Privacy Policy
Bubble is an iPhone email client that presents an existing Gmail mailbox as people-first conversations. This policy explains how Bubble accesses, uses, stores, shares, and deletes information.
1. Information Bubble accesses
When you connect Gmail, Bubble may access the information needed to provide its visible email features:
- Your Google account name, email address, and opaque Google account identifier.
- Gmail thread and message identifiers, subjects, sender and recipient addresses, timestamps, labels, snippets, message bodies, and attachment metadata.
- Attachment contents only when you choose to download or send an attachment.
- Gmail synchronization checkpoints and the email addresses or thread identifiers you choose to pin.
- OAuth authorization information created through Google Sign-In and stored as a secure SDK user record in Apple's device-only Keychain for each Gmail account you add.
Bubble does not request iOS permissions for Contacts, Photos, Location Services, microphone, or camera, and it does not request advertising identifiers or unknown Bcc recipients for its current features.
More precisely, Bubble does not request the iOS Location Services permission. Google's sign-in SDK has its own broader privacy declaration, described below.
2. How the information is used
Bubble uses Gmail data only to provide user-facing features:
- Display, search, filter, and organize your conversations.
- Clean email presentation by collapsing quoted history, signatures, and active or remote content without destroying the original representation.
- Compose, reply, reply all, and send mail using recipients you can review before sending.
- Apply actions you request, such as read or unread, star, archive, move to Trash, restore, and undo.
- Cache a bounded recent mailbox on your device for speed and limited offline access.
Bubble's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Where information goes and SDK disclosures
Gmail content is requested directly from Google's Gmail API by the Bubble app and is presented or stored on your iPhone. Bubble does not copy mailbox content to a Bubble-operated server.
Bubble uses Google Sign-In and supporting authentication libraries to authorize Gmail access. Google processes information according to your Google account choices and Google's policies. Apple provides the device, operating system, protected local storage, and App Store distribution.
The Google Sign-In 9.2.0 SDK privacy manifest declares that it may collect the following information, linked to your identity and not used for tracking:
- Name, email address, phone number, and coarse location for app functionality.
- Other data types and user ID for app functionality and analytics.
- Device ID and other usage data for analytics.
This SDK declaration is separate from Bubble's own app code. Bubble does not add an analytics SDK, request iOS Location Services permission, or use any of this information for advertising or tracking.
These public policy and support pages use hosting infrastructure that may process ordinary web-request information, such as an IP address, browser type, requested page, and security logs, to deliver and protect the pages. The pages do not intentionally use cookies, advertising, analytics, account sign-in, or mailbox data.
4. Storage and retention
- Recent mail is kept in a separate encrypted, file-protected cache for each Gmail account on your iPhone. Each current cache is bounded to 500 threads.
- Downloaded attachments use protected local files, are excluded from backup where appropriate, and are bounded to 50 MB with oldest-first eviction.
- Outgoing attachments remain in composer memory and are limited to 10 files and 20 MB total.
- Bubble securely archives each Google Sign-In SDK user object in device-only Keychain storage so multiple Gmail accounts can stay connected. Bubble does not store plaintext tokens in preferences, mailbox files, or logs.
- Appearance preferences contain no mailbox content and may remain after disconnect.
5. Sharing, selling, advertising, and human access
Bubble does not sell Gmail data, share it with data brokers or advertising platforms, use it for personalized advertising, or use it for credit, surveillance, or model training. Bubble has no third-party analytics SDK in the mailbox data path.
Bubble personnel do not have a mailbox-content backend to inspect. Do not send passwords, OAuth tokens, or sensitive email contents to support.
6. Remote images, links, and message safety
Bubble converts supported HTML email into inert text and blocks remote images, tracking pixels, scripts, forms, iframes, and active HTML by default. Opening an external link is an explicit user action. No email client can eliminate every malicious-message risk, so review unexpected links and attachments carefully.
7. Disconnecting, revoking access, and deleting local data
Bubble does not create a separate Bubble account. To disconnect Gmail, open Bubble, tap the settings gear, choose Sign out, and confirm Sign out and clear this iPhone.
This revokes Bubble's access for the selected Gmail account and deletes that account's Keychain credential, local cache, downloaded attachments, indexes, synchronization checkpoints, pinned conversations, and pinned people. Your original mail remains in Gmail. If you connected other Gmail accounts, they remain available in Bubble.
You can also remove Bubble's access from your Google Account connections. Deleting the app removes its local app data but may not by itself revoke the Google authorization, so use one of the revocation methods above as well.
8. Children
Bubble is a general-audience email utility and is not directed to children under 13. Bubble does not knowingly operate a service that collects children's mailbox data into a Bubble server.
9. Changes to this policy
If Bubble materially changes how it accesses or uses Gmail data, this policy and the in-app disclosure will be updated before the new use begins, and additional consent will be requested where required. The effective date above identifies the current version.
10. Contact
Questions about privacy or deletion can be sent to eapeal8@gmail.com. Please do not include passwords, authorization codes, OAuth tokens, or private email contents.