Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains how anymail ("anymail", "we", "us") handles personal data when you use the anymail service at anymail.watch and app.anymail.watch (the "Service").
1. Who is responsible for your data
The data controller is Creathink One Sp. z o.o., registered in Poland, KRS
0000909721, NIP 5242921982, REGON 389408538, registered office at
Odkryta 11C/12, 03-140 Warsaw, Poland.
For any privacy question or to exercise your rights, contact us at [privacy@anymail.watch].
2. What anymail does
anymail connects to your Gmail or Outlook mailbox to help you manage it. It reads your incoming mail, sorts it into categories, applies labels, flags senders you may want to unsubscribe from, and can prepare draft replies in your own writing style. anymail never sends email on your behalf. Drafts are saved into your mailbox as native drafts for you to review and send yourself.
3. What data we collect and store
Account and profile. When you connect a mailbox we store your email address, display name, avatar URL, any additional addresses you own, and a short summary of your writing style that anymail learns from your sent mail. If you subscribe, we store your Stripe customer and subscription identifiers and your plan status.
Access credentials. We store the OAuth tokens that let anymail access your mailbox. These tokens are encrypted at rest with AES-256-GCM. We never see or store your mailbox password.
Email content. To provide the Service we store, for messages we process: sender name and address, recipient addresses, subject, a snippet, the first part of the plain-text body, and the category anymail assigned. To match your writing voice we also store subjects and bodies of a sample of your own sent messages. We store your corrections to categories and the senders you choose to unsubscribe from or keep.
Configuration. Labels, rules, category preferences and profile settings you create, which may include sender addresses or domains you match on.
Usage and diagnostics. Basic product analytics (see the Cookie Policy). We do not use advertising trackers.
4. How we use your data and our legal bases (GDPR / RODO)
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Provide the core mailbox features (sort, label, unsubscribe, draft) | Email content, account, tokens | Performance of a contract (Art. 6(1)(b)) |
| Learn your writing style for drafts | Your sent messages | Performance of a contract (Art. 6(1)(b)) |
| Billing and subscription | Account, Stripe IDs | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, diagnostics | Usage data | Legitimate interest (Art. 6(1)(f)) |
| Optional analytics | Usage data | Consent (Art. 6(1)(a)) where required |
We do not sell your personal data. We do not use your email content for advertising. We do not use your Google or Microsoft user data to train generalized AI or machine learning models.
5. Google API Services Limited Use disclosure
anymail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data (your Gmail messages, labels and profile) to provide and improve the user-facing features of anymail that you can see and use.
- We do not transfer Google user data to third parties except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with your notice and consent.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read your Gmail data unless: we have your explicit consent for specific messages, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data is aggregated and anonymized and used for internal operations.
6. Sub-processors and international transfers
We share data with the following providers strictly to run the Service:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Google (Gmail API) | Mailbox access | OAuth-scoped mailbox data | Global |
| Microsoft (Graph API) | Outlook mailbox access | OAuth-scoped mailbox data | Global |
| Anthropic (Claude) | Categorize mail and generate drafts | Sender, subject, snippet, and message body excerpts | United States |
| Stripe | Payments and subscriptions | Email, billing identifiers (card data goes directly to Stripe, never our servers) | EU / US |
| Microsoft (Clarity) | Product analytics on public pages only | Usage events (never loaded on pages showing email content) | United States |
| Hosting provider (Creathink VPS) | Run the app and database | All stored data | European Union |
Anthropic does not use data submitted through its API to train its models. We do not send your email content to any other model provider. Analytics (Microsoft Clarity) is loaded only on public marketing and sign-in pages and never on the pages that display your email, so email content is not captured by session analytics.
Where a provider is outside the European Economic Area, transfers rely on an adequacy decision or the provider's Standard Contractual Clauses.
Note: the Creathink VPS is hosted by Hetzner in Nuremberg, Germany (EU). If you later enable an OpenAI-compatible LLM endpoint (opt-in, off by default), add it here with its region and confirm it has a no-training data-processing agreement.
7. Data retention
We keep your email content and configuration only while your mailbox is connected. When you disconnect a mailbox or delete your account, we revoke our access at your provider and permanently delete your stored email content and configuration immediately. Billing records are kept only as long as required by tax law. You can disconnect a mailbox at any time from Settings.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing. You can exercise most of these directly in the app (view your data, correct categories, disconnect and delete). To make a formal request contact [privacy@anymail.watch]. You may also lodge a complaint with the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.
9. Revoking access
You can revoke anymail's access to your Google account at any time at myaccount.google.com/permissions, and to your Microsoft account at account.microsoft.com. Disconnecting the mailbox inside anymail also revokes our access at Google automatically and deletes your stored data.
10. Security
We use encryption for access tokens, encryption in transit (TLS), and access controls. No method of storage or transmission is perfectly secure, but we work to protect your data and to limit what we store to what the features need.
11. Children
anymail is not directed to children under 16 and we do not knowingly collect their data.
12. Changes
We may update this policy. We will post the new version here and update the date above. Material changes will be notified in the app.
This document is a draft prepared to support Google OAuth verification. It is not legal advice. Have it reviewed by a lawyer before publishing, especially the controller identity, international-transfer mechanism, and retention section.