1. Who we are
DeclutrMail (“DeclutrMail”, “we”, “us”) is a Gmail cleanup service: it helps you decide, once per sender, what should happen to the email you no longer want — keep it, archive it, unsubscribe from it, deal with it later, or delete it. Reversible mail-moving actions have a defined undo window; a delivered unsubscribe request cannot be recalled.
For the purposes of the EU General Data Protection Regulation (GDPR), DeclutrMail is the data controller for the data described in this policy. For the purposes of India’s Digital Personal Data Protection Act, 2023 (DPDP Act), DeclutrMail is the Data Fiduciary. Contact details are in Section 12.
2. What we store — and what we never store
Our entire product is built around one boundary: Full bodies fetched: 0. We never fetch or store the full body of your messages. The published Gmail message-field disclosure is below; the operational records stored beyond message metadata are listed after it.
Message data we store:
- Gmail message and thread IDs
- Sender name and email address
- Subject
- Gmail Preview (the short snippet shown in your inbox list)
- Received date
- Gmail labels
- Read or unread state
- Whether a message was sent by you
- Recipient email addresses from To and Cc on mail you sent
- Unsubscribe links and whether one-click unsubscribe is supported
- Gmail message size estimate
We never fetch or store:
- Full message body
- HTML
- Attachments
- Inline images
- Raw MIME
- Headers other than From, Subject, To, Cc, and List-Unsubscribe fields
The “Gmail Preview” above is the short snippet Gmail itself computes and shows in your inbox list (roughly 160 characters). We receive it from Gmail’s API in metadata form — we never download or parse the full message body to produce it.
Beyond message metadata, we also store: your Google account email address and display name (from sign-in), your DeclutrMail preferences and per-sender decisions, an activity log of the actions DeclutrMail performed on your behalf, and billing records (handled by our payment providers — see Section 8; we never see or store full card numbers).
3. How we access your Gmail
DeclutrMail connects to your Gmail account through Google’s official API, using OAuth consent you grant explicitly. We request the gmail.modify scope — a restricted scope — because the product’s job is to act on your mail at your instruction: archive, label, delete, and unsubscribe.
- Message data is fetched in metadata format only: sender, subject, Gmail’s snippet, dates, labels, and read/unread state. We do not request message bodies or attachments from the API.
- Manual sender cleanup in Triage and Senders shows a current-scope preview before mail moves. Manual Archive, Later, and Delete can be reversed from Activity for your plan’s undo window. Delete also has Gmail Trash recovery, normally for up to 30 days; emptying Trash can end that separate fallback sooner. A delivered unsubscribe request cannot be recalled. Observe-mode Autopilot approvals show the sender scope; enabled Pro rules apply future matches without a new per-message approval.
- OAuth tokens are encrypted at rest and are never included in data exports or sent to your browser.
- Apps using restricted Gmail scopes are subject to Google’s independent CASA (Cloud Application Security Assessment) process. DeclutrMail’s current Tier 2 assessment cycle is in progress; current evidence will be published after it is issued.
You can revoke DeclutrMail’s access at any time from DeclutrMail’s settings or directly from your Google account permissions page.
4. Google API Services — Limited Use disclosure
DeclutrMail’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:
- We only use Gmail data to provide and improve the user-facing features of DeclutrMail that you can see in the product.
- We do not sell Gmail data, and we do not use it for advertising of any kind.
- We do not transfer Gmail data to third parties except the subprocessors needed to run the service (Section 8), as required by law, or as part of a merger or acquisition with notice to you.
- Humans at DeclutrMail do not read your Gmail data, except with your explicit permission (for example, a support request you initiate), where required for security or abuse investigation, or where required by law.
- We do not use Gmail data to train generalized artificial-intelligence or machine-learning models.
5. How we use your data
We use the data described above to:
- Show you a per-sender view of your inbox and recommend cleanup decisions — driven by volume, your engagement, and rules you set. DeclutrMail does not use machine learning to predict email categories. Deterministic product rules can automatically protect a sender when strong engagement signals, such as your reply history, cross the documented threshold; you can review and change that protection. Mail-changing automation follows rules you explicitly enabled.
- Execute the actions you approve (archive, unsubscribe, delete, label) on your Gmail.
- Keep an activity log so mail-moving actions are auditable and reversible during their undo window, and unsubscribe outcomes remain visible even though the request is one-way.
- Operate your subscription and billing.
- Send you transactional email about your account (sync status, receipts, security notices). Product-update email is optional and opt-out.
- Monitor errors and service health, and — with your consent — understand which features matter.
7. Data retention and deletion
You can leave cleanly through three self-serve controls in Settings:
- Disconnect an inbox — revokes our Google access and stops all syncing for that inbox. Your historical activity log is kept so you can reconnect later.
- Delete an inbox’s data — disconnects that inbox and permanently removes its indexed message data and derived product data. Gmail itself is unchanged; narrowly scoped pseudonymous security and deletion evidence remains under its stated retention policy.
- Delete your DeclutrMail account — removes all inboxes, all activity, all preferences, and your account itself. Deletion becomes permanent after the scheduled grace/undo window, or immediately when you explicitly waive those windows; there is no recovery after the purge runs.
Account deletion has a 7-day grace period during which you can change your mind. If you have recent actions still inside an undo window longer than 7 days (Pro’s 30-day undo), deletion is scheduled after the latest undo window expires — so “undo always works for its full window” stays true. If you want deletion sooner, you can explicitly waive the grace period and any remaining undo windows with a typed confirmation during the deletion flow — deletion then takes effect immediately. Once deletion is scheduled, syncing stops immediately.
From Settings → Privacy & Data, you can export mailbox email/status/connection metadata, sender records and standing policies, the message metadata index, and your decision/activity history as JSON. Dataset-specific CSVs are available for messages, senders, and decisions. The export does not include app preferences, billing records, message bodies, attachments, or OAuth tokens.
8. Subprocessors
We use a small set of infrastructure providers to run DeclutrMail. Each processes data only on our instructions:
| Provider | Purpose |
|---|---|
| Google Cloud | API and worker hosting; Gmail API access; push notifications |
| Supabase | Postgres database (the metadata listed in Section 2) |
| Vercel | Web application hosting |
| Upstash | Redis — job queues and rate limiting |
| Sentry | Error monitoring (no message content in events) |
| PostHog | Product analytics — only with your cookie consent; no Gmail message data |
| Anthropic | Recommendation explanations and Pro Brief narration — bounded metadata; Pro Brief can include subject and Gmail preview snippet; never a full message body |
| Resend | Transactional email delivery |
| Paddle | Merchant of record and payment processing (outside India) |
| Razorpay | Payment processing (India) |
Recommendation explanations can send Anthropic the sender identity and domain plus numerical engagement signals and the deterministic verdict; they do not send subject lines, Gmail preview snippets, or message bodies. Pro Brief can send sender identity, subject, and Gmail’s short preview snippet to Anthropic to generate its narrative. Full message bodies are never fetched or sent.
We will update this list before adding a new subprocessor that handles personal data.
9. Your rights (GDPR and DPDP)
If you are in the European Economic Area or the United Kingdom, you have the rights the GDPR gives you: access, rectification, erasure, restriction, portability, and objection. Most of these are self-serve in the product (export and deletion in Settings → Privacy & Data); for anything else, email us. You also have the right to lodge a complaint with your local supervisory authority.
If you are in India, the DPDP Act, 2023 applies: DeclutrMail is the Data Fiduciary, and processing is based on your explicit consent given when you connect your Gmail account, for the lawful purpose of providing the email cleanup service described here. As a Data Principal you have the right to access, correct, and erase your personal data, and the right to grievance redressal. You may withdraw consent at any time by disconnecting your inbox or deleting your account. In the event of a personal data breach affecting you, we will notify you and the Data Protection Board of India as the Act requires.
Grievance officer and privacy contact: privacy@declutrmail.com. We respond within 30 days.
10. Security
All data is encrypted in transit (TLS) and at rest. OAuth tokens are additionally envelope-encrypted with a managed key service. Access to production systems is limited and logged. Because we never store full message bodies or attachments, that content cannot leak from DeclutrMail. Subjects and Gmail Preview snippets can still contain sensitive information; we store those bounded fields as disclosed in Section 2 and protect them accordingly.
11. Changes to this policy
When we make a material change — a new data type, a new subprocessor, a change in how we access Gmail — we will update this page, change the date at the top, and notify you by email before the change takes effect. We will never silently expand what we store.
12. Contact
Privacy questions and data requests: privacy@declutrmail.com
General support: support@declutrmail.com