Legal

Privacy Policy

Last updated: 28 July 2026

AetherPortal ("we", "us", the "Service") is an independently operated, personal software project run by a single developer. It is not a company, and this policy is written in plain language rather than formal legal boilerplate. If anything here is unclear, contact thompaslambourne@gmail.com.

This policy covers the AetherPortal ecosystem, including AetherID (sign-in), AetherMail (webmail and mobile app), and AetherGames.

What we collect

Depending on which part of AetherPortal you use, we may store:

  • Account identity: the username associated with your AetherID sign-in, used to identify you across AetherPortal services. We do not separately collect your name or a password of our own — sign-in is handled by AetherID.
  • Linked mailbox credentials (AetherMail only): if you link an external email account (Gmail, Outlook, or a custom IMAP/SMTP provider), we store what's needed to connect to it — either an encrypted password/app password, or an encrypted OAuth refresh token if you signed in with Google or Microsoft. These are encrypted at rest and are never shown back to you or anyone else in plain text.
  • Email content: AetherMail fetches your messages live from your mail provider over IMAP to display them, and caches a copy locally (subject line, sender, a text/HTML preview, and read/flag status) so you can read recent mail while offline. This cache is deleted if you unlink the account.
  • Mobile app sign-in tokens: if you use the AetherPortal mobile app, a device-specific access token is stored (as a one-way hash on our side) so the app can stay signed in without repeatedly asking you to log in.

Google user data specifically

If you choose "Sign in with Google" inside AetherMail to link a Gmail account, we request access to read, send, and manage mail in that account (IMAP/SMTP access) purely so AetherMail can function as a webmail client for it — exactly the same access a mail app like Outlook or Apple Mail would request. Specifically:

  • We use this access only to display your messages within AetherMail, send mail on your behalf when you compose one, and reflect actions you take (read/flag/delete/move/create folders).
  • We do not use Google user data for advertising, and we do not sell it, rent it, or share it with any third party.
  • No human reviews your email content; it is processed automatically to render it in the app.
  • You can revoke this access at any time from inside AetherMail (remove the account) or directly from your Google Account's third-party access settings, either of which stops all further access immediately.

How we use what we collect

Solely to operate the Service: authenticating you, connecting to mail accounts you've chosen to link, displaying and sending your mail, and keeping your mobile app session signed in. We don't use your data for advertising, profiling, or any purpose beyond making the product work.

Data sharing

We do not sell or share your data with third parties. Your mail is transmitted directly between AetherMail's servers and your mail provider (Google, Microsoft, or another IMAP/SMTP server) to do the job you asked it to do — display or send your mail — and nowhere else.

Data retention & deletion

Linked-account credentials and cached messages are kept for as long as the account stays linked. Removing a linked account from AetherMail deletes its stored credentials and cached messages immediately. Removing your AetherID account removes everything associated with it across AetherPortal services. To request deletion, email thompaslambourne@gmail.com.

Security

Credentials and OAuth refresh tokens are encrypted at rest (AES-256-GCM). All traffic to AetherPortal services is served over HTTPS. Mobile app tokens are stored as one-way hashes, not plaintext, so a database compromise alone can't be replayed as a live session.

Children's privacy

AetherPortal is not directed at children under 13, and we don't knowingly collect data from them.

Changes to this policy

If this policy changes materially, the "Last updated" date above will change accordingly. Continued use of the Service after an update means you accept the revised policy.

Contact

Questions about this policy or your data: thompaslambourne@gmail.com.