Privacy policy
v1.0.2
August 4, 2026
MailSynth ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-driven email organization and daily-digest service (the "Service"). We believe in transparency regarding data practices and have designed this policy to clearly communicate how we protect your personal information.
1. Information We Collect
1.1 Account Information
When you sign up for MailSynth, we collect the following account information:
Google account email address
Your name (as provided by your Google account)
Your profile picture (as provided by your Google account)
OAuth 2.0 authentication tokens for Gmail API access
1.2 Email Data
To provide the Service, we access and process the following email data from your Gmail account:
Email metadata: sender, recipient(s), subject line, date and time sent, Gmail labels, thread information, and message flags
Email content: full message body text, used to generate AI summaries and categorizations
Email attachments: we do NOT access, download, or process any file attachments
Of the data above, we store only the following for each processed email: sender name and address, subject line, timestamp, the category and priority we assigned, the AI-generated summary, and the AI's confidence and reasoning for the classification. We do not store email message bodies. Message bodies are transmitted to our AI providers for processing (Section 3) and are not retained by MailSynth.
1.3 Usage Data
We automatically collect certain information about your interactions with the Service:
IP address
Browser type and version
Device type and operating system
Pages visited and features accessed
Time and date of access
Referring URLs and navigation paths
1.4 Information You Provide
The Service includes an AI assistant you can chat with to set up and manage your email organization. In connection with the assistant, we collect:
Messages you send to the assistant, which are processed by our AI Providers (Section 3) to generate responses; your conversation history is stored locally on your device, not on our servers
Preferences, notes, and instructions you provide (directly or through the assistant), such as how you want emails categorized and summarized — these are stored with your account
Feedback and support requests you choose to send us
1.5 Cookies and Similar Technologies
We use cookies and similar technologies for the following purposes:
Essential: session maintenance, user authentication, and remembering your preferences and settings
Analytics: Google Analytics, to understand usage patterns and improve the Service
Advertising measurement: pixels from Google Ads, Meta, and Reddit that let us measure whether our advertising leads to sign-ups (conversion tracking)
Advertising and analytics tools never receive your email content, summaries, or categorizations. See Section 5.4 for exactly what they do receive and how to opt out.
2. How We Use Your Information
2.1 Providing the Service
We use the information we collect to provide, maintain, and improve the MailSynth Service:
Reading and analyzing your emails to generate summaries and categorizations
Delivering daily email digests and organizational recommendations
Improving the Service's features and user experience through usage analytics — never through analysis of individual email content
Maintaining account credentials and access controls
2.2 Service Operations
We use your information for essential operational purposes:
User authentication and account management
Providing customer support and responding to inquiries
Sending service communications and important notices
Monitoring and analyzing Service performance and usage patterns
Processing subscription payments and managing billing
2.3 Advertising Measurement
We use limited event data (Section 5.4) to measure the effectiveness of our own advertising campaigns. We never use your email content, metadata, summaries, or categorizations for any advertising purpose.
2.4 Legal and Compliance
We may use your information when required by law or to protect the rights, property, and safety of MailSynth, our users, or the general public.
3. Artificial Intelligence and Data Processing
3.1 No AI Training
We want to be absolutely clear: we do NOT use any user data — including email content, email metadata, summaries, categorizations, or usage patterns — to train, fine-tune, improve, or develop any artificial intelligence or machine learning models, whether our own or those operated by third parties. Your data is never used to enhance or modify AI models.
3.2 AI Providers
MailSynth processes your emails — and the messages you send to our assistant (Section 1.4) — using AI models operated by third-party AI infrastructure providers ("AI Providers"), or using models that we host on our own infrastructure. Our AI Providers currently include Google (Gemini) and OpenAI.
Depending on your account's configuration, your emails are processed by one of our AI Providers. We may change or add AI Providers to improve quality and reliability, but only under the standards described in Section 3.3. When we run open-source or self-hosted models on our own cloud infrastructure, your data is not shared with any additional third party.
3.3 Standards Every AI Provider Must Meet
We only engage AI Providers whose terms with us guarantee all of the following:
Your data is NOT used to train, fine-tune, improve, or develop their AI models. This applies to all user data, including email content, metadata, summaries, categorizations, and any derived information.
Data is processed to generate real-time responses (such as email summaries and categorizations) and is not retained beyond a limited operational period (for example, up to thirty (30) days) used solely for abuse and security monitoring, after which it is deleted.
The provider is bound by a data processing agreement with confidentiality and security obligations, and appropriate international transfer safeguards where required (Section 8.2).
If we engage a new AI Provider to process email content, we will notify you by email or in-app notice before your data is processed by that provider.
3.4 No Data Sales or Commercial Distribution
We never sell, rent, lease, license, trade, or otherwise distribute user data to any third party for any commercial purpose whatsoever. This includes but is not limited to:
Data brokers or aggregators
Advertisers or marketing companies
Analytics firms
Artificial intelligence and machine learning training companies
Any other commercial entity for any commercial purpose
3.5 Data Processing Scope
When an email is processed through MailSynth:
The email content and metadata are securely transmitted to the AI Provider serving your account (or processed on our own infrastructure)
The model generates a summary and categorization, which are returned to MailSynth
The full email content is NOT retained by MailSynth, and is not retained by the AI Provider beyond the limited abuse-monitoring window described in Section 3.3
MailSynth retains the generated summary and categorization (not the full email content) as described in Section 7
4. How We Process Email Data
4.1 Real-Time Processing
Email processing occurs in real time or near-real time as new email arrives and when scheduled digest generation occurs. Full email content is processed at the moment of classification and is not stored by MailSynth.
4.2 Data Minimization
We follow the principle of data minimization: we retain only the data necessary to provide the Service. We store the per-email fields listed in Section 1.2 (sender, subject, timestamp, category, priority, summary, confidence, and reasoning) and never store full email content or attachments.
4.3 Summary Retention
Generated summaries and categorizations are retained for as long as your account is active. This is what lets the Service show your email history, build accurate digests, and keep your labels consistent over time. All summaries and categorizations are deleted when your account is deleted (Section 7.2).
5. Sharing Your Information
5.1 Service Providers
We share certain information with trusted service providers who assist us in operating the Service:
Google Cloud Platform — infrastructure, database, and computing services (all MailSynth data)
AI Providers (Section 3.2) — AI processing of email content
Twilio SendGrid — delivery of your digest emails and service notifications; digest emails contain email subjects and summaries, addressed only to you
Stripe — subscription billing; receives your name, email address, and payment details
We have Data Processing Agreements (DPAs) in place with all service providers that handle personal data. These agreements require that providers use data only to deliver the requested services and maintain strict confidentiality and security standards.
5.2 Legal Requirements
We may disclose your information when required by law, such as in response to a valid subpoena, court order, or other legal process. We will make reasonable efforts to notify you of such requests unless prohibited by law.
5.3 What We Never Do
To be absolutely clear, we never:
Sell your data
Rent, lease, or trade your data
Use your email content, metadata, summaries, or categorizations for advertising
Share your email content with third parties, except for the AI processing described in Section 3 and the delivery of your own digests described in Section 5.1
Allow humans to read your Gmail data — we do not store email bodies, and we never permit human access to your Gmail data except with your explicit consent, for security purposes, or as required by law
5.4 Advertising Measurement Partners
To measure whether our advertising works, we share limited event data with Google Ads, Meta, and Reddit when you take certain actions (such as signing up or starting a subscription). This data consists of: the event that occurred, a random event ID, the page URL, and — for matching purposes — a hashed (SHA-256) version of your email address, a hashed account identifier, your IP address, and browser information. It never includes email content, subjects, summaries, or categorizations.
This sharing may qualify as "sharing" for cross-context behavioral advertising under certain state privacy laws. You can opt out at any time as described in Section 8.
6. Data Security
We take data security seriously and implement multiple layers of security measures to protect your information:
TLS/SSL encryption for all data in transit
Encryption at rest (AES-256) provided by Google Cloud Platform infrastructure
OAuth 2.0 for secure authentication, using only the minimum Gmail scopes required, requested incrementally
Independent security assessment under Google's CASA (Cloud Application Security Assessment) framework, Tier 2
Strict access controls and role-based permissions
Google Cloud Platform enterprise-grade security infrastructure
While we implement strong security measures, no system is 100% secure. We encourage you to use strong, unique passwords and enable two-factor authentication on your Google account for additional protection.
7. Data Retention
7.1 Retention Periods
We retain your data according to the following schedule:
Account information: retained while your account is active
OAuth tokens: retained until revoked by you or your account is deleted
Email summaries and categorizations: retained while your account is active
Preferences, notes, and instructions you provide: retained while your account is active
Usage and operational logs: retained for up to ninety (90) days
Billing records: retained as required for tax and accounting purposes
7.2 Account Deletion
When you delete your account (or request deletion), we delete your personal data — including all stored email summaries, categorizations, and OAuth tokens — within thirty (30) days, except where we are legally required to retain it. You may also revoke MailSynth's access to your Gmail account at any time through your Google Account settings.
8. Your Rights and Choices
8.1 General Rights
Regardless of your location, you have the following rights with respect to your personal data:
Right to access: you may request a copy of the personal data we hold about you
Right to correction: you may request that we correct inaccurate or incomplete information
Right to deletion: you may request deletion of your personal data
Right to revoke access: you may revoke MailSynth's authorization to access your Gmail account at any time
Right to opt out of advertising measurement: you may opt out of the sharing described in Section 5.4 at any time by contacting us at support@mailsynth.com
8.2 European Economic Area (EEA) Residents
Legal Basis for Processing
Under the EU General Data Protection Regulation (GDPR), we process your personal data based on the following legal bases:
Contract Performance (Article 6(1)(b)): we process your email data and account information to perform our contract with you and provide the Service
Consent (Article 6(1)(a)): you provide explicit consent when you grant OAuth access to your Gmail account, and for non-essential cookies and advertising measurement
Legitimate Interest (Article 6(1)(f)): we process aggregated usage data, technical logs, and security information for service security, fraud prevention, and service improvement
Data Controller
MailSynth is the data controller with respect to your personal data. Our data protection contact information is provided in Section 13 of this Privacy Policy.
Sub-Processors
Sub-Processor | Purpose | Location | Safeguards |
Google Cloud Platform | Infrastructure, database, computing | USA | SCCs, ISO 27001, SOC 2 |
AI Providers (Section 3.2) | AI email processing per Section 3.3 | USA | SCCs, DPA, no-training terms |
Twilio SendGrid | Digest and notification email delivery | USA | SCCs, SOC 2 |
Stripe | Payment processing | USA | SCCs, PCI DSS |
We will provide notice as described in Section 3.3 before any new sub-processor processes your email content.
International Data Transfers
MailSynth transfers personal data of EEA residents to the United States to provide the Service. These transfers are implemented with appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission in our contracts with US-based sub-processors, and Transfer Impact Assessments for higher-risk processing activities.
Additional EEA Rights
In addition to the rights listed in Section 8.1, EEA residents have the following rights under the GDPR:
Right to data portability: you may request that we provide your personal data in a portable format
Right to restrict processing: you may request that we limit how we process your data
Right to object: you may object to our processing of your data for legitimate interest purposes
Right to withdraw consent: you may withdraw your consent at any time
Right to lodge a complaint: you have the right to lodge a complaint with your local Data Protection Authority
Breach Notification
In the event of a personal data breach affecting EEA residents, we commit to notifying the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, and notifying affected individuals without undue delay.
Data Protection Impact Assessment
We conduct Data Protection Impact Assessments (DPIAs) for processing activities involving special categories of personal data or presenting high risks to individuals' rights and freedoms, in accordance with GDPR Article 35.
8.3 United Kingdom Residents
Residents of the United Kingdom have similar rights to those of EEA residents under the UK GDPR (Data Protection Act 2018). All rights and safeguards described in Section 8.2 apply equally to UK residents. UK residents may lodge complaints with the UK Information Commissioner's Office (ICO).
8.4 California Residents (CCPA/CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to know: you may request what personal information we collect and how it is used
Right to delete: you may request deletion of personal information we have collected
Right to correct: you may request that we correct inaccurate personal information
Right to opt out of sale or sharing: we do not sell your personal information. Our use of advertising measurement partners (Section 5.4) may constitute "sharing" under the CPRA; you may opt out as described in Section 8.1
Right to limit use: you may limit our use of sensitive personal information
8.5 Exercising Your Rights
To exercise any of your privacy rights, please contact us at:
Email: support@mailsynth.com
We will respond to your request within thirty (30) days of receipt. If we need additional information to verify your identity, we will request it promptly.
9. Google API Services Compliance
MailSynth uses Google API Services to access your Gmail data. Our use of information received from Gmail APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:
We only request the minimum Gmail API scopes necessary to provide the Service
Gmail data is used only to provide and improve user-facing features of the Service
We do not use Gmail data for advertising purposes
We do not use Gmail data to train, develop, or improve generalized AI or machine learning models; Gmail content is transmitted to our AI providers (Section 3) solely to generate your summaries and categorizations, under terms that prohibit training
We do not transfer Gmail data to third parties except as necessary to provide user-facing features (Section 5.1), for security purposes, or as required by law
We do not permit humans to read your Gmail data except with your explicit consent, for security purposes, or as required by law
10. Third-Party Links
MailSynth may contain links to third-party websites and services that are not operated by us. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services before providing your information.
11. Children's Privacy
MailSynth is not intended for users under the age of 16. We do not knowingly collect or solicit personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will delete such information immediately. If you believe we have collected information from a child under 16, please contact us at support@mailsynth.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the effective date, and — for material changes to how we process your email data — by email. Your continued use of the Service following the posting of changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
MailSynth Support
Email: support@mailsynth.com
We are committed to addressing your privacy concerns and will respond to all inquiries within thirty (30) business days.

