Privacy & Google user data

Mailbrief Privacy Policy

Effective date
28 August 2026
Operator
KharMail
Privacy & deletion contact
togarabeska@gmail.com

1. Scope and service status

This policy explains how the private, non-commercial Mailbrief service handles Google user data obtained with a user's permission and related service data. Mailbrief is currently in setup and is available only to accounts approved in advance. There is no public sign-up.

2. Data Mailbrief accesses

For mailbox access, Mailbrief requests only the Gmail OAuth scopehttps://www.googleapis.com/auth/gmail.readonly. That scope technically permits viewing Gmail messages and settings. Mailbrief uses it only to read and synchronize messages for the features described here.

Data processed can include message and thread identifiers, labels, sender and recipients, subject, dates, headers, MIME structure, message body text, and attachment name, MIME type, and size. Mailbrief does not call the separate attachment API and does not decode, analyze, store, or transfer attachment content. If a provider includes attachment bytes in raw MIME, they pass transiently through memory and are discarded.

When configured by the user, Mailbrief also reads one Yandex Mail mailbox over read-only IMAP. Google identity used to enter the protected dashboard is checked against a private allowlist. Opaque aliases and HMAC identifiers are used instead of mailbox addresses in indexes and metrics.

Mailbrief does not send, modify, or delete Gmail or Yandex messages, drafts, labels, folders, or mailbox settings.

3. Purposes

Mailbox data is used only to provide these user-facing functions:

  • incremental synchronization of approved mailboxes;
  • importance, urgency, category, action, and deadline classification;
  • structured results in the protected dashboard;
  • a cleaned, bounded live view of one selected message after an explicit request;
  • deeper analysis only after an explicit user action; and
  • a strongly redacted Telegram digest, when notifications are enabled.

Content-free technical identifiers, counters, and events are also used to protect access, prevent duplicate processing, recover from failures, and enforce the application's AI spending cap.

4. Local processing and attachments

Mailbrief first parses and sanitizes messages locally, removes quoted history and signatures, redacts common personal data, applies rules, and checks a keyed cache. It never opens links, remote images, or tracking pixels and never executes email HTML, CSS, JavaScript, or forms.

Original MIME and cleaned text are processed in memory rather than kept as a mailbox archive. A cleaned, potentially truncated view of one message can be fetched live for the current protected session and is not cached.

5. Storage and retention

  • Unimportant structured results: normally 7 days.
  • Important, needs-review, or pending-AI results and related encrypted continuation data: 90 days in the current configuration.
  • Encrypted validated AI checkpoints: 39–90 days; the production default is 39 days. During unresolved recovery, only expiry may be extended while ciphertext remains unchanged.
  • Workflow/control records and runtime logs: 30 days. Logs exclude message bodies and AI prompts.
  • Encrypted Telegram outbox records and delivery markers: up to 120 days.
  • OAuth, Yandex, OpenAI, Telegram, and allowlist credentials: while the integration remains active, until revocation, rotation, or deletion.

Firestore TTL deletion is asynchronous. Point-in-time recovery can keep previous database versions for up to 7 days. Limited provider-managed recovery copies may remain until the applicable recovery window expires.

6. Service providers and transfers

Google Cloud

Google Cloud hosts Mailbrief, minimized results, secrets, and logs. Sensitive result fields are envelope-encrypted using AES-256-GCM and Cloud KMS. Core runtime resources and user-managed secret replicas are located in europe-west1.

OpenAI API

Only when local processing cannot produce the requested result, Mailbrief can send OpenAI a bounded, redacted message fragment and locally processed metadata such as sender, subject, recipients, date, labels, and technical classification signals. It does not send attachments, a mailbox archive, or mailbox credentials. Requests usestore=false. Provider-side handling follows the OpenAI API data controls applicable to the operator's account.

Telegram Bot API

If notifications are enabled, Telegram receives a short redacted digest for one configured chat. It can include category, urgency, action and deadline indicators, and a general redacted summary, but not full message text or attachment content. After delivery, Telegram may retain the message under the chat's settings and Telegram's rules until the user deletes it.

OpenAI and Telegram are outside the Google Cloud trust boundary and may process the minimum data sent to them in other jurisdictions under their applicable terms.

7. Google Limited Use

Mailbrief's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and the Google Workspace API User Data and Developer Policy.

Mailbrief does not sell Google user data; transfer it to advertising platforms, data brokers, or information resellers; use it for advertising, retargeting, credit scoring, or lending; or use it to create, train, or improve a general-purpose AI/ML model. AI use is limited to a visible classification or analysis feature for the specific user.

There is no routine human review of mailbox content. Human access to specific Google user data is limited to documented explicit user consent, security or incident investigation, or compliance with law. This Limited Use statement is the operator's commitment, not a claim of Google certification or endorsement.

8. Security

The dashboard is protected by Google Cloud IAP and a separate account allowlist. OAuth tokens are stored in Secret Manager. Service identities and encryption keys are separated by least-privilege function. Mailbrief accepts only strictly validated structured AI output, disables AI tools, and does not render original email HTML. Data is transmitted over secure protocols. No system can guarantee absolute security.

9. Revocation, deletion, and contact

A user can revoke Mailbrief's Google access at any time in Google Account connections. This stops future Gmail API access but does not by itself immediately delete already-created minimized results.

To request deletion or ask a privacy question, email togarabeska@gmail.com. The operator will verify and process the request subject to asynchronous TTL deletion, limited recovery windows, and security, accounting, or legal records that must be retained. Revoked data is not used for new user processing.

10. Public-site data and policy changes

This public information site has no advertising trackers, third-party analytics, external fonts, or public account registration. Essential infrastructure logs can process IP address, request time, path, user agent, and security signals for delivery and abuse prevention.

Before Google user data is used for a new or materially different purpose, this policy and in-product notice will be updated and fresh consent will be obtained when required. Contact: togarabeska@gmail.com.

Русская версия

Краткое изложение политики на русском языке

Mailbrief — частный некоммерческий сервис с доступом только для заранее разрешённых аккаунтов. Для почтового ящика Gmail он запрашивает только scope gmail.readonly и не отправляет, не изменяет и не удаляет письма или настройки. При настройке пользователем сервис также может читать один ящик Яндекс Почты по read-only IMAP.

Письма сначала очищаются и минимизируются локально. Сервис не открывает ссылки и tracking pixels, не исполняет HTML/JS и не анализирует вложения. Если байты вложения включены провайдером в исходный MIME, они проходят только транзитно через память и отбрасываются. Оригиналы остаются у почтового провайдера.

Только при необходимости OpenAI получает ограниченный отредактированный фрагмент и обработанные метаданные для видимой пользователю классификации или анализа. Telegram при включённых уведомлениях получает краткую сильно отредактированную сводку, но не полный текст и не содержимое вложений.

Неважные результаты обычно хранятся 7 дней; важные, needs-review и pending-AI — 90 дней; AI checkpoint — 39–90 дней; workflow и runtime logs — 30 дней; Telegram outbox — до 120 дней. Чувствительные поля шифруются, а OAuth tokens хранятся в Secret Manager.

Использование данных Google соответствует Google API Services User Data Policy, включая Limited Use. Данные не продаются, не используются для рекламы, кредитного скоринга или обучения AI-модели общего назначения. Отозвать доступ можно в настройках Google Account. Для вопросов и подтверждённых запросов на удаление: togarabeska@gmail.com.

Оператор: KharMail
Дата: 28 августа 2026 г.