Privacy Policy
Last updated: March 2026
1. What We Collect
- Account information — your email address and display name when you sign up.
- OAuth tokens — when you connect Gmail, we store encrypted access and refresh tokens to read your email on your behalf.
- Chat messages — the messages you send and the AI responses are stored so you can revisit conversations.
- Usage data — daily message counts for plan enforcement.
2. How We Use Your Data
- To provide the AI assistant service — reading your emails, summarizing them, and drafting replies.
- To enforce plan limits and billing.
- To improve the service and fix bugs.
3. Email Data Handling
We access your Gmail in read-only mode. We never send, delete, or modify your emails. Email content is processed in memory to generate AI responses and is never stored in our database. Only your chat messages (your questions and the AI's answers) are persisted.
4. Third-Party Services
- Supabase — authentication and database hosting.
- Anthropic — AI model provider (Claude). Your chat context is sent to Anthropic to generate responses.
- Stripe — payment processing. We do not store your card details.
- Google — Gmail API access via OAuth.
5. Data Security
OAuth tokens are encrypted at rest using AES-256-GCM. All communication is encrypted in transit via TLS. Database access is protected by row-level security policies.
6. Your Rights
- Disconnect your Gmail at any time from Settings.
- Delete your account and all associated data.
- Request a copy of your data by contacting us.
7. Contact
For privacy questions or data requests, email us at privacy@quinn.app.