Your email, handled carefully
Email is the most sensitive data most people own. This page explains exactly what MailRadar reads, what it stores, and what it will never do.
What we access
We request the narrowest Gmail scopes that make the product work:
gmail.readonlyRead your threads so we can work out who is waiting on whom.
gmail.composeCreate drafts and send the replies you explicitly press send on.
userinfo.email / profileIdentify which mailbox is connected.
We deliberately do not request gmail.modify or full-mail access. That means MailRadar is technically incapable of deleting, archiving or relabelling your mail, not merely unwilling. “Clean my inbox” hides threads inside MailRadar only.
What we analyse
- Message text, sender, recipients and timestamps, to detect requests, promises and deadlines.
- Thread structure, who wrote last, and how long it has been quiet.
- Your sent mail, to learn your writing style, so drafts sound like you.
Most analysis runs on our own servers with no external calls. A thread is only sent to an AI provider when the local engine cannot settle an ambiguous case, and never when its content is unchanged since the last analysis.
What we never do
How it is stored
- OAuth tokens are encrypted at rest with AES-256-GCM. They are never logged and never sent to the browser.
- Message bodies are stored as plain text so analysis can run incrementally, never as raw HTML, and never with tracking pixels.
- Product analytics live in a separate table that contains no message content: an event records that an analysis happened, its cost, and nothing else.
- Sessions are a signed, httpOnly cookie holding only your user id.
Leaving
Settings has two buttons. Disconnect removes the mailbox link and deletes the cached copy of your mail. Delete everything erases your account, threads, analyses, tasks and writing profile.
Both take effect immediately. There is no soft delete and no retention window. You can also revoke access at any time from your Google account security settings, independently of us.
Sub-processors
When an AI provider is configured, thread excerpts may be sent to it to improve a summary. Providers are used under agreements that prohibit training on the data. If no provider is configured, no email content leaves the server at all. Payments are processed by Stripe, which never receives email content, and we never see card details.
Questions about any of this are welcome. If something on this page ever stops being true, the page changes first.