PRIVACY
Privacy Policy
Effective August 11, 2026
Who operates the service
Information, purpose and retention
| Information | Purpose and basis | Retention in Ordinal Doctrine |
|---|---|---|
| Gmail address; encrypted OAuth access and refresh tokens; granted scopes; sync cursors | Connect the Gmail account and provide the mail client requested by the user | Until the user deletes the service data. |
| Message and thread IDs; dates; unread status; From, To, CC, Bcc and Reply-To names and addresses; subject; message body; attachment name, size, type and Gmail attachment ID | Show, search and synchronize the connected mailbox as a person-based history. This can include personal information about correspondents. | Until service-data deletion. During beta, up to the 50,000 most recent messages are stored per account. Message bodies are limited to 50,000 characters and may be shortened further to keep each stored message within 64 KiB. |
| Recipients, subject, body and attachments selected for an outgoing message; delivery status; provider message/thread ID; operation ID and payload hash | Send only the message the user confirms through Gmail and prevent accidental duplicate delivery | Until service-data deletion. Attachment bytes are handled only for the request and are not stored in the synchronized database. |
| Support email address and support message contents voluntarily supplied | Reply and provide requested support | Up to 90 days after resolution or the last response, unless law requires longer retention. The sender may request earlier deletion. |
| Session cookie and hashed session token; active account; hashed email/IP and minute-level request count | Keep the user signed in, secure the service and limit abuse | Sessions expire after 30 days and are deleted by the hourly cleanup within one additional hour. Rate-limit records are deleted when older than 24 hours, within the next hourly cleanup. |
| Organization name; accepted Privacy Policy, Terms and DPA versions; business-authority confirmation; Google-data consent; acceptance time | Identify the instructing organization and record its instructions and the user’s affirmative authorization before connecting Gmail | Until service-data deletion |
| Contact aliases and private markers entered by the user | Personalize names and make messages easier to find | Stored only in that browser until the user deletes the service data or clears browser storage. |
| Unsent draft mode, recipients, subject, body, reply/forward IDs and send-operation ID (attachments are not stored) | Restore an unfinished draft on the same browser | Stored only in that browser. After 14 days it is no longer restored and is deleted the next time the app checks that account; send, discard, sign-out, service-data deletion or browser-storage clearing deletes it earlier. |
Google API Limited Use
Providers and international processing
| Provider and role | Data and purpose | Location and duration |
|---|---|---|
| OpenAI OpCo, LLC — ChatGPT Sites host; Cloudflare, Ltd. is an infrastructure subprocessor. Sites DPA | Hosted account, mailbox, security and request data needed to run the site, Worker and database | United States and other infrastructure locations used by the providers. Sites does not currently offer the operator a data-residency choice. Processed for the hosting term and the providers’ deletion obligations. |
| Google LLC — connected Gmail provider. Google privacy policy | Gmail address, OAuth authorization, mailbox data requested through the Gmail API, and messages/attachments the user asks Gmail to send | United States and other Google server locations; when the user connects or uses Gmail features; retained by Google under the Google account and its policy. |
| Daou Technology Inc. — DaouOffice business email provider. Daou Technology | Support email address and message contents | South Korea; when the user sends a support email and while the correspondence is retained as described above. |
Sharing and human access
We do not sell mailbox data or provide it to advertisers. Data is processed by the providers above only as needed to operate a feature the user requests, or when disclosure is required by law or necessary to address security abuse. People do not read mailbox content unless the user gives permission for a specific support case, access is required to address a security incident, or access is legally required.
Cookies and local storage
The service uses a necessary 30-day sign-in cookie, 10-minute legal-confirmation and OAuth-state cookies, and Cloudflare security cookies such as __cf_bm (normally 30 minutes after inactivity). Blocking necessary cookies prevents account connection. Private markers, aliases and unsent drafts use browser localStorage; blocking or clearing it removes their persistence. There are no advertising or analytics trackers in the application.
Deletion
Your choices and rights
Security
Business use and sensitive information
The beta is offered only to users aged 18 or older acting for an organization. The organization controls the lawfulness of mailbox content and instructs Ordinal Doctrine as described in the DPA. A mailbox may contain sensitive information about the user or other people; do not use the beta for regulated sensitive-data workflows unless Ordinal Doctrine agrees in writing after appropriate legal review.
Changes
We update this policy when the service's data handling changes. A material change will be announced on the site before it takes effect where required.