Effective date: July 14, 2026
Last updated: July 14, 2026
Policy version: 2.2
1. Scope and identity
This Privacy Policy applies to PressedMail, pressedmail.com, PressedMail Free and Pro, the installed PressedMail WordPress plugin, customer accounts, purchases, licensing, updates, support, newsletters, and related services operated by CurbSoftware Tech Innovations ("CurbSoftware," "we," "us," or "our").
PressedMail is a WordPress email client. This policy covers both information handled by CurbSoftware-operated services and information processed by a customer's own WordPress installation. It does not replace the policies of Google, a customer's hosting provider, payment providers, or an optional AI provider selected by a customer.
2. Responsibility for information
CurbSoftware is responsible for personal information under its control through the PressedMail website, customer accounts, purchases, licensing, support, newsletters, and the PressedMail-operated OAuth relay.
A customer or organization operating a WordPress site normally controls the email accounts and mailbox information processed inside that PressedMail installation. CurbSoftware supplies the software, but the WordPress site owner determines which accounts are connected, who may use the mailbox, which local storage settings apply, and whether optional integrations are enabled. A person whose information appears in a customer's mailbox should normally contact that WordPress site owner about access, correction, export, or deletion of the mailbox information.
CurbSoftware's Privacy Officer is accountable for our privacy program and can be contacted at [email protected]. CurbSoftware Tech Innovations operates from British Columbia, Canada. A verified business mailing address will be provided in response to a legitimate privacy or regulatory request.
3. Information provided directly
Depending on the services used, we may receive:
- Name, email address, organization, login credentials and account preferences.
- Survey responses, newsletter subscriptions, marketing preferences and consent records.
- Contact-form and support messages, screenshots, logs and diagnostics a person chooses to provide.
- Purchase, billing and tax information described below.
- WordPress site details supplied for licensing, activation, updates or support.
Do not send mailbox content to support unless it is necessary for the support request and you are authorized to disclose it.
4. Website and customer-account information
Our website and account services may process IP address, browser and device type, operating system, referring page, timestamps, login and session records, cookie or local-storage identifiers, account activity, security events and approximate location inferred from IP address. We use this information to operate the site, authenticate users, remember preferences, measure consented website usage, prevent abuse and investigate security or reliability problems.
5. Licensing and plugin information
Depending on the edition and action, licensing and update services may receive a license key, plan, license status, WordPress site URL or domain, activation status, plugin version, WordPress version, PHP version and update-check information. These fields are required when needed to validate a Pro license, allocate site activations, provide licensed downloads or determine update compatibility.
PressedMail does not send mailbox content as licensing telemetry. Optional diagnostics are sent to CurbSoftware only when an administrator deliberately includes them in a support request or enables a separately disclosed diagnostic feature.
6. Payments
Payments may be processed by Stripe, BitCart, and crypto payment services or another payment provider shown at checkout. The provider handles full payment-card or wallet credentials under its own policy. CurbSoftware does not store full payment-card numbers.
We may receive and retain customer and transaction identifiers, billing name and address, payment status, tax information, currency and amount, invoice or receipt data, subscription status, limited card details such as brand and last four digits when supplied by the processor, or crypto wallet and network-confirmation details needed for reconciliation and refunds.
7. Mailbox information processed by the WordPress plugin
When a site owner or authorized user connects an email account, PressedMail may process the connected address, account settings, mailbox folders and labels, message headers and metadata, senders, recipients, dates, subjects, message bodies, conversation content, attachments, read or unread state, starred and other flags, drafts, sent messages, archive or trash state, search indexes and synchronization state. PressedMail processes only what is needed for enabled email-client features.
The plugin communicates directly from the customer-controlled WordPress site to the selected mail provider using IMAP and SMTP. Message bodies and attachments do not pass through the PressedMail OAuth relay. Mailbox metadata and synchronization state are stored in the customer's WordPress database. Depending on the user's email-body cache setting, sanitized message bodies may also be stored in that database; when server body persistence is disabled, bodies are retrieved for the active session and cached body rows are removed. Attachments are retrieved from the mail provider when requested and may be temporarily handled by the browser, WordPress, server or hosting caches involved in that request.
Google OAuth is available only in PressedMail Pro. PressedMail Free does not include the Google OAuth integration; site owners may connect Gmail to Free using Google's supported app-password flow. Both editions process mailbox data on the customer-controlled WordPress site.
PressedMail includes locally managed contacts and calendar features, but the PressedMail Pro Google OAuth flow does not request or use the Google Contacts API or Google Calendar API. Google contact and calendar permissions are future features and will require updated disclosures and consent before release.
8. OAuth credentials and authentication path
PressedMail never receives or stores a user's Google password.
For the one-click Gmail connection in PressedMail Pro, the customer starts authorization in the plugin and Google displays its consent screen. The authorization callback goes to the PressedMail relay on pressedmail.com. The relay receives the temporary authorization code, exchanges it with Google, verifies the connected Google email identity, and places the access token, refresh token, granted scope, mailbox address, customer site URL and authorization nonce in a service-role-only transfer record. The random browser transfer code is stored only as a SHA-256 hash. The transfer is valid for no more than five minutes, is single-use and is redeemed server-to-server by the originating WordPress site.
After redemption, the PressedMail plugin stores access and refresh tokens encrypted in the customer-controlled WordPress database. Token refresh requests pass directly from the WordPress server through the PressedMail relay to Google over HTTPS; the relay processes the refresh token to complete that request and does not add it to a customer profile or mailbox-content store.
Removing the connected email account from PressedMail deletes the locally stored OAuth credentials and that account's local mailbox mirror. A user may also revoke PressedMail from the third-party connections area of their Google Account. Revocation at Google immediately prevents future token use; already synchronized local data remains under the WordPress site owner's control until it is deleted, purged or the plugin is uninstalled.
9. Google Workspace and Gmail data
This section applies to the Google OAuth connection shipped only in PressedMail Pro. PressedMail Free does not request these Google OAuth permissions.
Google permission requested
The current centralized Google OAuth flow requests openid, email and the restricted Gmail scope https://mail.google.com/. PressedMail does not currently request Google Contacts or Google Calendar scopes. The Gmail scope is used because PressedMail is a full email client that connects through Gmail IMAP and SMTP and lets the authorized user read, compose, send and manage mail.
Google data accessed
After authorization, PressedMail may access:
- The connected Google email address and verified account identity.
- Mailbox folders and labels.
- Message headers, metadata, senders, recipients, dates and subjects.
- Message bodies, conversation content and attachments.
- Read, unread, starred, archived, deleted and other mailbox state.
- Draft and sent-message data.
- OAuth access and refresh tokens and the granted scope.
How Google data is used
Google user data is used only to provide or improve visible PressedMail email-client features chosen by the site owner or authorized mailbox user, including:
- Synchronizing and displaying email.
- Searching, filtering and organizing messages.
- Reading messages and requested attachments.
- Managing folders, labels, flags and mailbox state.
- Creating drafts and sending user-composed messages.
- Archiving, trashing, restoring or permanently deleting messages when the user requests that action.
- Providing optional AI summaries, drafting, rewriting, classification, phishing analysis or tag suggestions when an administrator has enabled the relevant feature.
Google Limited Use commitment
PressedMail's use and transfer of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
In particular, Google user data is not:
- Sold, rented or traded.
- Transferred to data brokers, information resellers or advertising platforms.
- Used for personalized advertising, retargeting or interest-based advertising.
- Used to determine creditworthiness or for lending.
- Used for unrelated profiling.
- Used by CurbSoftware to create, train or improve a generalized or foundational artificial-intelligence or machine-learning model.
Transfers are limited to providing a user-facing PressedMail feature with the user's consent, protecting security, complying with applicable law, or a corporate transaction after any explicit prior consent required by Google's policy.
Human access
CurbSoftware personnel do not read Gmail message content. Human access is permitted only when the user gives documented, explicit consent for specific data needed to resolve a support request; when access is necessary to investigate abuse or a security incident; when required by applicable law; or for internal operations using data that has been aggregated and anonymized in accordance with applicable law. Site administrators and other users authorized by the WordPress site owner may access mailbox content according to that site's permissions.
10. Optional AI processing
PressedMail Pro includes optional AI-assisted features. Core email-client functionality does not require AI. An administrator must select, configure and enable an AI provider before an AI feature can send content. Supported configurations include OpenAI-compatible endpoints, Google Gemini, Anthropic and compatible local or self-hosted endpoints.
PressedMail Free does not send email content or email metadata to an AI provider. PressedMail Pro AI features are separately distributed, disabled by default and unavailable until the administrator accepts the current provider-specific disclosure. Automatic processing, including background auto-tagging or security analysis, requires a second automation disclosure and acceptance.
AI requests are sent directly from the customer's WordPress installation to the administrator-configured provider endpoint using credentials stored encrypted in WordPress. The request does not pass through a CurbSoftware AI proxy and does not use a CurbSoftware-managed model account in the current architecture.
When an authorized user invokes an AI action, or when the administrator has explicitly enabled an automation such as auto-tagging or phishing analysis, the plugin may send the subject, sender and recipient information, relevant message body or conversation context, available tags and the user's instructions to the configured provider solely to return the requested result. PressedMail does not currently send email attachments or extracted attachment text to the AI provider.
The local WordPress installation records the administrator user ID, acceptance timestamp, provider type, normalized provider endpoint and policy/disclosure version. It also records whether interactive processing or automatic processing was accepted. The consent record does not contain the provider API key. Changing the provider type or endpoint operator invalidates the acceptance and disables AI processing until the administrator reviews and accepts the new provider disclosure; changing only the selected model does not require renewed acceptance.
Summaries, drafts, rewrites and suggested replies are returned for user review and are not sent as email until the user separately approves sending. Classification, security analysis and tag suggestions may be applied automatically only where the site administrator has enabled that behavior. AI output can be incomplete or inaccurate and should not be treated as professional advice or used for consequential decisions without human review.
CurbSoftware does not centrally retain the prompt or response because it does not proxy the AI request. A configured provider may log or retain requests under its disclosed retention terms. For Google-originated email data, the site owner must select a provider and account configuration that must not use Google-originated email data to create, train, or improve a generalized or foundational model. PressedMail requires the administrator to affirm this restriction before enabling the provider; if the administrator cannot make that affirmation, AI must remain disabled. Disabling an AI feature prevents future requests from that feature but does not erase information already processed by the provider; deletion requests must also be directed to that provider where applicable.
AI provider configurations
PressedMail contacts an AI provider only after the administrator configures it, accepts the applicable disclosure and an authorized user requests an AI feature or an accepted automation runs.
| Provider configuration | Data recipient and purpose | Terms and privacy |
|---|---|---|
| OpenAI Compatible | The configured OpenAI-compatible endpoint receives the selected email context and instructions to produce the requested AI result. If OpenAI operates the endpoint, OpenAI is the recipient. | OpenAI API, Service Agreement, Privacy Policy |
| Google Gemini | The Gemini API receives the selected email context and instructions to produce the requested AI result. | Gemini API, Gemini API Terms, Google Privacy Policy |
| Anthropic | The Anthropic API receives the selected email context and instructions to produce the requested AI result. | Anthropic API, Commercial Terms, Privacy Policy |
| Ollama or another local/self-hosted endpoint | The endpoint operator selected by the administrator receives the selected email context and instructions. For a self-hosted endpoint, the site owner controls the operator and infrastructure. | Ollama, Ollama Terms, Ollama Privacy Policy when Ollama operates the service |
For an arbitrary administrator-supplied endpoint, CurbSoftware cannot identify or control the operator. The administrator must evaluate that operator's terms, retention, security, data location and model-training behavior. PressedMail requires the administrator to affirm that the selected provider and account configuration prohibit using Google-originated email data to create, train or improve generalized or foundational AI models. If the administrator cannot make that affirmation, AI must remain disabled for the provider.
11. Purposes of processing
| Data category | Main purposes |
|---|---|
| Website and account data | Account creation, authentication, preferences, security, support and service operation |
| License and site data | Activation, entitlement, downloads, compatibility checks, fraud prevention and support |
| Payment and tax data | Checkout, subscriptions, invoices, reconciliation, refunds, accounting, tax and dispute handling |
| Mailbox and Gmail data | User-facing synchronization, reading, search, organization, drafting, sending and mailbox actions |
| OAuth credentials | Authorizing and maintaining the user-requested PressedMail Pro connection to Google |
| AI request content | Producing the specific enabled summary, draft, rewrite, classification, security result or tag suggestion |
| Logs and diagnostics | Reliability, abuse prevention, security, debugging and legal compliance |
| Newsletter and marketing data | Sending requested communications, recording consent and honoring opt-outs |
12. Service providers and disclosures
We disclose only the information needed for the described service:
- Google: for PressedMail Pro Google OAuth, account identity, OAuth authorization and Gmail email-client operations requested by the user.
- Customer hosting and WordPress infrastructure: mailbox data, tokens, settings, logs and local plugin records controlled by the site owner.
- Supabase and CurbSoftware hosting infrastructure: website accounts, licensing and the temporary five-minute OAuth transfer record.
- Stripe, BitCart and displayed payment providers: checkout, transaction, tax, fraud and refund data.
- Transactional email and support providers: delivery addresses and the content needed to send service notices or respond to support.
- **Listmonk at
news.pressedmail.com:** newsletter address, subscription status and consent or suppression records. - Umami: website analytics events, an account identifier once you are signed in, and associated technical data. Advertising trackers are not used for Google user data.
- The administrator-configured AI provider: only the content required for an enabled AI action, sent directly by the customer's WordPress site.
- Professional advisers, authorities or courts: information required for legal, tax, accounting, security or compliance purposes.
We may disclose business records during a merger, acquisition, financing, restructuring or asset sale, subject to applicable law and any explicit consent required for Google user data.
13. International processing
CurbSoftware operates from Canada. Our providers, customers and connected services may process information in Canada, the United States or other countries where they operate. Information may therefore be subject to the laws and lawful-access rules of those jurisdictions. A WordPress site owner's hosting location and selected AI or mail provider determine where most mailbox processing occurs.
14. Retention and deletion
We limit retention to the period needed for the identified purpose, applicable law, security, accounting, fraud prevention and dispute resolution. The following criteria apply:
| Data | Retention or deletion criterion |
|---|---|
| Website customer account | While active; deleted after a verified deletion request is completed, except for records that must be retained under another row below |
| License and activated-site records | While the license or related account remains active, then only as needed for entitlement history, fraud, disputes, security or legal obligations |
| Payment, invoice and tax records | For the period required by applicable accounting, tax, anti-fraud and financial-record laws |
| Support communications | Until the request is resolved and the record is no longer reasonably needed for follow-up, security, dispute handling or legal compliance |
| Security and access logs | For the configured operational log window; longer only when required to investigate an incident, abuse or legal claim |
| OAuth transfer record | Authorization material is valid for no more than five minutes, is single-use, and is removed through redemption and expiry cleanup processes |
| OAuth access token in WordPress | Until expiry, replacement, revocation or removal of the connected email account |
| OAuth refresh token in WordPress | Until replacement, Google revocation, removal of the connected email account or purging of plugin data |
| Locally synchronized email and indexes | Until deleted through mailbox actions, account removal, local retention settings, cache clearing or plugin uninstall |
| AI prompts and responses | Not retained by a CurbSoftware AI service in the current direct-provider architecture; the configured provider's disclosed retention applies |
| AI consent records | Retained locally while needed to document the active provider disclosure; revoked when the provider endpoint changes, the administrator revokes consent, the accepting WordPress user's PressedMail data is erased, or plugin data is purged |
| Infrastructure backups | Until the applicable rolling backup rotation expires; deletion is reapplied if a backup is restored where technically feasible |
| Newsletter records | Until unsubscribe; minimal suppression and consent evidence may be retained to honor the opt-out and demonstrate compliance |
| Privacy-breach records | At least two years where required by PIPEDA, and longer if another legal obligation applies |
Deleting a PressedMail website profile does not delete data controlled by an independently operated WordPress site. Removing an email account from the plugin deletes its locally stored credentials and local mailbox mirror. Uninstalling the plugin always deletes locally stored PressedMail data; deactivation preserves it.
15. Security
Safeguards include HTTPS for external transfers, encrypted storage for OAuth and AI credentials in the WordPress plugin, restricted service-role access to temporary OAuth transfer records, hashed one-time transfer codes, single-use and expiry controls, authorization and capability checks, administrative access restrictions, logging, backups, dependency and security review, and incident-response procedures.
No service can guarantee absolute security. WordPress site owners are responsible for securing their hosting, WordPress administrators, databases, backups and connected provider accounts.
16. User choices and controls
Users and administrators can:
- Decline Google authorization and use another supported connection method, including the Gmail app-password connection available in PressedMail Free, where available.
- Remove a connected Google email account in PressedMail to delete its local credentials and mailbox mirror.
- Revoke PressedMail access from the Google Account third-party connections page.
- Disable synchronization or email-body persistence and clear locally cached bodies.
- Delete messages or attachments through the connected mailbox, subject to the mail provider's behavior.
- Enable, disable or reconfigure each optional AI feature and remove its locally stored provider key.
- Choose a local or self-hosted AI endpoint where supported.
- Uninstall PressedMail to remove its locally stored plugin data; deactivation alone preserves that data.
- Request a WordPress personal-data export for locally stored PressedMail records. Credentials, passwords, access tokens, refresh tokens, API keys and encrypted provider configuration are excluded from the export.
- Request WordPress personal-data erasure to remove locally owned PressedMail accounts, mailbox mirrors, preferences and related plugin records. This local erasure does not delete messages from the remote mail provider and does not delete the WordPress user account.
- Reject optional website analytics cookies or change browser storage settings.
- Unsubscribe from marketing email using the link in each message.
17. Privacy rights and complaints
Depending on location and applicable law, a person may have privacy rights to request access, correction, deletion, portability, restriction, objection or withdrawal of consent for personal information controlled by CurbSoftware. Contact the Privacy Officer at [email protected]. We may need to verify identity and may retain records where legally required.
For mailbox data controlled by a customer's WordPress site, contact that site owner first. CurbSoftware generally cannot access or delete content held only on an independent WordPress installation.
Where supported by the site owner, WordPress personal-data export and erasure tools provide access to or deletion of local PressedMail records. They do not reach into Google, Microsoft, another mail provider, or an AI provider. Requests for data retained by those providers must be directed to the applicable provider.
Canadian users may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator. We will investigate privacy complaints and explain the outcome or available escalation route.
18. Cookies, analytics and marketing
Essential cookies and local storage support authentication, security, checkout, consent preferences and required website operation.
Umami analytics runs unless you reject cookies. Umami sets no cookies and stores no persistent tracking identifier of its own; it records page views and product interactions such as which pricing plan was selected or whether a form succeeded. It also honours the browser's Do Not Track setting. Rejecting cookies in the consent banner stops the analytics script from loading at all, and you can change that choice at any time through Cookie settings in the site footer. While you are signed in, analytics events are associated with your account identifier so that a customer journey can be followed across visits; they never include your email address, password, message content or mailbox data. PressedMail does not use Google user data for advertising.
For details, see the Cookie Policy. Newsletter and marketing messages are sent with consent or another lawful basis, identify the sender and include a working unsubscribe method. We retain the minimum suppression record needed to prevent further marketing after an opt-out.
19. Children
PressedMail is a business and professional WordPress administration product and is not directed to children under 16. We do not knowingly create customer accounts for children under 16. Contact the Privacy Officer if you believe a child has provided personal information to CurbSoftware.
20. Security incidents
We maintain procedures to assess, contain, document and respond to security incidents involving information under CurbSoftware's control. We will notify affected individuals and regulators where required by law. Under PIPEDA, this can include reporting and notification when a breach of safeguards creates a real risk of significant harm.
For a security incident involving Google user data, CurbSoftware will notify Google at [email protected] before making public statements where the Google Workspace API User Data and Developer Policy requires that notice, and will cooperate with any requested investigation or audit.
A WordPress site owner remains responsible for incident duties relating to information under that site's control, including incidents involving its hosting, administrators or local PressedMail database.
21. Policy changes
We may update this policy as PressedMail, its providers or legal requirements change. The current version and update date will remain at https://pressedmail.com/privacy. Material changes will be communicated through the website, account service, plugin or direct notice as appropriate. We will obtain renewed consent before using Google user data for a materially different purpose where required.
22. Contact
Privacy questions, rights requests and complaints may be sent to:
- Privacy Officer
- CurbSoftware Tech Innovations
- British Columbia, Canada
- Email:
[email protected] - Web: PressedMail Contact
People whose information exists only in a customer's mailbox should contact that WordPress site owner. CurbSoftware will assist with information under its control and explain when a request must be directed elsewhere.





