Privacy Policy
Effective September 20, 2026
Go Away ("goaway", "we", "us") is a newsletter-unsubscribe tool: you connect an email inbox, we scan it for senders you can unsubscribe from, and you decide what to do about each one. This policy explains what we collect, why, and what we do (and don't do) with it — including data we receive through Google APIs and the Microsoft Graph API.
1. Information we collect
- Account information. The email address you sign in with, used to send your one-click sign-in link and identify your account. We don't use passwords.
-
Connected inbox data. When you connect a Gmail or
Outlook.com/Hotmail/Live.com inbox, we receive an OAuth2 access/refresh
token from that provider, and use it to read message headers —
sender, subject, date, and the
List-Unsubscribe/List-Unsubscribe-Postheaders — and, when you click Unsubscribe, to send an unsubscribe request from your own inbox. For a connected Gmail inbox, our access is limited to headers: we never read, store, or process the body of a Gmail message. For a connected Outlook.com/Hotmail/Live.com inbox, we also scan the message body in memory at scan time, to catch an unsubscribe link that isn't advertised via a header — that body content is never stored. The subject line of a scanned message is stored so it can be shown to you as context for a pending item. - Unsubscribe activity. For each sender we find, we store the sender's address/name, the unsubscribe method available (link or mailto), and the status of your decision (pending, unsubscribed, or allowed), so we don't show you the same sender twice and so your dashboard reflects what you've already done.
- Billing information. If you subscribe, Stripe processes your payment directly — we never see or store your card details. We keep a record of your Stripe customer and subscription IDs and subscription status so we know whether your account is on the paid plan.
- Technical data. Ordinary server logs (timestamps, IP address, and requested path) for operating and securing the service.
2. How we use Google user data
Go Away requests two Gmail scopes when you connect a Gmail inbox: metadata access to your mail, limited to message headers rather than message content (to scan headers for unsubscribable senders), and permission to send mail (used only to send the unsubscribe request itself, from your address, when you click Unsubscribe or turn on automated unsubscribe). We use this access solely to provide and improve the inbox-scanning and unsubscribe features you see in the product — never for advertising, never to build a profile of you for any other purpose, and never sold or transferred to third parties except as necessary to provide the service (e.g., to Google's own APIs) or to comply with the law.
Go Away's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use and share information
We use the information above to operate the service: running scans, showing you results, carrying out the unsubscribe/allow actions you request, sending sign-in links and account notifications, and billing subscribers. We share data only with the service providers who help us do that, each acting on our behalf and bound to use it only for that purpose:
- Google — to read headers from, and send mail through, a Gmail inbox you've connected. Microsoft — to read headers and, transiently, message bodies from, and send mail through, an Outlook.com/Hotmail/Live.com inbox you've connected.
- Stripe — to process subscription payments.
- Resend — to deliver sign-in-link and transactional emails.
- Our hosting/database provider — to store the data described above.
We do not sell your information, and we do not share it with anyone for their own advertising or marketing purposes.
4. Data storage and security
Data is stored in a Postgres database on encrypted disks. OAuth refresh tokens are the one thing stored in plaintext rather than separately encrypted, since disk encryption already protects them at rest; access to that table is restricted to the application's own database role. Sign-in links and session cookies are stored only as a one-way hash, never in a form that could be used to sign in if the database were exposed.
5. Data retention and deletion
We keep your account and connected-inbox data for as long as your account is active. Disconnecting an inbox deletes its stored OAuth tokens and revokes goaway's access on our side immediately; we recommend also removing goaway's access from your Google Account permissions or Microsoft account permissions page, which revokes it on the provider's side too. To close your account and delete your data entirely, email us (below) and we'll delete it, other than what we're required to retain for billing/tax records.
6. Your choices
You control what goaway does with each sender it finds — nothing is unsubscribed automatically unless you turn on automated unsubscribe for a given inbox, and you can turn it back off at any time. You can disconnect an inbox, allowlist a sender, or delete your account at any time from within the product or by contacting us.
7. Children's privacy
goaway is not directed at children under 13, and we don't knowingly collect information from them.
8. Changes to this policy
If we make a material change to this policy, we'll update the effective date above and, where required, notify you in the product or by email before the change takes effect.
9. Contact us
Questions about this policy or your data can be sent to [email protected].