Privacy
Privacy Policy
Last updated: 29 July 2026. MailOdi is built around sensitive inbox data, so privacy, limited access, and user control are core product rules.
Information we collect
When you sign in, MailOdi stores basic account information such as name, email address, Clerk user ID, plan, usage limits, and product preferences. When you connect Gmail, MailOdi may store your connected Gmail address, encrypted OAuth tokens, token metadata, message IDs, thread IDs, sender details, subjects, snippets, timestamps, labels needed for analysis, priority scores, sender trust signals, commitment signals, feedback, MailOdi-local Viewed, Reviewed, or Resolved state, and reply draft metadata needed to operate the service.
How we use Gmail data
MailOdi uses Gmail data only to provide user-facing email assistant features: listing and reading recent messages, ranking important messages, identifying urgent or risky emails, detecting commitments and deadlines, finding follow-ups, checking sender risk, preparing summaries, creating editable reply drafts, refreshing your priority inbox, sending email when you explicitly request it, and showing account usage. MailOdi does not sell Gmail data, does not use Gmail data for advertising, and does not use Gmail data to determine credit-worthiness or eligibility for financial products.
Google API Services User Data Policy
MailOdi's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only for the MailOdi features visible to you in the product and is not transferred except as needed to provide, secure, maintain, or comply with the service.
Gmail permissions
During beta, MailOdi may request Gmail read permission (`gmail.readonly`) to synchronize and analyze messages and Gmail send permission (`gmail.send`) to deliver email through your connected Gmail account. The send permission does not allow MailOdi to delete, archive, label, or otherwise modify your Gmail mailbox.
Sending email
When you send an email through MailOdi, MailOdi processes the recipient, Cc and Bcc addresses, subject, message body, and any selected attachments and transmits them to Gmail for delivery. Sending occurs only after you press Send or otherwise give an explicit send instruction. MailOdi does not currently send email autonomously. AI-generated and suggested drafts remain editable, and you should review the recipients, content, and attachments before sending. Selected attachment content is transmitted to Gmail for that send; MailOdi does not currently claim to permanently store locally selected compose attachments.
Human access limits
MailOdi does not use staff or contractors to routinely read Gmail content. Human access to user data is limited to cases where you ask for support, where access is needed to investigate abuse or security issues, where required by law, or where data has been aggregated or de-identified for service operations.
Analytics and monitoring
MailOdi uses privacy-conscious product analytics and error monitoring to understand page usage, failures, and system health. Gmail subjects, snippets, bodies, OAuth tokens, and reply drafts are not intentionally sent to analytics tools. Error monitoring is configured to help diagnose application failures without using Gmail content as product analytics data.
Storage and security
MailOdi stores app data in Neon Postgres and hosts the application on Vercel. Authentication is handled by Clerk. OAuth access and refresh tokens needed to use the connected Gmail account are encrypted using server-side secrets. Access to production systems and secrets should remain limited to authorized operators. No internet service can be guaranteed perfectly secure, but MailOdi aims to minimize stored data, minimize permissions, and protect sensitive tokens and inbox-derived data.
AI processing
MailOdi currently uses deterministic rules for its free beta intelligence. Future paid AI features may process message snippets and related metadata with AI providers to produce rankings, warnings, summaries, commitments, notifications, and drafts. If AI provider processing is introduced, MailOdi will keep it limited to user-facing product features and will update this policy as needed before broader production use.
MailOdi and Gmail message state
Viewed, Reviewed, and Resolved are MailOdi application states used to organize your MailOdi workspace. They may be separate from Gmail's native read or unread state and do not necessarily alter the message in your Gmail mailbox.
Retention and deletion
MailOdi keeps Gmail-derived records only as long as needed to provide the product, debug service reliability, comply with law, or honor your account controls. You can disconnect Gmail from MailOdi, export MailOdi-held data, use the available deletion control, or request deletion of MailOdi account data. Deletion is subject to the service's current implementation and any limited retention required for security, legal, or operational reasons. Instructions are available on the Data Deletion page.
Your choices
You can stop Gmail access by disconnecting MailOdi in your Google Account permissions or from MailOdi settings. You can export MailOdi-held data, delete MailOdi-held data from settings, or request account data deletion by contacting support at support@mailodi.com.