PRIVACY

Privacy Policy

Effective August 11, 2026

Who operates the service

Ordinal Doctrine operates Ordinal Doctrine Mail and decides how the service data described below is used. Contact the Privacy Desk at andrea@nprit.co.kr.

Information, purpose and retention

InformationPurpose and basisRetention in Ordinal Doctrine
Gmail address; encrypted OAuth access and refresh tokens; granted scopes; sync cursorsConnect the Gmail account and provide the mail client requested by the userUntil the user deletes the service data.
Message and thread IDs; dates; unread status; From, To, CC, Bcc and Reply-To names and addresses; subject; message body; attachment name, size, type and Gmail attachment IDShow, search and synchronize the connected mailbox as a person-based history. This can include personal information about correspondents.Until service-data deletion. During beta, up to the 50,000 most recent messages are stored per account. Message bodies are limited to 50,000 characters and may be shortened further to keep each stored message within 64 KiB.
Recipients, subject, body and attachments selected for an outgoing message; delivery status; provider message/thread ID; operation ID and payload hashSend only the message the user confirms through Gmail and prevent accidental duplicate deliveryUntil service-data deletion. Attachment bytes are handled only for the request and are not stored in the synchronized database.
Support email address and support message contents voluntarily suppliedReply and provide requested supportUp to 90 days after resolution or the last response, unless law requires longer retention. The sender may request earlier deletion.
Session cookie and hashed session token; active account; hashed email/IP and minute-level request countKeep the user signed in, secure the service and limit abuseSessions expire after 30 days and are deleted by the hourly cleanup within one additional hour. Rate-limit records are deleted when older than 24 hours, within the next hourly cleanup.
Organization name; accepted Privacy Policy, Terms and DPA versions; business-authority confirmation; Google-data consent; acceptance timeIdentify the instructing organization and record its instructions and the user’s affirmative authorization before connecting GmailUntil service-data deletion
Contact aliases and private markers entered by the userPersonalize names and make messages easier to findStored only in that browser until the user deletes the service data or clears browser storage.
Unsent draft mode, recipients, subject, body, reply/forward IDs and send-operation ID (attachments are not stored)Restore an unfinished draft on the same browserStored only in that browser. After 14 days it is no longer restored and is deleted the next time the app checks that account; send, discard, sign-out, service-data deletion or browser-storage clearing deletes it earlier.

Google API Limited Use

Ordinal Doctrine's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not sold, used for advertising, used to determine creditworthiness, or used to train generalized AI models.

Providers and international processing

Provider and roleData and purposeLocation and duration
OpenAI OpCo, LLC — ChatGPT Sites host; Cloudflare, Ltd. is an infrastructure subprocessor. Sites DPAHosted account, mailbox, security and request data needed to run the site, Worker and databaseUnited States and other infrastructure locations used by the providers. Sites does not currently offer the operator a data-residency choice. Processed for the hosting term and the providers’ deletion obligations.
Google LLC — connected Gmail provider. Google privacy policyGmail address, OAuth authorization, mailbox data requested through the Gmail API, and messages/attachments the user asks Gmail to sendUnited States and other Google server locations; when the user connects or uses Gmail features; retained by Google under the Google account and its policy.
Daou Technology Inc. — DaouOffice business email provider. Daou TechnologySupport email address and message contentsSouth Korea; when the user sends a support email and while the correspondence is retained as described above.

Sharing and human access

We do not sell mailbox data or provide it to advertisers. Data is processed by the providers above only as needed to operate a feature the user requests, or when disclosure is required by law or necessary to address security abuse. People do not read mailbox content unless the user gives permission for a specific support case, access is required to address a security incident, or access is legally required.

Cookies and local storage

The service uses a necessary 30-day sign-in cookie, 10-minute legal-confirmation and OAuth-state cookies, and Cloudflare security cookies such as __cf_bm (normally 30 minutes after inactivity). Blocking necessary cookies prevents account connection. Private markers, aliases and unsent drafts use browser localStorage; blocking or clearing it removes their persistence. There are no advertising or analytics trackers in the application.

Deletion

In Mail accounts, choose Delete service data. The service first asks Google to revoke access for every connected Gmail account, then deletes those connections, encrypted OAuth credentials, synchronized messages, delivery records, policy-acceptance record and service sessions from the active application database. It also clears private markers, aliases and unsent drafts from the current browser when deletion is initiated there. Original mail remains in Gmail as the Customer's return copy, and another browser's local storage is not cleared. If Google cannot confirm revocation for an account, the app reports the number of failures after local deletion; remove the remaining grant in Google Account permissions. Infrastructure copies follow the providers' retention and deletion terms.

Your choices and rights

You may view the synchronized data in the app, correct original mail or contacts in Gmail, edit local aliases and markers, and delete the service data in Mail accounts. You may also request access, correction, deletion, suspension of processing or information about the source of personal data by emailing andrea@nprit.co.kr. We may verify the requester's identity before acting.

Security

The hosted D1 database is encrypted at rest with AES-256, and OAuth credentials receive additional application-level AES-GCM encryption. The service uses HTTPS, secure and HttpOnly cookies, access controls, same-origin checks, request limits and deletion controls. No internet service can guarantee absolute security.

Business use and sensitive information

The beta is offered only to users aged 18 or older acting for an organization. The organization controls the lawfulness of mailbox content and instructs Ordinal Doctrine as described in the DPA. A mailbox may contain sensitive information about the user or other people; do not use the beta for regulated sensitive-data workflows unless Ordinal Doctrine agrees in writing after appropriate legal review.

Changes

We update this policy when the service's data handling changes. A material change will be announced on the site before it takes effect where required.