Flick MailMergeSEND SMARTER · GROW FASTER
Sign in →
The Trust Page

Your data, treated like our own.

Flick MailMerge is a small, focused tool. We hold the minimum data needed to send your mail well — encrypted at rest, isolated per user, never sold or rented.

Last updated · 2026-09-02 v5 · Studio EU-aligned · GDPR-friendly
🛡️

Privacy

What we collect, what we don't, who we share with.

↘
🔒

Security

Encryption, sessions, audit log, infrastructure.

↘
📜

Terms

Service, billing, cancellation, liability, law.

↘
🔒
0-bit
AES-Fernet, sealed at rest
🔁
TLS 1.3
Encrypted in transit · HSTS
🚫
0
Rows ever sold or rented
🗑️
0-day
Full wipe after you cancel
§ 01 · Privacy

What we collect, what we don't.

We hold the minimum needed to send mail and run your account. Nothing is sold or rented; nothing is read for advertising.

📋

What we collect

  • Account basics — username, email, password (hashed), plan, daily cap
  • Provider credentials — Gmail & Outlook OAuth tokens, plus Yahoo / Zoho / custom-SMTP app passwords — all encrypted
  • Recipient lists you upload (CSV / XLSX / Sheets)
  • Send activity — timestamps, recipient, subject, status, opens, clicks, replies, bounces
  • Audit events — sign-in attempts, IP, user-agent, ID-mismatch flags
  • Operational logs — error traces, request IDs (kept ≤ 30 days)
🚫

What we don't

  • Your recipients' replies read for advertising, profiling, or resale
  • Your Gmail / Outlook account password — OAuth only, never on our wire
  • Tracking pixels for our marketing on this page (none)
  • Data sold or rented to third parties · ever
  • Cross-site fingerprinting or third-party advertising cookies
🔁

Third parties & sub-processors

  • DigitalOcean — application hosting (containerised, BLR1 region)
  • PostgreSQL — managed database on the same private network
  • Google & Microsoft — OAuth providers (you authorise scope)
  • Let's Encrypt — TLS certificates for HTTPS

We use no analytics, no ad networks, no session-replay tools.

🍪

Cookies

  • session — keeps you signed in (HttpOnly, Secure, SameSite=Lax)
  • csrf — anti-CSRF token for write actions
  • mm-theme — local-storage only, your colour preference

That's the entire cookie list. No tracking, no advertising IDs.

🧾

Your rights

  • Access — export every row tied to your account
  • Correction — fix inaccuracies in profile, contacts, settings
  • Deletion — wipe your account & all derived data within 7 days
  • Portability — JSON / CSV export of campaigns & recipients
  • Objection — stop processing anytime by signing out / cancelling

Reach: info@codeftech.com

🗓️

Data retention

  • Active account — kept while you use the service
  • Cancelled account — full wipe within 7 days, including backups
  • Audit log — 24 months (regulatory traceability)
  • Operational error logs — 30 days, anonymised IPs
🌐

The Email Extractor runs in your browser

The optional Email Extractor ("Signal Lock") is a bookmarklet with Live, Search and Domain scanners. Every page it reads and every address it finds stays on your machine — nothing is uploaded to our servers.

  • No scanned page, contact or query ever reaches us
  • Off by default — enabled per account, opt-in only
  • You export the results yourself; we never see them
📈

Bounce, reply & deliverability data

We watch outcomes only for campaigns you send from your own mailbox — across every provider.

  • Bounces — dead addresses auto-detected and suppressed from future sends
  • Replies — inbound replies appear in your Replies tab; never mined for ads or resale
  • Spam Check — an in-app content score plus a real-inbox seed test before you send
  • Per-campaign grade — an A–F health score with live SPF / DKIM / DMARC checks

Read via Gmail / Outlook APIs and Yahoo / SMTP over IMAP.

🎯

What we won't pretend to know

No sender — us included — can tell whether a delivered email reached the inbox or the spam folder. That signal doesn't exist.

  • We never guarantee inbox placement
  • We report only what's real: accepted, bounced, blocked-as-spam, complaints and Postmaster rates
🔐

Google user data — Limited Use

Flick MailMerge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • gmail.send — to send your personalised campaign emails from your own mailbox
  • gmail.readonly — to read delivery status and detect replies/bounces for your campaigns, and to count messages you sent in the last 24h so we stay under Gmail's daily limit
  • spreadsheets.readonly — to import recipient lists you choose from Google Sheets

Your Google data is used only to provide these features — never for advertising, never sold or transferred to third parties. No human reads your Gmail content; access is automated, except with your consent (e.g. support), for security/abuse investigation, or to comply with law.

§ 02 · Security

Built so we can't see your secrets.

Every credential — provider tokens, SMTP passwords — is sealed with Fernet AES-128 before it touches the database. Single-session, idle auto-logout, and a full audit log on top.

🔐

Encryption at rest

OAuth tokens, refresh tokens, SMTP passwords and any user-uploaded credentials are encrypted with Fernet (AES-128-CBC + HMAC-SHA256) using a per-deployment key held outside the database.

  • Postgres column-level encrypted blobs
  • Per-deployment master key, rotated yearly
  • Backups inherit the same encryption
🔁

Encryption in transit

TLS 1.3 only, on every endpoint, with HSTS preloaded. We refuse old ciphers, refuse plain HTTP, and refuse mixed content.

  • Cloudflare TLS termination
  • HTTP → HTTPS at the edge
  • HSTS · max-age 1 year
👤

Single-session enforcement

One active login per ID. Signing in elsewhere kicks the previous session immediately — and the audit log records both events with IP and user-agent.

  • Session tokens · server-stored · invalidated on rotate
  • ID-match rule — connected mailbox must equal assigned email
⏳

Idle auto-logout

5-minute inactivity timer with a 60-second warning. Tab-visibility checks on return kill a session left open overnight before you touch it.

  • Client + server enforced (heartbeat every 20s)
  • Graceful warning UI, "Stay signed in" recovery
📜

Audit log

Every authentication event, password change, OAuth connect/disconnect, and impersonation request is appended to an immutable activity log with IP, user-agent, and detail string.

  • 24-month retention
  • Visible to admins for forensics
🛡️

Operational hardening

  • Auth-storm circuit breaker (rate-limit on /login)
  • Auto-purge of stale OAuth tokens
  • Bcrypt password hashing (Werkzeug default rounds)
  • CSRF tokens on every write endpoint
  • Postgres-only architecture (no shared file state)
📤
You connect

Gmail or Outlook via OAuth, or Yahoo / Zoho / SMTP via an app password — your provider hands us one credential.

OAuth 2.0 · SMTP
🔐
We seal it

Fernet encrypts the token with a per-deployment master key before it touches Postgres.

AES-128-CBC
📨
We send mail

For each dispatch we decrypt in memory, send via your provider, then forget the plaintext token.

In-memory only
§ 03 · Terms of service

A small set of plain rules.

By using Flick MailMerge, you agree to the following. None of it is exotic.

Service description
Personalised mail sent through your own Gmail, Outlook, Yahoo, Zoho or custom-SMTP mailbox. Multi-tenant, subscription-based; no warranty of fitness beyond the published feature list.
Acceptable use
No spam, phishing, malware, harvested address lists, or scraped emails without consent. We may suspend any account whose recipients consistently mark mail as junk, or whose campaigns trigger rate-limit cascades on Gmail / Outlook.
Subscription & billing
Plans renew monthly or annually; invoices via Stripe. Price changes announced 30 days ahead. Refunds within 14 days of first payment, pro-rata thereafter at our discretion.
Cancellation
Cancel anytime from your profile; service runs to the end of the current billing period. Account & derived data wiped within 7 days; audit log kept 24 months for regulatory traceability.
Uptime & SLA
99.5% monthly uptime target on Team and Bureau; Solo is best-effort, no SLA. Scheduled maintenance announced ≥ 48 hours ahead.
Limitation of liability
To the maximum extent permitted by law, our aggregate liability is capped at fees paid in the 12 months before the claim. No liability for incidental, consequential or punitive damages — including lost profits or sender reputation.
Changes to these terms
Substantive changes emailed and bannered in-app ≥ 14 days before they take effect. Continued use after the effective date is acceptance.
Governing law
These terms are governed by the laws of India, without regard to conflict-of-laws principles. Disputes resolved in the courts of Bengaluru, Karnataka.
Contact
Code Flick Technologies · info@codeftech.com · codeftech.com

Questions about anything on this page?

Email us in plain language — we'll respond in plain language.