Privacy Policy
Last updated: April 2026
1. Information We Collect
We collect information you provide when creating an account, including your name, email address, and organization details. We also collect usage data to improve our services.
- Account information: Name, email address, password (hashed), organization name
- Communication data: Messages are end-to-end encrypted using the Signal Protocol and cannot be read by Olbongo
- Usage data: Feature usage analytics, login timestamps, device information
- Third-party account data: When you connect external services (e.g., Gmail), we store authentication tokens securely to provide the service
2. Google User Data
When you connect your Google account to Olbongo, we request access to the following Google services:
- Gmail (IMAP/SMTP access): To read, send, and manage your email directly within Olbongo. We access your email messages, attachments, and labels.
- Google Contacts (read-only): To import your contacts into Olbongo for easier communication.
- User profile information: Your name and email address to identify your connected account.
How We Use Google Data
- Gmail data is used solely to display, send, and manage your email within the Olbongo application
- Google Contacts data is used to populate your Olbongo address book
- We do not use Google user data for advertising purposes
- We do not sell, rent, or share Google user data with third parties
- We do not use Google user data for any purpose other than providing the Olbongo mail and contacts features
How We Store Google Data
- OAuth tokens (access and refresh tokens) are encrypted at rest and stored in our secure database
- Email messages are cached locally on your device for offline access and synced via IMAP
- We retain your Google authentication credentials only while your account is connected
- When you disconnect your Google account, all stored tokens and cached data are permanently deleted
Google Data Sharing
Olbongo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How We Use Information
We use your information to:
- Provide, maintain, and improve Olbongo services
- Communicate with you about your account and service updates
- Ensure the security and integrity of our platform
- Provide customer support
- Comply with legal obligations
4. Data Security
We implement industry-standard security measures to protect your data:
- End-to-end encryption for all messages using the Signal Protocol (X3DH + Double Ratchet)
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Argon2 password hashing
- Regular security audits and vulnerability assessments
5. Data Retention
We retain your account data for as long as your account is active. When you delete your account:
- Your profile and account data are permanently deleted within 30 days
- Connected third-party service tokens are immediately revoked and deleted
- Cached email and contact data are permanently deleted
- Encrypted messages are removed from our servers (messages already delivered to other users remain under their control)
6. Your Rights
You have the right to:
- Access and download your personal data
- Correct inaccurate data
- Delete your account and associated data
- Disconnect third-party services at any time
- Revoke Google account access from your Google Account permissions page
7. Contact
For privacy-related questions or data requests, contact us at:
- Email: privacy@olbongo.co.tz
- Website: olbongo.co.tz