Who is responsible

IMAP Migrator is the data controller for this service.

Privacy questions and requests: [email protected].

What we collect

  • Account: email address, password hash, language, two-step verification status and notification settings you choose.
  • Migrations: server addresses, mailbox addresses, folder names, message counts and an action log. Mailbox passwords are encrypted while a run is active and deleted within 24 hours after it ends, or, if you set up an ongoing sync, when that sync ends (30 days at most).
  • Message contents: not stored during a migration: messages pass through our server in memory on their way from the source to the target server. Only when you use the file tools do messages sit on our server for a short time: a PST or MBOX file you upload for import, and the MBOX archive of an export, both kept in a private directory that only the service can read, and deleted as listed below.
  • Payments: amount, date, plan, payment reference and billing email. Card and PayPal details are handled by Stripe and PayPal; we never see them.
  • Sign-ins: IP address, browser and time, to protect your account.
  • Support: the messages you send us.

Why we use it

  • To provide the service you signed up for (contract, UK GDPR art. 6(1)(b)).
  • To keep invoices as tax law requires (legal obligation, art. 6(1)(c)).
  • To keep accounts secure, prevent abuse and send service emails such as receipts and expiry reminders (legitimate interests, art. 6(1)(f)).
  • To send at most one reminder when you leave checkout or check mailboxes without starting (legitimate interests; switch it off in Account → Notifications or with the link in the email).

We do not sell data, show ads, build marketing profiles or use your data to train AI models.

How long we keep it

DataKept for
Mailbox passwordsup to 24 hours after a run ends; for an ongoing sync, until it ends (30 days at most)
Uploaded PST/MBOX filesdeleted within 15 minutes after the import ends; unused uploads after 24 hours
MBOX export archives24 hours, then deleted
Detailed action logs90 days
Migration summaries and reports365 days
Sign-in history365 days
Unverified accounts30 days
Invoices6 years (UK tax law), also after account deletion
Everything elseuntil you delete your account

Who processes it for us

  • Cloudflare — network delivery and protection against attacks.
  • Stripe, PayPal — payments, only when you buy a plan.
  • Email provider — delivery of account and receipt emails.
  • Hosting provider — the servers that run the service.
  • Google, Microsoft — only if you connect a mailbox with their sign-in.

Where a provider handles data outside the UK, the transfer is covered by UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.

Cookies

We only use cookies that the site needs to work, so we do not ask for consent:

NamePurposeDuration
wmi_laravel_sessionkeeps you signed in7 days
XSRF-TOKENprotects forms against cross-site requests7 days
localeremembers your language1 year
__cf_bmCloudflare bot protection30 minutes

Your light/dark theme choice is stored in your browser only. PayPal sets its own cookies when you open its checkout. We use no analytics or advertising cookies.

Your rights

You can ask to access, correct, delete, restrict or port your data, and object to how we use it.

  • Download or delete everything yourself under Account → Privacy.
  • Or write to [email protected]. We reply within one month.
  • If you are unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.

Security

Traffic is encrypted with TLS. Credentials and API keys are encrypted at rest. Admin access requires two-step verification, and every admin action is logged.

Changes

If we change this policy in a way that matters, we will email account holders before it takes effect.