Skip to content
Fantodic.
Home Terms Open Fantodic

Fantodic legal

Privacy Policy

Last updated August 25, 2026

This policy explains what information Fantodic accesses, why it is used, where it is stored, and the choices available to the authorized user.

1. Scope

Fantodic is a private email workspace that connects supported Gmail, Microsoft Outlook, and Zoho Mail accounts for one authorized user. This policy applies to the Fantodic website and hosted application.

2. Information Fantodic accesses

Account information

When an account is connected, Fantodic receives basic identity information from the provider, including the account identifier, email address, display name, provider name, and—where applicable—the provider region.

Authorization information

Fantodic receives OAuth access and refresh tokens. These tokens allow the application to make authorized requests to the selected mail provider without receiving or storing the user’s provider password.

Mailbox information

Fantodic may access mailbox folders or labels, message metadata, message bodies, conversation content, attachment metadata, attachment content requested by the user, read status, and starred or flagged status.

3. Provider permissions and purposes

  • Google Gmail: Fantodic requests identity information and Gmail modification access so it can display mail, list labels, download user-requested attachments, mark messages read or unread, star or unstar messages, and move messages between labels or folders.
  • Microsoft Outlook: Fantodic requests identity, offline access, and Mail.ReadWrite permission so it can display and organize mail and keep the connection available between sessions.
  • Zoho Mail: Fantodic requests read-only account, folder, and message permissions. The Zoho integration does not modify messages.

Fantodic limits its use of this information to operating and securing the mailbox features initiated by its authorized user.

4. How information is used

Information is used to connect accounts, identify the selected mailbox, retrieve and display folders and messages, perform mailbox actions requested by the user, refresh authorization, diagnose operational errors, and protect access to the application.

Fantodic does not sell personal information, serve targeted advertising, or use Google user data to train generalized artificial-intelligence or machine-learning models.

5. Storage and security

Connected-account metadata and encrypted OAuth tokens are stored in a Cloudflare D1 database. OAuth token bundles are encrypted using AES-GCM before they are written to the database. Mailbox message content is requested from the relevant provider when the user uses the application; Fantodic does not intentionally maintain a separate server-side archive of message bodies or attachments.

The private mailbox application is protected with Cloudflare Access and an allowlist for the authorized user. The browser may store limited interface preferences, such as the most recently selected account, folder, and expanded-folder state.

6. Sharing and service providers

Fantodic does not sell or rent personal information. Information may be processed by Cloudflare as the hosting, access-control, and database infrastructure provider, and exchanged with Google, Microsoft, or Zoho as necessary to provide the connected-mailbox features. Information may also be disclosed if required by law or to protect the security and integrity of the service.

7. Google API Services User Data Policy

Fantodic’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

8. Retention and deletion

Connected-account metadata and encrypted tokens are retained while the account remains configured for use with Fantodic. The user may revoke Fantodic’s access at any time through the security or connected-app settings of Google, Microsoft, or Zoho. To request deletion of Fantodic’s stored connected-account metadata and tokens, contact the address below. Operational security logs may be retained for a limited period by the infrastructure provider.

9. Choices and rights

The authorized user may choose which supported accounts to connect, decline provider permissions, revoke previously granted access, or request access to or deletion of stored account information. Applicable law may provide additional privacy rights.

10. Changes to this policy

This policy may be updated when Fantodic’s functionality or data practices change. The revised policy will be posted on this page with a new “Last updated” date.

11. Contact

Questions or deletion requests may be sent to danny@dallinstone.com.

Fantodic.

Personal mail, in one place.

HomePrivacy PolicyTerms of Service