Effective September 5, 2026
Privacy Policy
Respawn Mail is a CORSAIR XENEON EDGE widget published by Respawn Icons. It connects only to Google accounts that you explicitly authorize.
Information accessed
- Google account identity: account ID, email address, display name, and profile-photo URL if Google returns them.
- Mailbox metadata: mailbox totals, history identifier, labels, unread counts, Gmail search queries, conversation identifiers, and message labels.
- Email content: senders, recipients, subjects, dates, snippets, plain-text or text-converted message bodies, reply headers, and attachment filenames, media types, sizes, and identifiers.
- OAuth credentials: Google access and refresh tokens. Respawn Mail never receives your Google password.
Respawn Mail does not request access to Google Drive files, Calendar events, Contacts, payment data, or unrelated Google data.
How information is used
Information is used only to connect your account; display, search, and refresh your mailbox; mark opened conversations as read; perform the Trash or read-status action you select; open a selected conversation in Gmail; renew authorization; and manage the local connection. It is not used for advertising, profiling, data brokerage, model training, or sale.
Google permission and user-controlled changes
Respawn Mail requests Gmail's modify permission to read conversations, update read status, and move mail to Trash. Google bundles sending into this permission; it does not offer a read-and-Trash-only scope. The widget does not provide compose, reply, forwarding, or sending features, and its mail service rejects send and draft requests. The app does not request the broader full-mail permission and cannot permanently delete messages while bypassing Trash. Opening a conversation marks it as read. Other mailbox changes require an explicit user action.
Processing and storage
Mailbox metadata and email content travel directly between the hosted widget running in iCUE and Gmail. They are held in widget memory only as needed for display or a requested action. The Respawn Icons sign-in service does not receive, proxy, or retain messages, searches, labels, bodies, recipients, subjects, or attachments.
During sign-in, the service exchanges Google's authorization response, reads basic account identity, and creates an encrypted handoff package for the requesting widget. Retrieval triggers deletion; the record also expires within 15 minutes.
The service stores short-lived session records containing random-token hashes plus keyed one-way fingerprints that bind the browser callback and refresh-token renewal to the requesting installation. Raw network addresses and raw Google refresh tokens are not stored in those binding records. An unused refresh-token binding expires after 90 days; successful renewal restarts that period.
After connection, OAuth credentials, account identity, profile-photo URL, and granted-permission flags are stored locally as an AES-GCM encrypted record in the widget's IndexedDB on your Windows device. A non-extractable device-local key protects the record. If secure storage is unavailable, the connection remains in memory only and never falls back to plaintext. Message content, searches, and attachment data are not persisted.
Message safety and remote content
Respawn Mail prefers plain-text message parts. If only HTML exists, the widget parses it in a detached document and extracts text. Raw email HTML is never inserted into the app. Scripts, forms, frames, remote images, and tracking pixels remain blocked.
To open Google sign-in and Gmail links in the default browser without exposing them to the iframe bridge, the widget encrypts each target locally with a fresh AES-GCM key. The service stores only opaque ciphertext and a keyed network binding for up to 60 seconds; the decryption key stays in the browser URL fragment and is never sent to the service. Retrieval is one-use.
Sharing and service providers
Respawn Mail communicates with Google and with the Respawn Icons sign-in service hosted on Cloudflare. Cloudflare processes limited network, session, OAuth credential, and encrypted-handoff data as an infrastructure provider. Google processes mailbox reading and Trash/read-status requests. Respawn Icons does not sell, rent, or disclose Google user data to advertisers or data brokers.
Security
Safeguards include Google-hosted OAuth, a narrowly selected scope, PKCE, random one-time values, same-browser and same-network callback checks, HTTPS, rate limits, short-lived encrypted handoffs, strict browser-origin controls, a narrow content security policy, installation-bound token renewal, encrypted local credentials, and safe-text email rendering. No system can be guaranteed perfectly secure.
Your choices and deletion
Disconnecting an account deletes its locally stored credentials and account metadata from Respawn Mail. You can also revoke access through Google Account connections. Moving mail to Trash changes it in Gmail; use Gmail to restore it or manage its retention. Unclaimed sign-in packages expire within 15 minutes, encrypted browser links within 60 seconds, and inactive service records automatically. For a privacy or deletion request, email respawnicons@gmail.com.
Google API Services User Data Policy
Respawn Mail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Children
Respawn Mail is not directed to children under 13, and Respawn Icons does not knowingly collect their personal information.
Changes
Material changes will be posted here with a revised effective date before they take effect.