Privacy Policy

Last updated: June 25, 2026

This Privacy Policy explains how Mizton (“Mizton,” “we,” “us”) collects, uses, stores, and shares information when you use Miztrace(the “Service”) — a tool that adds open- and click-tracking (“read receipts”) to emails you send from Gmail. By using the Service, you agree to this policy.

1. Information we collect

Account information

When you create an account we collect your name and email address. If you sign in with Google, we receive your basic Google profile (name, email address, and profile picture) to identify your account.

Gmail connection

If you choose to send campaigns, you connect a Google account and grant the gmail.send permission. We store an encrypted refresh token (encrypted at rest using AES-GCM) so we can send the messages you compose. We do not read, search, download, delete, or modify the contents of your mailbox.

Email tracking data

The core function of the Service is to tell you when an email you sent has been opened or its links clicked. To do this we embed a small tracking pixel and wrap links in the emails you send. When a recipient opens your email or clicks a link, we record:

We use IP address and user-agent only to distinguish real opens from automated loads and to show approximate context; we do not build advertising profiles from this data.

Content you create

We store the templates, signatures, campaigns, contact notes, categories, and uploaded media you create in the Service.

Billing information

If you subscribe to a paid plan, payments are processed by Stripe. We store your subscription status and Stripe customer identifier; we never receive or store your full card number.

2. How we use Google user data

We request the minimum Google permissions needed to provide the Service:

ScopeWhy we request it
openid / email / profileSign you in and show your name and email address in the app.
https://www.googleapis.com/auth/gmail.sendSend the campaign emails you compose, from your own Gmail address. This permission only sends mail — it cannot read, search, delete, or modify your inbox.

Signing in with Google is used for identity only and does not request access to your Gmail. Sending is a separate, optional step that you initiate from the dashboard.

3. Limited Use of Google user data

Miztrace's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, information received from Google APIs is used only to provide or improve user-facing features that are prominent in the Service’s interface (sending the emails you compose). We do not transfer or sell this data to third parties for advertising, market research, or other purposes, and humans do not read it except as necessary for security, to comply with law, or with your explicit consent. See the Google API Services User Data Policy.

4. How we use your information

5. How we share information

We do not sell your personal data. We share data only with the service providers (“sub-processors”) that help us run the Service, and only as needed:

ProviderPurposePrivacy policy
Google LLCGoogle Sign-In and sending campaign emails via the Gmail API.View
Convex, Inc.Application hosting, database, and serverless backend.View
Stripe, Inc.Subscription billing and payment processing.View
Resend (Plus Five Five, Inc.)Sending transactional emails such as alerts and digests.View

We may also disclose information if required by law or to protect the rights, safety, and security of our users and the Service.

6. Data retention

We keep your account and tracking data for as long as your account is active. You can delete tracked emails, campaigns, and other content at any time, which removes their associated open and click events. When you delete your account or disconnect Gmail, we delete or de-identify the associated data within a reasonable period, except where we must retain it to comply with legal obligations.

7. Security

We protect your data with industry-standard measures, including encryption in transit (HTTPS) and encryption at rest for sensitive secrets such as Gmail refresh tokens (AES-GCM). No method of transmission or storage is completely secure, but we work to protect your information.

8. Your rights and choices

If you are in the EU/UK, please also see our GDPR Policy for additional rights. For cookies, see our Cookie Policy.

9. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date above. Material changes will be communicated through the Service.

11. Contact us

Questions about this policy or your data? Contact us at privacy@miztrace.com.
Mizton, [Mizton mailing address — street, city, country].


This document is provided as a tailored template describing how Miztrace actually handles data. It is not legal advice; please have qualified counsel review it for your jurisdiction before relying on it.