Legal

Privacy Policy

Last updated: July 29, 2026

Batmail is an email assistant that triages your inbox overnight: it reads incoming email, runs the rules you write, applies labels, and produces a morning roundup. To do that it needs access to your email, and this policy explains exactly what we collect, why, what we store, and how you get rid of it. It is written to be read, not skimmed.

What we collect

  • Your Google account basics. When you sign in with Google we receive your email address and name to create your account.
  • Gmail data for each connected mailbox. When you connect an inbox, you grant Batmail the Gmail gmail.readonly, gmail.modify, and gmail.send scopes. Read access lets Batmail triage incoming mail; modify lets it archive, star, and label per your rules; send is used only when a rule you wrote replies to or forwards an email.
  • What you configure. Your rules, labels, roundup guidelines, and settings.

How we use it

We use your data for one purpose: running Batmail for you. Concretely, that means checking each incoming email against your rules, applying labels with a written reason, assembling your morning roundup, and carrying out the actions your rules authorize. We do not use your data for anything else.

Google user data and Limited Use

Batmail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice: Gmail data is used only to provide the features described above, is never sold, is never used for advertising, and is never transferred to third parties except as needed to provide those features (see AI processing below), to comply with law, or as part of a merger or acquisition with notice to you.

AI processing

Batmail's triage engine is powered by Anthropic. Email content is sent to the Anthropic API to run your rules, apply labels, and generate roundups and rule-authorized replies. Your email content is not used to train AI models. Anthropic acts as a data processor for Batmail under its commercial API terms.

Service providers

Batmail runs on a small set of providers. Each receives only what it needs, and none of them receives the contents of your mailbox except Anthropic, as described above.

  • Vercel hosts the application. Neon hosts the database.
  • Anthropic processes email content to run your rules, labels and roundups.
  • Resend delivers your morning roundup email. It receives your email address and the roundup we send you.
  • Crisp powers the support chat widget. If you open a chat, it receives your name and email address so we know who we are talking to, along with whatever you choose to write to us. It never receives your mail.
  • Slack receives internal operational alerts: a new account, a mailbox connected or disconnected, an account deleted, and job success or failure counts. These carry account email addresses and totals only. No subject line, sender, or message content from your mailbox is ever sent to Slack.

What we store

  • Processed snapshots of triaged messages (sender, subject, a short excerpt, and the decision made) so your roundup and audit history work.
  • OAuth refresh tokens for each connected mailbox, encrypted at rest with AES-256-GCM.
  • Your rules, labels, guidelines, and generated roundups.

We do not store a full copy of your mailbox. Your mail stays in Gmail.

What we never do

  • We never sell your data, to anyone, in any form.
  • We show no ads and share nothing with advertisers.
  • Humans at Batmail do not read your email, except with your explicit permission during a support request you initiate.

Retention and deletion

Disconnect a mailbox and the token we hold for it is handed back to Google and deleted immediately; Batmail loses access from that moment. The message snapshots for that mailbox, and the activity and roundup entries built from them, are deleted with it. Delete your account and all of your data (snapshots, rules, labels, guidelines, and roundups) is removed from our systems. You can also revoke Batmail's access at any time from your Google account security settings.

Security

All data is encrypted in transit (TLS) and at rest. Refresh tokens carry an additional layer of AES-256-GCM application-level encryption. Access to production systems is limited to the people who operate the service and is logged. If a breach affects your data, we will notify you promptly and tell you plainly what happened.

Changes to this policy

If we change this policy in a way that matters, we will email account holders before the change takes effect and update the date at the top of this page.

Contact

Questions, concerns, or deletion requests: support@batmail.ai.