Skip to content

Privacy, plainly

Your inbox stays yours.

YourSec needs access to be useful, but access is not ownership. This is the working agreement: what the product reads, what it keeps, who helps operate it, and what happens when you leave.

EffectiveWritten for peopleAbout 7 minutes

The short version

We read only to serve you

Mailbox metadata powers the brief. Message bodies are fetched only when a feature needs them; we do not keep a standalone body copy.

We store the working record

Account details, mailbox metadata, your instructions, and assistant-produced work are retained so the product can stay useful between visits.

Sensitive content gets another layer

OAuth tokens and sensitive assistant-produced content are encrypted at the application layer with keys protected by Google Cloud KMS.

No ads. No sale. No training.

We do not sell inbox data, use it for advertising, train a general AI model on it, or send email through your Gmail account.

01

Data we handle

Before Gmail is connected

The founding-pilot application collects your email address, the kind of work you do, a short description of your inbox challenge, and whether you are open to feedback conversations. We also keep application, approval, and invite-email timestamps. Applying does not connect to or read your Gmail account.

When you create an account

Google supplies the profile details used for your account, such as your email address, name, and profile image. We keep authentication state, your product settings, and encrypted OAuth tokens. Your Gmail password is never provided to YourSec.

While Gmail is connected

We store the mailbox information needed to organize your work: message and thread identifiers, sender and recipient addresses, sender name, subject, Gmail snippet, labels, timestamps, and read or starred state.

Full message bodies are fetched from Gmail on demand when a feature needs more context: to classify a message, follow a watch, determine whether something resolved, answer a Tell me instruction, prepare a summary, or draft a reply. We do not store a standalone copy of the full body with the message record. Selected context may be sent to the AI services described below and retained inside encrypted assistant work or a Tell me conversation.

We also keep what you deliberately create in the product, including watches, preferences, standing instructions, Tell me conversations, and draft guidance. Assistant-produced drafts, summaries, classifications, and activity records are kept when needed to provide and explain the service.

Operational data

We process session cookies, request and rate-limit identifiers, basic page-view analytics, and browser push-subscription details to secure, operate, and understand the service. Push messages contain only an encrypted “something changed” signal, never email text.

02

How we use it

Pilot-application information is used to review applications, choose a small cohort, send invitations, and arrange onboarding or feedback conversations you agreed to.

Gmail data is used only to provide user-facing YourSec features: organizing the brief, tracking the threads you ask us to watch, preparing work for your review, following bounded instructions you approve, and showing what happened afterward.

YourSec holds read access and bounded modify access to your mailbox (the gmail.readonly and gmail.modify scopes). Modify access is used only for actions you set up or approve: applying labels, archiving, marking read, and saving drafts for your review. YourSec never sends email from your account and never deletes your mail; the only thing it removes is a draft it created itself, when you discard that draft.

Google Limited Use

YourSec's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We do not sell personal data, use Gmail data for advertising, or use it to train or improve a general-purpose AI model. No person reads your Gmail data unless you explicitly ask for support involving specific content, or access is necessary for security, fraud prevention, or a legal obligation.

03

Storage and deletion

Mailbox metadata and assistant-produced working data are kept while Gmail is connected and for as long as they are needed to provide the features you use. We do not persist Gmail bodies as standalone message records, but selected excerpts can remain inside encrypted drafts, summaries, or Tell me conversations.

Disconnecting Gmail revokes the connection and deletes stored email metadata, active brief items and drafts, sender-engagement aggregates, watch observations derived from mail, and mailbox activity logs. It also resets sync state so a later reconnection starts fresh.

Disconnecting does not delete your YourSec account or the account-level material you deliberately created. Watches, preferences, Tell me conversation history, and encrypted cached brief compositions can remain until you delete the account. Tell me history can contain selected email context used during that conversation.

Gmail labels and filters YourSec created remain in Gmail after disconnect. They are part of your mailbox and stay under your control; you can remove them in Gmail settings.

Deleting your account removes the account and its related product data. A founding-pilot application is a separate record retained while the pilot is being selected and operated. You can ask us to delete it at any time by emailing hello@yoursec.ai.

04

How we protect it

  • In transitConnections use HTTPS and modern TLS.
  • DatabaseData is stored in PostgreSQL on Neon with storage-layer encryption and provider access controls.
  • Sensitive fieldsOAuth tokens and sensitive assistant-produced fields are additionally encrypted with AES-256-GCM. Their data keys are wrapped by Google Cloud KMS.
  • OAuth tokensTokens are encrypted at rest and excluded from application logs. Google handles the password and credential exchange.
  • Message bodiesBodies are fetched only when needed. They are not stored as standalone message-body records; selected context retained in assistant work is covered by the sensitive-field encryption above.
05

Service providers

These companies process data only to help operate YourSec. None receives inbox data for advertising.

ProviderRoleData involved
GoogleSign-in, Gmail API, Cloud KMSAccount identity, the Gmail access you grant, and encrypted key operations. KMS does not receive your plaintext content.
VercelHosting, analytics, AI GatewayRequest traffic and aggregate page views. AI requests are routed through its Gateway to the current model provider.
AI model providerAI model processingThe selected email context and instructions needed for a feature, routed through Vercel AI Gateway. We use commercial API terms that do not permit training on your data; inputs are retained briefly for safety review (currently up to 30 days), then deleted.
NeonPostgreSQL hostingStored account and product records. Sensitive content fields receive the additional application-encryption layer described above.
ResendTransactional email deliveryRecipient address, invite or reconnect-email content, and delivery information.
UpstashAbuse prevention and rate limitingIP- or user-derived rate-limit identifiers and counters, not Gmail message content.
Browser push serviceSide-panel freshness notificationsA subscription endpoint and an encrypted, content-free change signal. No subject, sender, or message text.

AI requests pass through Vercel AI Gateway, which lets us change the underlying model provider without changing how your data is protected; the constraints above apply regardless of provider. See Resend's privacy policy for its current terms.

06

Your choices

In YourSec settings you can disconnect Gmail, reconnect it, change product preferences, or delete your account. You can also revoke YourSec directly from your Google Account's third-party access settings.

You may ask for access to, correction of, or a portable copy of the personal data we hold, or ask us to delete a pilot application. Email hello@yoursec.ai. We aim to respond within two business days and may need to verify that the request belongs to you.

07

Policy changes

We will update the effective date when this policy changes. If a change materially affects what we access, how we use it, who receives it, or how long it is kept, we will email everyone with an active account at least 30 days before the change takes effect. When a new use of Google data requires renewed consent, we will ask before making that use.

The person behind the policy

Theo Omoregbee, Founder

Questions or requests: hello@yoursec.ai