Legal

Privacy Policy

Last updated: September 7, 2026

This policy explains how meanmail.dev collects and uses personal data when you visit this website, use a JetBrains IDE plugin published by meanmail.dev, subscribe to updates, or contact us.

Who is responsible for your data

The data controller is Alexander Petrov, operating meanmail.dev from Yerevan, Armenia. You can contact us about privacy at privacy@meanmail.dev.

What this policy covers

This policy covers the meanmail.dev website and JetBrains IDE plugins published under the meanmail.dev vendor account. A product-specific notice applies instead where its data practices differ. In particular, Browseflow is covered by its product-specific privacy policy.

Data we collect and why

Website delivery and security

Cloudflare processes technical request data needed to deliver and protect the website. This may include your IP address, request URL, timestamp, browser and device information, referring page, and security signals. We use this data to operate the site, prevent abuse, diagnose errors, and maintain security.

JetBrains IDE plugins and local processing

Our JetBrains plugins run inside your IDE and can read or modify project files, execute local tools, and store plugin settings as needed to provide the features you choose to use. This processing ordinarily stays on your device and is not transmitted to meanmail.dev.

Some features connect to a service or tool that you configure, such as an AAP/AWX server, a remote runtime, or a password-manager CLI. When you invoke such a feature, the plugin sends only the data needed for that request directly to the selected service. meanmail.dev does not receive that content. The selected service processes it under its own terms and privacy policy.

Google Apps Script Support

The next-release verification candidate of Google Apps Script Support connects to Google only after an explicit action in the IDE. Login establishes a user-approved read-only OAuth grant. Only when you choose Compare with remote HEAD does the plugin use the https://www.googleapis.com/auth/script.projects.readonly scope to request the source files and manifest of the single Apps Script project identified by the Script ID in your local .clasp.json file. It uses that data only to show a read-only comparison with your local project inside the IDE.

Project source, manifests, Script IDs, Google account identity, and access tokens are not sent to or stored on meanmail.dev servers. Source data is held in memory only for the requested comparison. Short-lived access tokens remain only in memory until expiry and are never persisted. The refresh credential is stored locally in JetBrains Password Safe so you can stay signed in. The plugin does not request profile or email access and does not enumerate projects, make unattended, scheduled, or automatic Google-data requests, or write, deploy, execute, or synchronize Apps Script projects.

Google user data is not sold, shared with third parties, used for advertising, or used to train generalized AI or machine-learning models. You can use Logout in the plugin toolbar to delete the locally stored credential and can also revoke access from your Google Account. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. meanmail.dev does not sell, share, or use Google user data for advertising.

JetBrains Marketplace operations

JetBrains processes Marketplace accounts, installations, licensing, trials, purchases, and payments under its own privacy policy. JetBrains may provide us with limited customer, transaction, or support data that is necessary to operate a paid plugin, answer a support request, maintain business records, or comply with legal obligations. We do not receive payment-card details from JetBrains.

Nginx Configuration Pro 202622.0 and later

After you install version 202622.0 or later and restart the IDE, Nginx Configuration Pro does not collect or send automatic usage analytics. Previously queued Pro analytics events remain inactive and are not sent. This does not change analytics in older versions or in the separate Nginx Configuration plugin. User-submitted error reports and JetBrains licensing and Marketplace processing remain separate, as described below.

Optional plugin analytics

Django PowerTools (Beta), Nginx Configuration, and versions of Nginx Configuration Pro before 202622.0 offer optional usage analytics. These plugins ask for permission before enabling analytics. Denying or dismissing the request leaves analytics disabled.

If you allow analytics, Django PowerTools sends the JetBrains permanent installation identifier. When a licensed-to value is available, it uses a one-way hash of that value as the event identifier and also sends the permanent installation identifier as an anonymous-linking identifier. The Nginx plugins instead send a vendor-scoped random UUID stored on the device. Its local record is bound to a fingerprint derived from the hostname and operating-system username; that fingerprint and the raw hostname and username are not transmitted.

The analytics payload also includes plugin ID and version; IDE name, version, and build; operating-system name, version, and architecture; license state and trial timing where applicable; and feature events, aggregate feature counts, and product milestones. PostHog also receives network metadata such as the IP address needed to deliver the request.

The Nginx plugins may additionally send derived configuration characteristics such as file and line counts, whether includes are present, module usage, and directive names, including names that are not recognized by the plugin. Apart from those disclosed directive names, plugin analytics do not send project file contents, complete source lines, project names, file paths, or secret values. We use these events to understand compatibility, feature use, trial experience, and product priorities.

User-submitted error reports

Error reports are sent only after you choose a submission action in the IDE. Most meanmail.dev plugins use JetBrains Marketplace error reporting. Requirements and Requirements Pro can submit reports to Sentry. A report may contain a stack trace, error message, information you add, plugin and IDE versions, and the event time. The IDE shows a notice before submission. Review the report and remove personal data, source code, credentials, file paths, or other confidential information that you do not want to share. We use submitted reports to diagnose defects, provide support, and protect product security.

Website analytics

If you accept optional data collection, we use Google Analytics 4 to understand visits and interactions. It may process page views, referral source, approximate location, browser and device information, and actions such as product views or outbound Marketplace clicks. Google Analytics uses a first-party cookie such as _ga containing a randomly generated client identifier. We do not enable Google Signals or advertising personalization, and we do not send email addresses to Google Analytics. Analytics event and user data in our property is retained for 14 months.

With the same permission, we use PostHog for a limited set of anonymous product-discovery events. For this website, PostHog autocapture, session replay, heatmaps, exception capture, performance capture, and surveys are disabled. PostHog stores a randomly generated anonymous browser identifier in localStorage so visits from the same browser can be recognized over time. We do not call PostHog's identification API or link this identifier to your email or an account. Query strings and URL fragments are removed before URLs are sent, and browser Do Not Track signals are respected. The browser identifier remains until you withdraw permission or clear this site's stored data. Analytics events are retained only while they remain useful for aggregate product and website analysis.

Newsletter and communications

If you subscribe to the newsletter, we send your email address to Resend so it can maintain the subscriber list and deliver messages. We retain it until you unsubscribe or ask us to delete it. Analytics receives the email domain and signup location, but not the full email address. If you contact us directly, we process the information in your message to respond and retain correspondence only as long as reasonably necessary for support, recordkeeping, or legal obligations.

Embedded content and external links

Some pages embed YouTube videos or a GitHub Sponsors button. When that content loads, the provider may receive technical data such as your IP address, browser information, and the page you visited, and may use its own cookies. Links to JetBrains Marketplace and other external websites are governed by those websites' privacy policies after you leave meanmail.dev.

Advertising measurement

If you accept optional data collection, the site loads the LinkedIn Insight Tag. LinkedIn may receive the page URL, referrer, IP address, timestamp, and browser or device characteristics, and may use cookies or similar identifiers. LinkedIn uses this data to measure advertising performance, understand website audiences, and support retargeting under its own privacy settings and policies. We do not send newsletter email addresses to the tag or use LinkedIn enhanced matching in the website code.

Your analytics choice

Google Analytics, PostHog, and the LinkedIn Insight Tag do not load before you accept optional data collection. We use Basic Consent Mode v2, so rejected or undecided visits do not send analytics pings to Google. Your choice is stored in your browser's localStorage under a site-specific preference so we can apply it on later visits.

For a plugin that offers optional analytics, use that plugin's Analytics page in the IDE settings to disable future collection. Disabling it stops new events; data already submitted remains subject to the retention and deletion rules below. You can contact privacy@meanmail.dev to request access or deletion and may need to provide the relevant pseudonymous identifier so we can locate the records.

You can change your choice at any time using “Privacy choices” in the site footer. Withdrawing permission stops optional tracking and removes the first-party Google Analytics and PostHog identifiers available to this website. You may also need to use LinkedIn's controls or your browser settings to remove identifiers stored by LinkedIn.

Legal bases

Depending on the context, we process personal data because:

  • it is necessary for our legitimate interests in delivering and securing the website, preventing abuse, and responding to requests;
  • you consent to optional analytics and advertising measurement or plugin analytics, submit an error report, or subscribe to marketing communications, and you may withdraw that consent at any time; or
  • processing is necessary to provide a requested plugin or Marketplace service, respond to your request, maintain business records, or comply with a legal obligation.

Service providers and international transfers

We use the following service providers:

  • Cloudflare for hosting, delivery, and security;
  • Google for Google Apps Script API access initiated by Google Apps Script Support and for website analytics;
  • PostHog for limited website and optional plugin analytics;
  • JetBrains for Marketplace distribution, licensing, purchases, and user-submitted error reporting;
  • Sentry for error reports that Requirements and Requirements Pro users explicitly submit;
  • Resend for newsletter contact storage and email delivery; and
  • LinkedIn for advertising measurement and website audience insights.

These providers may process data in countries outside your country of residence, including the United States. Where required, transfers are protected through contractual or other legally recognized safeguards offered by the relevant provider.

Website analytics events in our Google Analytics property are retained for 14 months. PostHog website and plugin analytics are retained only while useful for aggregate product analysis. Error reports and related support correspondence are retained until the issue is resolved and no longer needed for support, security, recordkeeping, or legal claims. Marketplace customer, transaction, and business records are retained while needed for an active subscription, support, or accounting, and then for the period required by applicable tax, consumer-protection, dispute, and other legal obligations. We delete or aggregate data when the applicable purpose and retention period end.

Your choices and rights

You can unsubscribe from marketing emails using the link in any email. You can reopen “Privacy choices” in the footer to accept or reject optional analytics. You can also block or delete cookies and local storage through your browser, enable Do Not Track, or use the Google Analytics opt-out add-on. Blocking analytics does not prevent you from using the website.

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, object to certain processing, withdraw consent, and complain to your local data protection authority. To exercise a right, email privacy@meanmail.dev. We may need to verify your identity before completing a request.

We do not sell personal data. You can manage LinkedIn advertising preferences through LinkedIn's privacy and advertising controls.

Children's privacy

The website and plugins are intended for a general developer audience and are not directed to children. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy when our website or data practices change. We will publish the revised policy here and update the date at the top of the page.