Email Assistant
Email Assistant

Privacy policy

Last updated: 5 September 2026

This policy describes how Email Assistant handles information when its operator connects their own Gmail or Google Workspace accounts. The application is for personal use and is not offered as a public email service.

Information accessed

With Google authorization, the assistant accesses the connected account’s email address, message and conversation identifiers, sender and recipient fields, subjects, timestamps, labels, and message body text. Sent messages are included to identify outstanding requests and commitments. The current version does not download or analyze attachments.

Read-only Gmail access allows retrieval across a mailbox, although processing is limited by the configured synchronization window and conversation limits. The default initial window is the previous 30 days.

Purpose of use

Email information is used to assess importance and urgency, summarize conversations, identify outstanding replies or actions, prepare digests, and send reminders requested by the operator. The assistant does not send email or change messages in Gmail.

The operator does not sell Google user data, use it for advertising, or use it to train general-purpose AI models. Email Assistant’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

AI processing and service providers

Selected conversation text, account context, and the operator’s preferences are transmitted over HTTPS to OpenRouter, which routes requests to the configured model provider. Requests require structured-output support and use OpenRouter’s provider-routing setting that denies provider data collection. This setting is not a blanket statement that every service retains no metadata or operational records.

Telegram receives the summaries, sender and account information, suggested actions, deadlines, and original Gmail links included in alerts and digests. These are sent to the operator’s configured private chat. The application runs on a Hetzner server controlled by the operator.

OpenRouter, the selected model provider, Telegram, Google, and Hetzner also process information under their own applicable terms and privacy policies. The operator should review their account settings and provider policies.

Storage and protection

Google refresh tokens, generated summaries, and queued notification contents are encrypted within the application’s private database. Some operational metadata, including account addresses, conversation identifiers, priorities, and timestamps, is stored without application-level field encryption. Encryption keys and service credentials are kept in restricted server files.

Full message bodies are processed in memory and are not intentionally saved in the application database. This does not describe the retention practices of Google, OpenRouter, model providers, or Telegram. Routine application logs are designed to omit email bodies, tokens, and passwords.

Retention, disconnection, and deletion

Saved connections, summaries, follow-up states, and delivery records remain until the operator removes them. The current version does not automatically delete them after a fixed retention period.

The operator can revoke access through Google Account connections. Revocation prevents future authorized retrieval but does not automatically erase information already stored by the assistant or messages already delivered to Telegram. To delete that information, the operator must remove the relevant local and server records, Telegram messages, and any backup copies they maintain.

This public website

These information pages do not use analytics, advertising, tracking cookies, or forms. Standard connection information, such as IP addresses, may be processed by hosting and network infrastructure to deliver and protect the site. Mailboxes and application credentials are not served by this website.

Contact and changes

For questions or deletion requests, contact the application operator using the user-support email displayed on the Google consent screen. Material changes to data handling will be reflected in this policy before the changed handling is enabled.