Overwood operates this private mailbox service at overwood.duaranet.com. Contact fyberpay@gmail.com about mailbox access, data handling or deletion requests.
Information we access
When you connect a Google mailbox, Google provides account identity information and authorization tokens. With your permission, Overwood reads mailbox information, message headers, sender and recipient addresses, subjects, dates, labels, message content and attachment information. Authorized requests can retrieve attachment content. Google mailbox passwords are not collected by Overwood.
For an IMAP connection, Overwood stores the mailbox credentials you supply and accesses the selected folders. The app also records workspace accounts, permissions, synchronization status and administrative audit events. Login uses a session cookie. Server request logs may contain IP addresses, request paths and timestamps.
Purpose and access
Overwood uses this information to connect and synchronize mailboxes, search and display correspondence, retrieve attachments, and provide requested mail context to authorized agents. The workspace owner can access connected mailboxes and grant other users or agents access to selected mailboxes. Only connect a mailbox you are authorized to share with the workspace.
An agent holding an authorized MCP token can receive message content and attachments for its permitted mailboxes. If the operator connects an external AI service, that service processes the information sent to it. The operator must disclose the chosen service and obtain any necessary consent before enabling that transfer. Overwood V1 itself does not run a language model or automatically send mail to an AI service.
Storage and retention
Indexed messages and account records are stored on Overwood's Contabo-hosted server. Provider credentials are encrypted by the application, and public connections use HTTPS. These protections do not make the service end-to-end encrypted: the application and authorized server administrators can access stored message content.
Indexed mail has no automatic age-based deletion policy. Disconnecting a mailbox removes its stored provider credentials and stops synchronization, but retains indexed mail unless the owner selects the purge option. Purge removes the mailbox's indexed messages, threads, folders and change history from the active database; account and administrative audit records remain. Any separately retained backups or copies already received by agents require separate handling. Contact the operator for deletion beyond the active index.
You can also revoke Google's authorization through your Google Account. Revocation stops future authorized access but does not itself remove data already indexed in Overwood. An owner can revoke an agent token to stop future access by that token.
Data-use commitments
Google user data is used only for the mailbox features described here. It is not sold, used for advertising, or used to train general-purpose AI models. Transfers are limited to authorized service functionality with user consent, necessary security purposes, or applicable legal obligations. Human access to Google message content requires the user's affirmative agreement, except where Google's Limited Use rules permit access for security or legal purposes.
Overwood's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements: Google API Services User Data Policy.
Material changes to these data practices will be reflected in this notice, with renewed consent obtained where required before using Google data for a new purpose.