← Back to Dashboard

Privacy Policy

Last updated: July 3, 2026

1. Introduction

Two Hands Technology ("Company," "we," "us," or "our") operates the THT Device Email Relay service (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.

We respect your privacy and are committed to protecting your personal data. Please read this policy carefully to understand our practices regarding your information.

2. Information We Collect

2.1 Account Information

When you register for the Service, we collect:

  • Your name and email address
  • Organization name (if provided)
  • Account credentials (passwords are hashed and never stored in plaintext)
2.2 OAuth Tokens

When you connect an email mailbox (Microsoft 365 or Google Workspace), we receive and store OAuth 2.0 access and refresh tokens. These tokens allow the Service to send email on your behalf. Tokens are encrypted at rest using AES-256 encryption and are only decrypted at the moment of use.

2.3 Email Relay Metadata

When the Service relays an email, we log the following metadata:

  • Sender address (the "From" address used by your device)
  • Recipient address(es)
  • Subject line
  • Timestamp of transmission
  • Delivery status (success, failure, bounce)
  • Source IP address of the sending device
  • Device authentication method used

We do not store the body content of relayed emails. Message bodies are held transiently in memory only for the duration of the relay operation and are not written to persistent storage.

2.4 Device Configuration Data

We store configuration data you provide for authenticating your devices, including:

  • Authorized IP addresses
  • Authorized send-to email addresses
  • Subject-line authentication codes
  • Device names and notes you assign
2.5 Usage Data and Analytics

We may collect standard web analytics data (page views, session duration, browser type) to improve the Service. This data is aggregated and not linked to specific email content.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery: To relay emails on behalf of your connected devices through your email accounts.
  • Authentication: To verify that incoming SMTP connections are from your authorized devices.
  • Account management: To maintain your account, process billing, and provide customer support.
  • Security: To detect and prevent unauthorized access, abuse, or fraud.
  • Service improvement: To analyze usage patterns and improve reliability, performance, and features.
  • Communication: To send you service-related notices, billing reminders, and — with your consent — product updates.

4. What We Do Not Do

We want to be explicit about what we do not do with your data:

  • We do not read the content of your relayed emails.
  • We do not sell, rent, or trade your personal information to third parties.
  • We do not use your email content for advertising or profiling.
  • We do not access your email inbox, calendar, contacts, or any data beyond the minimum OAuth scopes required to send email.
  • We do not store email body content after the relay operation completes.

5. How We Share Your Information

We may share your information only in the following limited circumstances:

  • Service providers: We use third-party hosting, database, and payment processing services. These providers have access to data only as necessary to perform their functions and are contractually obligated to protect it.
  • Legal compliance: We may disclose your information if required to do so by law or in response to valid legal process (e.g., a subpoena or court order).
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
  • With your consent: We may share your information for any other purpose with your explicit consent.

6. OAuth Scopes and Third-Party Access

The Service requests the minimum OAuth scopes necessary to function:

  • Microsoft 365: SMTP.Send — Allows the Service to send email through your connected account. We do not request Mail.Read, Mail.ReadWrite, or any scope that would give us access to your inbox.
  • Google Workspace: https://www.googleapis.com/auth/gmail.send — Allows sending only. We do not request gmail.readonly or gmail.modify.

You can review and revoke the Service's access at any time:

7. Data Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted via TLS 1.2+.
  • OAuth tokens are encrypted at rest using AES-256.
  • Passwords are hashed using bcrypt with appropriate work factors.
  • Access to production systems is restricted and audited.
  • We perform regular security reviews of our infrastructure and code.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your data for the following periods:

  • Account data: Retained for the duration of your account. You may request account deletion at any time.
  • OAuth tokens: Retained until you revoke access or delete your connected mailbox.
  • Email log metadata: Retained for operational purposes and automatically purged after 90 days (subject to change based on operational needs).
  • Device configuration: Retained for the duration of your account.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: You can request a copy of the personal data we hold about you.
  • Correction: You can request that we correct inaccurate or incomplete data.
  • Deletion: You can request that we delete your personal data, subject to legal retention requirements.
  • Portability: You can request your data in a structured, commonly used, machine-readable format.
  • Objection: You can object to our processing of your personal data in certain circumstances.
  • Restriction: You can request that we restrict processing of your personal data.

To exercise any of these rights, contact us at help@twohandstech.com. We will respond to your request within 30 days.

10. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect and how it is used.
  • The right to request deletion of your personal information.
  • The right to opt out of the sale of your personal information (we do not sell personal information).
  • The right to non-discrimination for exercising your privacy rights.

11. GDPR (European Users)

If you are located in the European Economic Area (EEA), our legal basis for collecting and using your personal data depends on the context:

  • Contract performance: Processing necessary to provide the Service you signed up for.
  • Legitimate interests: Processing necessary for our legitimate business interests (security, fraud prevention, service improvement).
  • Consent: Where we have obtained your explicit consent (e.g., marketing communications).

You have the right to lodge a complaint with a supervisory authority if you believe your rights under the GDPR have been violated.

12. Cookies

The Service uses cookies strictly for session management and authentication purposes. We do not use tracking cookies or third-party advertising cookies. By using the Service, you consent to the use of cookies for session management.

13. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Two Hands Technology

Email: help@twohandstech.com

Phone: 858-242-4422