MailSynth ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-driven email organization and daily-digest service (the "Service"). We believe in transparency regarding data practices and have designed this policy to clearly communicate how we protect your personal information.

1. Information We Collect

1.1 Account Information

When you sign up for MailSynth, we collect the following account information:

  • Google account email address

  • Your name (as provided by your Google account)

  • Your profile picture (as provided by your Google account)

  • OAuth 2.0 authentication tokens for Gmail API access

1.2 Email Data

To provide the Service, we access and process the following email data from your Gmail account:

  • Email metadata: sender, recipient(s), subject line, date and time sent, Gmail labels, thread information, and message flags

  • Email content: full message body text, used to generate AI summaries and categorizations

  • Email attachments: we do NOT access, download, or process any file attachments

Of the data above, we store only the following for each processed email: sender name and address, subject line, timestamp, the category and priority we assigned, the AI-generated summary, and the AI's confidence and reasoning for the classification. We do not store email message bodies. Message bodies are transmitted to our AI providers for processing (Section 3) and are not retained by MailSynth.

1.3 Usage Data

We automatically collect certain information about your interactions with the Service:

  • IP address

  • Browser type and version

  • Device type and operating system

  • Pages visited and features accessed

  • Time and date of access

  • Referring URLs and navigation paths

1.4 Information You Provide

The Service includes an AI assistant you can chat with to set up and manage your email organization. In connection with the assistant, we collect:

  • Messages you send to the assistant, which are processed by our AI Providers (Section 3) to generate responses; your conversation history is stored locally on your device, not on our servers

  • Preferences, notes, and instructions you provide (directly or through the assistant), such as how you want emails categorized and summarized — these are stored with your account

  • Feedback and support requests you choose to send us

1.5 Cookies and Similar Technologies

We use cookies and similar technologies for the following purposes:

  • Essential: session maintenance, user authentication, and remembering your preferences and settings

  • Analytics: Google Analytics, to understand usage patterns and improve the Service

  • Advertising measurement: pixels from Google Ads, Meta, and Reddit that let us measure whether our advertising leads to sign-ups (conversion tracking)

Advertising and analytics tools never receive your email content, summaries, or categorizations. See Section 5.4 for exactly what they do receive and how to opt out.

2. How We Use Your Information

2.1 Providing the Service

We use the information we collect to provide, maintain, and improve the MailSynth Service:

  • Reading and analyzing your emails to generate summaries and categorizations

  • Delivering daily email digests and organizational recommendations

  • Improving the Service's features and user experience through usage analytics — never through analysis of individual email content

  • Maintaining account credentials and access controls

2.2 Service Operations

We use your information for essential operational purposes:

  • User authentication and account management

  • Providing customer support and responding to inquiries

  • Sending service communications and important notices

  • Monitoring and analyzing Service performance and usage patterns

  • Processing subscription payments and managing billing

2.3 Advertising Measurement

We use limited event data (Section 5.4) to measure the effectiveness of our own advertising campaigns. We never use your email content, metadata, summaries, or categorizations for any advertising purpose.

2.4 Legal and Compliance

We may use your information when required by law or to protect the rights, property, and safety of MailSynth, our users, or the general public.

3. Artificial Intelligence and Data Processing

3.1 No AI Training

We want to be absolutely clear: we do NOT use any user data — including email content, email metadata, summaries, categorizations, or usage patterns — to train, fine-tune, improve, or develop any artificial intelligence or machine learning models, whether our own or those operated by third parties. Your data is never used to enhance or modify AI models.

3.2 AI Providers

MailSynth processes your emails — and the messages you send to our assistant (Section 1.4) — using AI models operated by third-party AI infrastructure providers ("AI Providers"), or using models that we host on our own infrastructure. Our AI Providers currently include Google (Gemini) and OpenAI.

Depending on your account's configuration, your emails are processed by one of our AI Providers. We may change or add AI Providers to improve quality and reliability, but only under the standards described in Section 3.3. When we run open-source or self-hosted models on our own cloud infrastructure, your data is not shared with any additional third party.

3.3 Standards Every AI Provider Must Meet

We only engage AI Providers whose terms with us guarantee all of the following:

  • Your data is NOT used to train, fine-tune, improve, or develop their AI models. This applies to all user data, including email content, metadata, summaries, categorizations, and any derived information.

  • Data is processed to generate real-time responses (such as email summaries and categorizations) and is not retained beyond a limited operational period (for example, up to thirty (30) days) used solely for abuse and security monitoring, after which it is deleted.

  • The provider is bound by a data processing agreement with confidentiality and security obligations, and appropriate international transfer safeguards where required (Section 8.2).

If we engage a new AI Provider to process email content, we will notify you by email or in-app notice before your data is processed by that provider.

3.4 No Data Sales or Commercial Distribution

We never sell, rent, lease, license, trade, or otherwise distribute user data to any third party for any commercial purpose whatsoever. This includes but is not limited to:

  • Data brokers or aggregators

  • Advertisers or marketing companies

  • Analytics firms

  • Artificial intelligence and machine learning training companies

  • Any other commercial entity for any commercial purpose

3.5 Data Processing Scope

When an email is processed through MailSynth:

  • The email content and metadata are securely transmitted to the AI Provider serving your account (or processed on our own infrastructure)

  • The model generates a summary and categorization, which are returned to MailSynth

  • The full email content is NOT retained by MailSynth, and is not retained by the AI Provider beyond the limited abuse-monitoring window described in Section 3.3

  • MailSynth retains the generated summary and categorization (not the full email content) as described in Section 7

4. How We Process Email Data

4.1 Real-Time Processing

Email processing occurs in real time or near-real time as new email arrives and when scheduled digest generation occurs. Full email content is processed at the moment of classification and is not stored by MailSynth.

4.2 Data Minimization

We follow the principle of data minimization: we retain only the data necessary to provide the Service. We store the per-email fields listed in Section 1.2 (sender, subject, timestamp, category, priority, summary, confidence, and reasoning) and never store full email content or attachments.

4.3 Summary Retention

Generated summaries and categorizations are retained for as long as your account is active. This is what lets the Service show your email history, build accurate digests, and keep your labels consistent over time. All summaries and categorizations are deleted when your account is deleted (Section 7.2).

5. Sharing Your Information

5.1 Service Providers

We share certain information with trusted service providers who assist us in operating the Service:

  • Google Cloud Platform — infrastructure, database, and computing services (all MailSynth data)

  • AI Providers (Section 3.2) — AI processing of email content

  • Twilio SendGrid — delivery of your digest emails and service notifications; digest emails contain email subjects and summaries, addressed only to you

  • Stripe — subscription billing; receives your name, email address, and payment details

We have Data Processing Agreements (DPAs) in place with all service providers that handle personal data. These agreements require that providers use data only to deliver the requested services and maintain strict confidentiality and security standards.

5.2 Legal Requirements

We may disclose your information when required by law, such as in response to a valid subpoena, court order, or other legal process. We will make reasonable efforts to notify you of such requests unless prohibited by law.

5.3 What We Never Do

To be absolutely clear, we never:

  • Sell your data

  • Rent, lease, or trade your data

  • Use your email content, metadata, summaries, or categorizations for advertising

  • Share your email content with third parties, except for the AI processing described in Section 3 and the delivery of your own digests described in Section 5.1

  • Allow humans to read your Gmail data — we do not store email bodies, and we never permit human access to your Gmail data except with your explicit consent, for security purposes, or as required by law

5.4 Advertising Measurement Partners

To measure whether our advertising works, we share limited event data with Google Ads, Meta, and Reddit when you take certain actions (such as signing up or starting a subscription). This data consists of: the event that occurred, a random event ID, the page URL, and — for matching purposes — a hashed (SHA-256) version of your email address, a hashed account identifier, your IP address, and browser information. It never includes email content, subjects, summaries, or categorizations.

This sharing may qualify as "sharing" for cross-context behavioral advertising under certain state privacy laws. You can opt out at any time as described in Section 8.

6. Data Security

We take data security seriously and implement multiple layers of security measures to protect your information:

  • TLS/SSL encryption for all data in transit

  • Encryption at rest (AES-256) provided by Google Cloud Platform infrastructure

  • OAuth 2.0 for secure authentication, using only the minimum Gmail scopes required, requested incrementally

  • Independent security assessment under Google's CASA (Cloud Application Security Assessment) framework, Tier 2

  • Strict access controls and role-based permissions

  • Google Cloud Platform enterprise-grade security infrastructure

While we implement strong security measures, no system is 100% secure. We encourage you to use strong, unique passwords and enable two-factor authentication on your Google account for additional protection.

7. Data Retention

7.1 Retention Periods

We retain your data according to the following schedule:

  • Account information: retained while your account is active

  • OAuth tokens: retained until revoked by you or your account is deleted

  • Email summaries and categorizations: retained while your account is active

  • Preferences, notes, and instructions you provide: retained while your account is active

  • Usage and operational logs: retained for up to ninety (90) days

  • Billing records: retained as required for tax and accounting purposes

7.2 Account Deletion

When you delete your account (or request deletion), we delete your personal data — including all stored email summaries, categorizations, and OAuth tokens — within thirty (30) days, except where we are legally required to retain it. You may also revoke MailSynth's access to your Gmail account at any time through your Google Account settings.

8. Your Rights and Choices

8.1 General Rights

Regardless of your location, you have the following rights with respect to your personal data:

  • Right to access: you may request a copy of the personal data we hold about you

  • Right to correction: you may request that we correct inaccurate or incomplete information

  • Right to deletion: you may request deletion of your personal data

  • Right to revoke access: you may revoke MailSynth's authorization to access your Gmail account at any time

  • Right to opt out of advertising measurement: you may opt out of the sharing described in Section 5.4 at any time by contacting us at support@mailsynth.com

8.2 European Economic Area (EEA) Residents

Legal Basis for Processing

Under the EU General Data Protection Regulation (GDPR), we process your personal data based on the following legal bases:

  • Contract Performance (Article 6(1)(b)): we process your email data and account information to perform our contract with you and provide the Service

  • Consent (Article 6(1)(a)): you provide explicit consent when you grant OAuth access to your Gmail account, and for non-essential cookies and advertising measurement

  • Legitimate Interest (Article 6(1)(f)): we process aggregated usage data, technical logs, and security information for service security, fraud prevention, and service improvement

Data Controller

MailSynth is the data controller with respect to your personal data. Our data protection contact information is provided in Section 13 of this Privacy Policy.

Sub-Processors

Sub-Processor

Purpose

Location

Safeguards

Google Cloud Platform

Infrastructure, database, computing

USA

SCCs, ISO 27001, SOC 2

AI Providers (Section 3.2)

AI email processing per Section 3.3

USA

SCCs, DPA, no-training terms

Twilio SendGrid

Digest and notification email delivery

USA

SCCs, SOC 2

Stripe

Payment processing

USA

SCCs, PCI DSS

We will provide notice as described in Section 3.3 before any new sub-processor processes your email content.

International Data Transfers

MailSynth transfers personal data of EEA residents to the United States to provide the Service. These transfers are implemented with appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission in our contracts with US-based sub-processors, and Transfer Impact Assessments for higher-risk processing activities.

Additional EEA Rights

In addition to the rights listed in Section 8.1, EEA residents have the following rights under the GDPR:

  • Right to data portability: you may request that we provide your personal data in a portable format

  • Right to restrict processing: you may request that we limit how we process your data

  • Right to object: you may object to our processing of your data for legitimate interest purposes

  • Right to withdraw consent: you may withdraw your consent at any time

  • Right to lodge a complaint: you have the right to lodge a complaint with your local Data Protection Authority

Breach Notification

In the event of a personal data breach affecting EEA residents, we commit to notifying the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, and notifying affected individuals without undue delay.

Data Protection Impact Assessment

We conduct Data Protection Impact Assessments (DPIAs) for processing activities involving special categories of personal data or presenting high risks to individuals' rights and freedoms, in accordance with GDPR Article 35.

8.3 United Kingdom Residents

Residents of the United Kingdom have similar rights to those of EEA residents under the UK GDPR (Data Protection Act 2018). All rights and safeguards described in Section 8.2 apply equally to UK residents. UK residents may lodge complaints with the UK Information Commissioner's Office (ICO).

8.4 California Residents (CCPA/CPRA)

California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know: you may request what personal information we collect and how it is used

  • Right to delete: you may request deletion of personal information we have collected

  • Right to correct: you may request that we correct inaccurate personal information

  • Right to opt out of sale or sharing: we do not sell your personal information. Our use of advertising measurement partners (Section 5.4) may constitute "sharing" under the CPRA; you may opt out as described in Section 8.1

  • Right to limit use: you may limit our use of sensitive personal information

8.5 Exercising Your Rights

To exercise any of your privacy rights, please contact us at:

Email: support@mailsynth.com

We will respond to your request within thirty (30) days of receipt. If we need additional information to verify your identity, we will request it promptly.

9. Google API Services Compliance

MailSynth uses Google API Services to access your Gmail data. Our use of information received from Gmail APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • We only request the minimum Gmail API scopes necessary to provide the Service

  • Gmail data is used only to provide and improve user-facing features of the Service

  • We do not use Gmail data for advertising purposes

  • We do not use Gmail data to train, develop, or improve generalized AI or machine learning models; Gmail content is transmitted to our AI providers (Section 3) solely to generate your summaries and categorizations, under terms that prohibit training

  • We do not transfer Gmail data to third parties except as necessary to provide user-facing features (Section 5.1), for security purposes, or as required by law

  • We do not permit humans to read your Gmail data except with your explicit consent, for security purposes, or as required by law

10. Third-Party Links

MailSynth may contain links to third-party websites and services that are not operated by us. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services before providing your information.

11. Children's Privacy

MailSynth is not intended for users under the age of 16. We do not knowingly collect or solicit personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will delete such information immediately. If you believe we have collected information from a child under 16, please contact us at support@mailsynth.com.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the effective date, and — for material changes to how we process your email data — by email. Your continued use of the Service following the posting of changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

MailSynth Support

Email: support@mailsynth.com

We are committed to addressing your privacy concerns and will respond to all inquiries within thirty (30) business days.