Privacy
Effective September 27, 2026
Who we are
MailGPT ("we") operates mailgpt.com, an AI email assistant that triages your inbox and delivers what matters to Telegram, Slack, WhatsApp, or the web app at my.mailgpt.com. Contact us at support@mailgpt.com or via the MailGPT bot on Telegram (@mailgptcombot).
What we access
- Google account, with your consent via Google OAuth: basic profile (
openid,email,profile), read-only Gmail access to classify your mail (gmail.readonly), sending only when you explicitly approve a reply (gmail.send), and your Google Calendar (calendar.events): we read your upcoming events to give you a heads-up the evening before and shortly before a meeting, to put today's schedule in your morning brief, and to check a time an email proposes against your calendar. We add an event only when you ask, and we answer an invitation or move an event you organize only when you approve it: your answer shows on the organizer's invitation, and a move notifies the event's guests. - Microsoft account, if you connect Outlook: basic profile (
User.Read), your mail (Mail.ReadWrite, because Microsoft prepares a reply as a draft before it is sent; we don't change or delete your existing mail), sending only when you explicitly approve a reply (Mail.Send), andoffline_accessso triage keeps working while you're away. We don't request access to your Outlook calendar. - App Store Connect, if you add an API key in Settings: the key is used only to check and release your app versions. We read your apps and their versions, and we release a version only when you ask.
- Messaging identities you connect: your Telegram chat, Slack workspace/user, or WhatsApp phone number — used only to deliver your assistant.
What we store
- Account records: your email address and connected channel IDs.
- Triage records: sender, subject, the decision (skip / notify / act), and a short AI-written summary.
- Assistant memory: facts, sender relationships (including how often and when you write to each person, counted from the To and Cc of your sent mail), events, and commitments extracted from your email to personalize triage for you.
- Contacts you ask the assistant about: a person's role and company, with the web page it came from.
- Things you ask the assistant to wait for: what to watch your mail for, what to do when it arrives, and which email completed it. Each is deleted 30 days after the assistant stops watching for it: when it is done or cancelled, or when its watch period ends (30 days, or up to 90 if you ask).
- OAuth tokens, encrypted at rest with AES-256-GCM.
- An App Store Connect API key, if you add one in Settings, encrypted at rest with AES-256-GCM. Disconnecting it in Settings deletes it.
- Your recent conversation with the assistant, including the alerts we send you: the last 20 messages per channel, deleted 7 days after your last activity on that channel.
- Error records: when something fails we log it, which can include your account ID or email address. They are kept for 30 days, then deleted.
- Calendar events are read when they are needed and kept for at most 15 minutes, so one check can serve several emails. We don't store them beyond that. While an invitation answer or a move waits for your approval, we keep only a reference to the event, not its details, for at most 30 days.
Full email bodies are never written to our database. While a message is being processed it waits in our processing queue — at most 4 days, if processing keeps failing — and is then discarded. Short snippets may be kept up to 30 days to learn from your explicit feedback, then expire automatically.
How AI processing works
Your email content, and the calendar events described above, are processed by OpenAI's models, reached through an AI router we operate, solely to classify, summarize, and extract what the assistant shows you, and to answer your questions. We handle it under the requirements of the service it comes from: for Gmail, the Google API Services User Data Policy, including the Limited Use requirements below; for Outlook, the Microsoft APIs Terms of Use. It is used only to operate the assistant for you: no advertising and no profiling for third parties.
What leaves our systems
- Email content and calendar events go to OpenAI through our AI router, as described above.
- When you ask who someone is, their name, company and email address are sent to OpenAI's web search, and the answer is saved with its source.
- Notifications and chat replies are delivered through the messaging platforms you connect (Telegram, Slack, WhatsApp) and are subject to those platforms' terms. WhatsApp messages travel through Meta's WhatsApp service, either through Meta's Business API or through a WhatsApp relay we host on Render.
- If you connect App Store Connect, we call Apple's App Store Connect API with your key, only to check and release your app versions; nothing from your email is sent to Apple. What Apple returns about your apps goes to OpenAI through our AI router when you ask the assistant about them.
- Sign-in links and service emails are sent through Resend.
- If you use package tracking or flight lookups, only the tracking or flight number is sent to 17TRACK or aviationstack — never email content.
- Hosting and storage run on Cloudflare (Workers, D1, KV, Queues).
- Our website, mailgpt.com, uses Google Analytics to count visits. It sets cookies in your browser and never receives your email.
Google API Services — Limited Use
MailGPT's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the user-facing features described here; it is not used for advertising and is not sold. People at MailGPT don't read your email unless you ask us to look at a specific message, it's needed to investigate a bug, abuse, or a security issue, or the law requires it.
Retention & deletion
We keep your data while your account is active. To delete it, open Settings at my.mailgpt.com and choose Delete account, confirming with your email address. That removes your account and everything we store about you, disconnects your mailboxes, and revokes our Google access. You can also email support@mailgpt.com and we'll do it for you. Copies in our database backups expire within 30 days. You can revoke our access at any time at myaccount.google.com/permissions, or for Outlook in your Microsoft account's app permissions.
Security
Encrypted tokens (AES-256-GCM), signature-verified webhooks on every inbound channel (Telegram, Slack, Meta, 17TRACK), TLS in transit, and least-scope OAuth. No system is perfectly secure, but silent failure modes are monitored daily.