Privacy Policy
Last updated: September 17, 2026 — revised for version 2.1.5. Previously published as “WhatsApp Chat Sync to Gmail”; the app is the same, renamed because it is no longer Gmail-only.
This app copies WhatsApp chat exports that you provide into your own mailbox. It runs entirely on your device. There is no backend server and no account system — the developer never receives, stores, or has access to your messages, your mail, or your accounts. This version carries no analytics, no advertising and no third-party SDK of any kind.
One promise does not depend on which version you are reading: your chats, your attachments and your credentials go only to the mailbox you name. They are never sold, never used to target anything at you, and never sent to the developer or to anyone else. If a future version ever collects anything at all, this page and the store listing's data-safety declaration change with the release that does it — before you install it, not after.
There is one way to connect: an email app password over IMAP, which works with any IMAP provider, including Gmail, Yahoo, iCloud and Fastmail.
None of this has to be taken on trust. The app is open source, and every claim on this page can be checked against the code that is supposed to keep it: github.com/harshalambani/ChatMailSync.
No account is created, and nothing is registered with the developer or with any server:
APPEND command, which adds a message to a
folder. It creates the folders it needs and lists folder names to check
whether they already exist. It does not fetch, search, modify or
delete any message already in your mailbox, and it never sends
mail. To be exact about
what enforces this: an app password is not something your provider can
restrict to a subset of operations, so the limit is the
app's own code, whose entire mail command surface is the four commands just
described. The
source is
public and the check takes about a minute.
Your mail provider necessarily sees the messages you archive, because they are stored in the mailbox they host for you. That relationship is governed by your provider's own privacy policy, not this one.
The developer retains nothing, because the developer never receives anything. On your own device, the saved app password is kept until you clear it in the app or uninstall, and the local dedup database is stored until you uninstall or clear the app's data. That database holds the names of the chats you have synced, the export filenames, and a one-way hash of each message it has sent — no message text and no attachments.
Emails the app has added to your mailbox are yours — delete them like any other message at any time. The app cannot do it for you, and that is by design rather than an omission: it holds no permission to delete anything in your mailbox, so nothing it could be told to do, and no defect in it, can remove mail you already have.
Nowhere but your own device and your own mailbox. The WhatsApp export file you share or import is copied into the app's private storage on your device, parsed there, and sent directly from your device to your mail provider's IMAP server over TLS. There is no intermediate server operated by the developer that your messages, attachments, or credentials ever pass through.
The app keeps a small local database on your device — chat names, sync status, and a hash of each message sent — purely to avoid sending the same message twice. It stays on your device unless you export a backup of it yourself. Deleting the app removes it.
A new phone with no copy of that database would re-send your entire history, so the app can write a backup file for you to carry across. It is written only when you ask for one, never automatically and never anywhere but where you choose to put it.
What the file contains is fixed and deliberately narrow: the dedup database described above, and a short list of preferences — theme, batch size, IMAP host, port and email address. It contains no password and no credential of any kind. The app builds it from a list of keys that are permitted to travel rather than by removing ones known to be secret, and it refuses to write the file at all if a key that looks like a credential ever appears on that list. Your new device asks you for the app password once, as a fresh install would.
The backup is an ordinary zip file and it is not encrypted. Once written it is a file like any other: the app does not know where you put it and cannot reach it again. Because it names the chats you have synced and your email address, treat it as you would any personal document, and prefer moving it directly between your own devices over leaving it somewhere shared.
Because the messages you sync are sensitive personal data, the app is built so that this data is exposed to as few systems as possible:
Because your data lives only on your own device and in your own mailbox, we recommend protecting both with the usual safeguards — a device lock/OS-level encryption, and two-step verification on your mail account.
Clear the saved password in the app (Settings → Forget saved password), and revoke the app password with your mail provider so it cannot be used again.
Revoking access does not delete anything already synced — those are ordinary emails in your mailbox and are yours to keep or delete like any other message.
None. The app does not share, sell, or transmit any data to any third party. The only network calls it makes are to the IMAP server you name, directly from your device.
If this policy changes, the updated version is published at this same address with a new "Last updated" date, and is carried in the app from the next release.
Questions about this policy or the app can be sent to the developer at chat.mail.sync+privacy@gmail.com, or raised as an issue on the GitHub repository. The full source is there too, for anyone who would rather read the code than the promise.