Privacy Policy
Mailcore processes only the data needed to respond to a request, connect a domain, deliver messages, and protect business email.
Who this policy applies to
This policy applies to the mailcore.uz website, the Mailcore form and Telegram bot, and the managed email service. Companies are connected through an agreed process, and operator details, service scope, and payment terms are documented individually before a production domain is switched.
Data we process
When you register a Mailcore account, we receive your work email, the name of the organization you create, and technical session information. You can verify the address with a one-time code or sign in with Google. For Google sign-in, we validate the Google ID token and process a stable Google account identifier and verified email; we do not receive your Google password or Google API access tokens. Sign-in does not give Mailcore access to Google Calendar—calendar permissions are requested separately only when you explicitly connect it. A request may include the name or company name, domain, contact method, and task description you enter. An Email API connection request also includes the project name, sender address, use case, and expected service-message volume. To protect the form, we may retain the IP address, page address, referrer, and technical markers.
When providing email service, we process account and domain data, sender and recipient addresses, technical headers, delivery time and outcome, IP addresses, and sign-in events. Message content and attachments are processed only as needed to store, scan for malware and spam, transmit, and receive email.
Connecting Google Calendar
Google Calendar is connected only after an explicit user action and confirmation on Google's page. Mailcore receives the selected Google account identifier and address; available calendars and their names, colors, and time zones; and events with dates, times, descriptions, locations, attendees, attendee responses, reminders, and video-meeting data. If the user enables editing, Mailcore can also create, update, and delete events and send responses on the user's behalf.
This data is used only to display and operate the calendar inside Mailcore. It is not used for advertising, credit scoring, sale, training general-purpose artificial intelligence models, or profiling users outside this feature. Mailcore does not share Google data with third parties except when necessary for an explicitly selected feature, security, legal compliance, or an action separately confirmed by the user.
Google tokens are stored encrypted on the server and are not sent to the browser. Events are requested from Google during use and synchronization. Technical synchronization state may include calendar identifiers, versions, and sync tokens, but Mailcore does not create a permanent separate calendar copy for other purposes.
Use of information received through Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Why we need the data
We use data to register and protect accounts; manage organizations and products; respond to enquiries; verify domain control; create and protect mailboxes; deliver messages; diagnose issues; perform backups after that system enters operation; issue invoices; investigate complaints; and prevent abuse. We do not sell personal data or use email content for advertising.
Infrastructure and data recipients
Mailcore's primary mail node is located in Uzbekistan. Outgoing delivery uses Amazon SES in the eu-central-1 region; Cloudflare may provide DNS and protection for public web resources. Telegram requests are processed through the Telegram Bot API. A message is also passed to the mail system of the recipient selected by the sender.
Retention period
Accounts and organizations are retained while in use or while the data is needed to provide the service and meet obligations. Work email and temporary code-delivery data are stored encrypted on the server; the one-time code copy is cleared immediately after sending, and expired verification data is removed by scheduled cleanup. Messages and mailbox data are retained for the duration of the service and removed under an agreed procedure after termination. Security, delivery, suppression, and abuse logs may be retained longer when needed to protect the service, investigate an incident, or meet obligations. The contact address in an Email API connection request is stored encrypted, and the request is automatically deleted within 30 days. Before deletion, qualified-client details may be transferred to an agreed customer system. Other requests are kept while needed to respond and preserve the history of arrangements, then deleted or anonymized.
When Google Calendar is disconnected, Mailcore revokes permission where technically possible and deletes stored tokens and synchronization state. Users can also revoke access in their Google account settings. After an email account is deleted, any remaining technical connection state is removed by scheduled cleanup within 90 days unless a longer period is required for incident investigation or by law.
Security
Mailbox access requires authentication, and client domains are connected after manual review. We use TLS in transit, SPF, DKIM, and DMARC, spam and malicious-attachment filtering, restricted administrative access, and technical-event logging. Internet email is not end-to-end encrypted: do not send passwords, private keys, or two-factor authentication codes by ordinary email.
Your requests
You can manage a Google Calendar connection directly in the Calendar interface, where you can view the connected account and disconnect it while deleting Mailcore tokens. To request access to, correction of, or deletion of data, write to support@mailcore.uz. Reports of spam, phishing, and other abuse are accepted at abuse@mailcore.uz and handled under the abuse-handling procedure.
Changes
If the data scope or infrastructure changes materially, we will update this page and its effective date.