Privacy Policy
Bubble is a mobile and web email client that presents an existing Gmail mailbox as people-first conversations. This policy explains how Bubble accesses, uses, stores, shares, and deletes information.
1. Information Bubble accesses
When you connect Gmail, Bubble may access the information needed to provide its visible email features:
- Your Google account name, email address, and opaque Google account identifier.
- Gmail thread and message identifiers, subjects, sender and recipient addresses, timestamps, labels, snippets, message bodies, and attachment metadata.
- Attachment contents only when you choose to download or send an attachment.
- Gmail synchronization checkpoints and the email addresses or thread identifiers you choose to pin.
- Account-scoped writing tools you create, including templates, signatures, and quick replies, plus saved triage views and the local attachment inventory used by the attachment center.
- OAuth authorization information created through Google Sign-In and stored as a secure SDK user record in Apple's device-only Keychain for each Gmail account you add.
Bubble does not request iOS permissions for Contacts, Photos, Location Services, microphone, or camera, and it does not request advertising identifiers or unknown Bcc recipients for its current features.
More precisely, Bubble does not request the iOS Location Services permission. Google's sign-in SDK has its own broader privacy declaration, described below.
2. How the information is used
Bubble uses Gmail data only to provide user-facing features:
- Display, search, filter, and organize your conversations.
- Clean email presentation by collapsing quoted history, signatures, and active or remote content without destroying the original representation.
- Compose, reply, reply all, and send mail using recipients you can review before sending.
- Apply actions you request, such as read or unread, star, archive, move to Trash, restore, and undo.
- Cache a bounded recent mailbox on your device for speed and limited offline access.
- Save the writing tools and triage views you create for the selected Gmail account and present downloaded files in the local attachment center.
Bubble's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Where information goes and SDK disclosures
Gmail content is requested directly from Google's Gmail API by Bubble on your device. The iPhone app stores its bounded cache in file-protected local storage. The web app calls Gmail directly from your browser, keeps its short-lived Google access token in memory, and stores a bounded per-account cache in IndexedDB. Bubble does not copy mailbox content to a Bubble-operated server.
Bubble uses Google Sign-In and supporting authentication libraries to authorize Gmail access. Google processes information according to your Google account choices and Google's policies. Apple provides the device, operating system, protected local storage, and App Store distribution.
Apple processes optional Bubble Plus and appearance purchases, and Bubble derives paid access from verified current StoreKit entitlements. Bubble does not send Apple a Gmail address, Bubble account identifier, message value, or other mailbox-derived identifier for a purchase or restore. StoreKit access is app-wide and remains separate from every Gmail account's local data.
The Google Sign-In 9.2.0 SDK privacy manifest declares that it may collect the following information, linked to your identity and not used for tracking:
- Name, email address, phone number, and coarse location for app functionality.
- Other data types and user ID for app functionality and analytics.
- Device ID and other usage data for analytics.
This SDK declaration is separate from Bubble's own app code. Bubble does not add an analytics SDK, request iOS Location Services permission, or use any of this information for advertising or tracking.
The public policy, support, and marketing pages use hosting infrastructure that may process ordinary web-request information, such as an IP address, browser type, requested page, and security logs, to deliver and protect the pages. Those public pages do not intentionally use cookies, advertising, analytics, account sign-in, or mailbox data. Gmail authorization is available only inside the Bubble web app at /app.
4. How Bubble protects Google user data
- Encryption in transit. Google Sign-In and Gmail API requests use HTTPS/TLS directly between Google and the device. The iPhone app uses Apple's App Transport Security, and the web app's Content Security Policy restricts Google authorization and Gmail API connections to Google endpoints.
- Protected credentials. On iPhone, Google Sign-In credential records are stored in Apple's device-only Keychain. On the web, short-lived Google access tokens remain only in browser memory. Bubble does not write plaintext tokens to app preferences, mailbox files, IndexedDB, localStorage, service worker caches, hosting storage, or logs.
- Protected local storage. The iPhone app writes cached Gmail data with complete iOS file protection, uses opaque hashed paths, and excludes downloaded attachment caches from backup where appropriate. Web mailbox data is kept in origin-isolated IndexedDB under a one-way account hash and is subject to the browser and operating system's device protections.
- Least privilege and isolation. Bubble requests the single Gmail permission needed for its visible email features, keeps every connected account in a separate local data root, and does not operate a server-side mailbox index.
- Untrusted-content controls. Active HTML, scripts, forms, frames, remote images, and tracking pixels are blocked in message presentation by default. Bubble also applies restrictive browser security headers and never places mailbox contents or credentials in application logs.
- Deletion controls. Disconnect removes the selected account's credential and account-derived local data. Cache and attachment bounds reduce how much information is kept before disconnect.
No security method eliminates every risk. Keep the device and browser updated, use a device passcode, and review unexpected links or attachments before opening them.
5. Storage and retention
- On the web, Google access tokens remain in browser memory and are not written to IndexedDB, localStorage, the service worker cache, or Bubble's hosting infrastructure. Closing or disconnecting the session removes the token from Bubble.
- The web cache is namespaced by a one-way hash of the Gmail address and bounded to 500 recent threads. It may also contain the pins, templates, signatures, saved views, and recoverable Bubble Sweep checkpoint that you create on that browser.
- The Bubble service worker caches only the application shell and static assets for installation and offline error handling. It does not intercept or cache Gmail API responses.
- Recent mail is kept in a separate file-protected cache for each Gmail account on your iPhone. Free caches are bounded to 500 threads per account; Bubble Plus caches are bounded to 1,500 threads per account.
- Downloaded attachments use protected local files, are excluded from backup where appropriate, and use oldest-first eviction. The per-account bound is 50 MB on Free and 150 MB with Bubble Plus.
- Outgoing attachments remain in composer memory and are limited to 10 files and 20 MB total.
- Templates, signatures, quick replies, saved triage views, pins, and the downloaded-attachment inventory are stored in the selected account's file-protected local root. They are not stored in StoreKit.
- Bubble securely archives each Google Sign-In SDK user object in device-only Keychain storage so multiple Gmail accounts can stay connected. Bubble does not store plaintext tokens in preferences, mailbox files, or logs.
- Bubble builds paid access in memory from verified StoreKit transactions instead of keeping a separate persistent "paid user" flag. Losing an entitlement does not delete account-derived data.
- Appearance preferences contain no mailbox content and may remain after disconnect.
6. Sharing, selling, advertising, and human access
Bubble does not sell Gmail data, share it with data brokers or advertising platforms, use it for personalized advertising, or use it for credit, surveillance, or model training. Bubble has no third-party analytics SDK in the mailbox data path.
Bubble personnel do not have a mailbox-content backend to inspect. Do not send passwords, OAuth tokens, or sensitive email contents to support.
7. Remote images, links, and message safety
Bubble converts supported HTML email into inert text and blocks remote images, tracking pixels, scripts, forms, iframes, and active HTML by default. Opening an external link is an explicit user action. No email client can eliminate every malicious-message risk, so review unexpected links and attachments carefully.
8. Disconnecting, revoking access, and deleting local data
Bubble does not create a separate Bubble account. To disconnect Gmail, open Settings in Bubble and choose the disconnect or removal action for that account. On iPhone, confirm Sign out and clear this iPhone. On the web, choose Disconnect and clear this browser.
Bubble reports a disconnect only after deleting the selected account's Keychain credential and account-derived local root, including cached mail, downloaded attachments and their inventory, indexes, synchronization checkpoints, pinned conversations, pinned people, templates, signatures, quick replies, and saved triage views. If local cleanup cannot finish, Bubble preserves a retry record instead of silently dropping the account, and retries cleanup when the app next opens. Your original mail remains in Gmail. Other connected Gmail accounts and app-wide StoreKit entitlements remain available.
Bubble also makes a best-effort request to revoke the selected Google authorization. Network, Google-account, or SDK conditions can prevent remote revocation from completing, but they do not prevent Bubble from deleting that account's local data. To confirm or remove the remote grant, review your Google Account connections.
Deleting the app removes its local app data but may not by itself revoke the Google authorization, so review Google Account connections as well.
In the web app, disconnecting revokes the current token when Google allows it, clears the selected account's IndexedDB data, and removes the account from the in-memory session. Clearing browser site data or uninstalling the web app also removes its local cache, but may not revoke Google authorization by itself.
9. Children
Bubble is a general-audience email utility and is not directed to children under 13. Bubble does not knowingly operate a service that collects children's mailbox data into a Bubble server.
10. Changes to this policy
If Bubble materially changes how it accesses or uses Gmail data, this policy and the in-app disclosure will be updated before the new use begins, and additional consent will be requested where required. The effective date above identifies the current version.
11. Contact
Questions about privacy or deletion can be sent to contactenvisiondigital@gmail.com. Please do not include passwords, authorization codes, OAuth tokens, or private email contents.