1. Who we are
Kolbaba is run by Jakub Šťastný, a sole trader (OSVČ) registered in the Czech Republic, IČO 08542953, with registered place of business at Rečkova 1597/6, 130 00 Praha 3 – Žižkov, Czech Republic (“we”, “us”). We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).
For anything about your data, write to hello@kolbaba.app. We haven’t appointed a data protection officer (we aren’t required to), so that address reaches the person responsible directly.
This policy covers the website kolbaba.app and the Kolbaba app at app.kolbaba.app, whether you use it in a browser or installed on your home screen.
2. The short version
- We keep a copy of your mail on our servers so Kolbaba is fast on every device. Your mailbox provider (Gmail, Seznam and others) still holds the original.
- Passwords and tokens for your mailboxes are encrypted. For passkeys we store only the public key.
- No ads, no selling or renting of data, no analytics or tracking cookies, and no AI training on your mail.
- Kolbaba has no built-in AI. Your mail reaches an AI agent only if you connect one, and only from the mailboxes you share with it.
- Read tracking is off by default. When you turn it on, we never store recipients’ IP addresses or location.
- When you disconnect a mailbox, we delete our copy of it. You can have your whole account deleted at any time.
3. What data we process
Your account
Your email address and name, your profile picture if you sign in with Google, your signatures and your settings (for example list density, accent colour, whether to load remote images, the undo-send delay and whether read tracking is on by default).
Signing in
- Passkeys: the credential ID and public key, a usage counter, whether the passkey is synced between devices, a label guessed from your browser (such as “iPhone”), and when it was created and last used. The private key never leaves your device or password manager.
- Sign in with Google: your Google account ID, email address, name and profile picture.
- Sessions: for each signed-in browser, a hashed session token, the browser’s user agent, and when the session started, was last used and expires.
- While sign-up is invite-only, we check your email address against the list of invited addresses.
Connected mailboxes
The mailbox address, the provider and its server settings, your app password or OAuth tokens (encrypted), the sync state, the name, colour and icon you pick, your sender name and whether the mailbox is shared with AI agents.
Your mail
To show, search and organise your mail, we keep a copy of the messages in your Inbox, Sent and Archive (for Gmail: all mail except Spam, Trash and drafts):
- senders and recipients (names and addresses, including Cc, Bcc and Reply-To), subject, date and the technical headers that group messages into conversations;
- the message body (HTML and plain text) and a short preview;
- names, types and sizes of attachments;
- folders or labels, read and pinned status, the unsubscribe link of newsletters and the sender’s company domain (used to show its logo);
- a search index built from the subject, sender, preview and body.
The first import goes back 90 days; older mail stays only with your provider. After that, new mail is added as it arrives. Attachment files are not stored on our servers: we fetch them from your mailbox when you open or download them.
What you create in Kolbaba
Drafts, outgoing and scheduled messages (each send waits in a queue for the undo window or until its scheduled time), snoozes, follow-up reminders and pins. Recipient suggestions are worked out from your recent mail; we keep no separate address book.
Read tracking, notifications and AI agents
- Read tracking: see section 7.
- Push notifications: for each device where you turn them on, the push address issued by your browser’s push service, its encryption keys and the browser’s user agent.
- AI agents: see section 6.
Technical data
Our hosting providers process technical data for every request (IP address, time, the address requested and the browser type) and keep short-lived logs to run the service and keep it secure. Our own database stores no IP addresses.
On your device
So that Kolbaba opens instantly and works offline, the app keeps your most recent conversations (up to 400, including message bodies), your mailboxes and drafts in your browser’s storage (IndexedDB), plus a few display preferences in local storage. Signing out clears this cache.
When you contact us
Your email address and whatever you write to us.
Where the data comes from
From you; from Google when you sign in with Google or connect Gmail; from your mailbox providers (your mail); from AI agent apps you connect (their name, logo and technical details); and from the mail apps of people who open an email you chose to track. You must give us an email address to create an account and access to a mailbox to connect it. Everything else is optional.
4. Why we process data and on what legal basis
- To provide Kolbaba to you (Art. 6(1)(b) GDPR, contract): your account and sign-in; syncing, showing, searching and organising your mail; sending and scheduling; snooze, reminders and notifications; read tracking for the emails you choose; the AI agent access you set up; and support.
- Legitimate interests (Art. 6(1)(f) GDPR): keeping Kolbaba and your data secure, preventing abuse and fraud, technical logs, fixing bugs and defending legal claims. Our interest is running a safe and reliable service. You can object to this processing (section 14).
- Consent (Art. 6(1)(a) GDPR): passing your mail to an AI agent you connect (section 6). You can withdraw consent at any time by disconnecting the agent; this doesn’t affect what was processed before.
- Legal obligations (Art. 6(1)(c) GDPR): answering lawful requests from authorities, handling your data protection requests and, if we ever charge for Kolbaba, keeping accounting and tax records.
We don’t use your data for advertising, marketing profiles or AI training, and we don’t sell it.
5. Google user data
This section explains how Kolbaba handles data it receives from Google APIs: when you sign in with Google and when you connect a Gmail or Google Workspace mailbox.
Kolbaba's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access and why
- Sign in with Google (scopes openid, email, profile): your Google account ID, email address, name and profile picture. We use them only to create your Kolbaba account and sign you in.
- Connecting Gmail (scope https://www.googleapis.com/auth/gmail.modify, plus openid, email and profile to identify the mailbox): we read your messages with their headers, labels and attachments; change labels and status when you, or an AI agent you authorised, archive, mark as read or unread, pin (star), move to Spam or move to Trash; send the email you write or schedule; and sign up for Gmail change notifications so new mail appears right away. gmail.modify is the narrowest single scope that covers reading, organising and sending. It doesn’t allow permanent deletion, and Kolbaba never permanently deletes your mail.
How we use it
Only to provide and improve the user-facing features of Kolbaba that you see in the app: showing, searching and organising your mail, sending and scheduling, snooze and follow-up reminders, notifications, recipient suggestions, read tracking of your own sent mail and access for AI agents you connect.
What we never do with it
- Use it for advertising, including retargeting, personalised or interest-based ads.
- Sell it, or pass it to data brokers, information resellers or advertising platforms.
- Use it to develop, improve or train generalised or non-personalised AI or machine-learning models. Kolbaba has no built-in AI at all.
- Use it to determine creditworthiness or for lending purposes.
- Let any person read it, unless you have given us explicit permission to look at specific messages (for example, to solve a support request), it is necessary for security purposes such as investigating a bug or abuse, it is necessary to comply with applicable law, or the data has been aggregated and anonymised and is used for internal operations.
When it leaves Kolbaba
We transfer Google user data only:
- to provide user-facing features you use or explicitly turn on. Above all, an AI agent you connect through MCP receives the mail it asks for, from the mailboxes and at the permission level you chose (section 6). When Kolbaba shows a sender’s company logo, your device asks DuckDuckGo for the icon of that sender’s domain (section 9);
- to the service providers that host Kolbaba for us (section 9), under contract and only to run Kolbaba;
- for security purposes, such as investigating abuse;
- to comply with applicable laws;
- as part of a merger, acquisition or sale of assets, and only after obtaining your explicit prior consent.
Storage and protection
Google tokens are stored encrypted (AES-256-GCM, see section 12). Our copy of your Gmail is stored and deleted as described in sections 3 and 11.
Revoking access and deleting data
- In Kolbaba: disconnect the mailbox in Settings. We immediately delete its tokens and all mail, drafts, scheduled messages and read-tracking data of that mailbox from our database. Backups expire within 30 days.
- In your Google Account: remove Kolbaba under Security → Your connections to third-party apps & services (myaccount.google.com/connections). Kolbaba then can no longer access your Gmail. This alone doesn’t delete the copy we already hold, so also disconnect the mailbox in Kolbaba or ask us to delete your account.
- Disconnecting in Kolbaba deletes our tokens but doesn’t remove Kolbaba from the list in your Google Account; you can remove it there as well.
- To delete your Kolbaba account, including your Google sign-in data, write to hello@kolbaba.app.
6. AI agents (MCP)
Kolbaba includes an MCP server (Model Context Protocol) that lets AI agents such as Claude, ChatGPT or Cursor work with your mail. Kolbaba itself has no built-in AI: your mail reaches an AI provider only if you connect an agent.
How connecting works
- You add Kolbaba’s MCP address in the agent’s app. It sends you to a Kolbaba consent page (OAuth 2.1) that shows which app is asking.
- You choose which mailboxes to share. Shared mailboxes are available to all agents you have connected.
- You choose a permission level: Read only (search and read mail), Organize & draft (also archive, pin, snooze, mark as read and write drafts, but not send) or Full access (everything, including sending and scheduling email as you; you must first confirm that you understand the risk).
What the agent receives
Whatever it asks for within those limits, for example search results, whole conversations as text (senders, recipients, dates, subjects, message bodies and attachment names) and the list of shared mailboxes. We pass this data on at your direction and based on your consent.
The company behind the agent (for example Anthropic for Claude or OpenAI for ChatGPT) processes what the agent receives as an independent controller, under its own terms and privacy policy, possibly outside the EEA. Please read them before connecting. Disconnecting an agent stops further access but doesn’t delete what it has already received; ask its provider for that.
What we keep
- The agent app’s registration (name, logo and the addresses it uses to sign in) and the name and version it reports.
- Your permission level and whether access is paused.
- Access tokens (valid for 1 hour) and refresh tokens (valid for 60 days), stored only as hashes.
- AI activity: a log of every action the agent takes: what, when, in which mailbox and conversation, a short summary (which can include a subject and recipient names) and what’s needed to undo it (which can include the previous text of a draft).
You stay in control
- The AI activity timeline shows everything agents did (the app shows the last 14 days).
- You can undo reversible actions: archiving, read status, pins, snoozes and drafts, and sending or scheduling while the email still waits in the queue.
- You get a notification whenever an agent sends or schedules an email.
- You can pause an agent, change its level or disconnect it at any time in AI activity → Manage. Disconnecting deletes its tokens and its activity history.
7. Read tracking
If you use Kolbaba
Read tracking is off by default. You turn it on for each email with the Track switch, and you can change the default in Settings.
When it’s on, Kolbaba adds an invisible 1×1 image with a unique random address to the email. When the recipient’s mail app loads that image, we record the time, a rough description of the app and device (such as “iPhone · Gmail”) and whether the request came through Apple’s or Google’s image proxy. We look at the request’s IP address only in memory, to recognise Apple’s proxy, and never store it. We never store or work out a location. Your own views of the email in Kolbaba are not counted.
There is one image per email, so with several recipients we can’t tell who opened it. Many apps block images or load them in advance (Apple Mail Privacy Protection does this for every email), so an open is a hint, not proof. Opens through Apple’s proxy are shown as “delivered”, not “opened”.
Tracking is your choice. For the open data, we act on your behalf: you are responsible for having a legal basis for it and for informing recipients where the law requires it (see the Terms of Service).
If you received a tracked email
A Kolbaba user chose to track an email they sent you. We record only what is described above, show it only to that sender and never build profiles across senders. To prevent it, block remote images in your mail app. If you have questions, contact the sender, or write to us at hello@kolbaba.app and we’ll pass your request on.
8. People you exchange email with
Your mail contains personal data of the people you write with. We process it only to provide Kolbaba to you: we don’t contact them, profile them or use their data for anything else. If you use Kolbaba for work or business, you decide about that data under the GDPR and we process it on your behalf. If you are one of those people and have a question, write to us at hello@kolbaba.app.
10. Transfers outside the EEA
Some of the providers above are based in the United States or process data there (in particular Vercel, Neon, Google, browser push services and DuckDuckGo). Our servers may run in the EU or in the United States; we don’t promise EU-only storage.
Where data goes to a country without an adequacy decision of the European Commission, we rely on the EU–US Data Privacy Framework for providers certified under it, and otherwise on the European Commission’s Standard Contractual Clauses. Write to us for details. AI agent providers you choose may also be outside the EEA; that transfer happens at your direction and under their terms.
11. How long we keep data
- Account, settings and signatures: as long as you have an account.
- Copy of your mail: as long as the mailbox is connected. Messages deleted in your mailbox are removed from our copy at the next sync. When you disconnect a mailbox, we immediately delete its password or tokens and all its mail, drafts, scheduled messages and read-tracking data from our database.
- Send queue: entries for sent or cancelled emails are deleted 30 days after the send time.
- Read tracking: until you disconnect the mailbox or delete your account.
- AI activity and agent data: until you disconnect the agent or delete your account.
- Sessions: a session expires 60 days after you last used it and is deleted when you sign out.
- Push subscriptions: until you turn notifications off on that device, the push service reports the address as no longer valid, or you delete your account.
- Sign-in challenges: 5 minutes.
- Technical logs at our hosting providers: for a short time, generally no longer than 30 days.
- Emails with us: as long as needed to deal with your request, then for up to 3 years (the general limitation period under Czech law) in case of a dispute.
- Billing records, if we ever charge for Kolbaba: for the period required by Czech accounting and tax law (up to 10 years).
Deleting your account: write to hello@kolbaba.app from the address you use with Kolbaba. We delete your account and everything in it within 30 days. Copies in our database backups expire within a further 30 days. Your mail stays in your mailboxes; Kolbaba never deletes it there when you leave.
12. Security
- All connections use encryption: HTTPS for the app, and TLS is required for connections to mail servers.
- Mailbox passwords and OAuth tokens are encrypted with AES-256-GCM, each with its own key, which is in turn encrypted with a master key kept outside the database. The master key can be rotated.
- Session tokens and the tokens of AI agents are stored only as hashes, so a copy of the database can’t be used to sign in.
- For passkeys we store only the public key.
- Incoming HTML is cleaned on the server and displayed in a sandboxed frame without scripts. Remote images are blocked by default and known tracking pixels are removed.
- Every record belongs to one user and every query is limited to that user’s data.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we’ll tell you and the Czech data protection authority as the GDPR requires.
14. Your rights
Under the GDPR you have the right to:
- access your personal data and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- data portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another provider;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting earlier processing.
To use any of these rights, write to hello@kolbaba.app, ideally from the address you use with Kolbaba so we can confirm it’s you. It’s free, and we’ll reply within one month (in complex cases we can extend this by two more months and will tell you why).
You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic, that is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz. You can also complain to the authority in the EU country where you live or work.
15. Children
Kolbaba is not intended for people under 16, and they may not create an account. If we learn that someone under 16 has an account, we’ll delete it.
16. Automated decisions
We don’t make decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects. Kolbaba sorts mail automatically for display (for example, telling newsletters from personal mail), but that is a feature for you, not a decision about you.
17. Changes to this policy
When this policy changes, we update the date at the top. We’ll tell you about significant changes in the app or by email before they take effect.
This version is effective from 9 October 2026.