Disconnecting and deleting your data

You can stop Unified E box's access to your Gmail account at any time, and you can ask us to erase the data we have stored. These are two different actions, and this page explains both.

Last updated September 21, 2026

Nothing here deletes anything from Gmail

Every action on this page affects only the copy of data held by Unified E box. Your mail stays in your Google account exactly as it is. The permissions we hold do not allow us to permanently delete your mail, and we never ask for one that would.

The difference between the two

  • Disconnecting ends our access. We revoke the token with Google and delete the stored credentials, so we can no longer read or send anything. By design it leaves the conversations that were already synced visible in the workspace, so your team keeps its history.
  • Deletion goes further: it erases the stored messages, threads, and attachment metadata we hold for your mailbox.

If you want both, disconnect first and then request deletion.

Option 1: Disconnect a Gmail account

Takes effect immediately and needs no help from us.

  1. Sign in to Unified E box.
  2. Go to the Accounts page.
  3. Find the mailbox you want to disconnect.
  4. Select Disconnect and confirm.

When you do this, we:

  • Stop the Gmail change-notification subscription for that mailbox.
  • Ask Google to revoke the refresh token.
  • Delete the encrypted refresh and access tokens from our database.
  • Mark the account as disconnected and stop all Gmail API calls for it.

Option 2: Revoke access from your Google Account

You do not need Unified E box to be working, or to be signed in to it, to cut off access. Go to your Google Account permissions page, select Unified E box, and choose Remove access. Our credentials stop working at once. The next time the application tries to sync that mailbox it will fail, and it will be marked as needing re-authorization.

Option 3: Request deletion of stored data

To have the Gmail-derived data we hold erased, email privacy@uniebox.vercel.app with the subject Data deletion request, and include:

  • The Gmail address whose data you want deleted.
  • The email address of your Unified E box account, if it is different.
  • Whether you want the mailbox disconnected as part of the request.

Send the request from an address we can tie to the account. We verify every request before acting on it, because acting on an unverified one would itself be a security failure. If we cannot confirm that a request is genuinely yours, we will ask for more information rather than proceed.

What deletion removes

On a verified request we delete:

  • Stored messages: subjects, snippets, bodies, participants, and timestamps.
  • Stored conversation threads and their metadata.
  • Attachment metadata. Attachment contents were never stored.
  • The encrypted OAuth tokens, if the mailbox is still connected.
  • The connected account record.

We complete verified deletions within 30 days. Deleted content is also removed from routine backups within the backup rotation period, which does not exceed 90 days.

What we may keep, and why

We retain a minimal record that a deletion request was made and carried out: the request date, the address it concerned, and the completion date. We keep it to prove we honoured the request and to meet our own accountability obligations. It contains no message content. We may also retain data where law requires it, for as long as that obligation lasts.

Deleting a whole workspace

An organization administrator can request deletion of the entire workspace, which removes every connected mailbox and all stored mail for that organization. Send that request from an administrator account to privacy@uniebox.vercel.app.

Questions

If anything here is unclear, or a request is not handled to your satisfaction, write to privacy@uniebox.vercel.app. The privacy policy describes your broader rights over your data.