What we read,
and what we never will.
In thirty seconds
- We read
- Gmail metadata (sender, subject, snippet, labels, timestamps) to organize your inbox. Full message bodies are fetched live only when the assistant prepares a draft or summary, and are never stored.
- We hold
- Metadata and the drafts we prepare for you, on our own database. Tokens and AI-prepared content are encrypted at rest with Google Cloud KMS. Tokens are never logged.
- We share
- With Anthropic, to prepare your drafts and summaries. Anthropic keeps that content for up to 30 days for safety checks, then deletes it, and never trains on it. Nothing sold. Nothing for ads.
- We won't
- Send, archive, or delete email without your explicit approval. Train any model on your inbox. Keep anything after you disconnect.
01
What YourSec accesses
YourSec connects to your Gmail through Google's OAuth 2.0. We request two Gmail permissions: read ('gmail.readonly') to classify and organize your inbox, and modify ('gmail.modify') to prepare draft replies you review before anything is sent, and to apply labels and archive when you ask. We never receive your Gmail password.
Day to day we read metadata (sender, subject, snippet, timestamps, labels) to surface what needs you. Full message bodies are fetched live from Gmail only at the moment the assistant prepares a draft or summary, used in that request, and never written to our database.
02
How your data is used
Your data is used to organize your desk, watch the threads you put a watch on, and prepare drafts and summaries for your review. That's the entire surface area.
We do not sell your data. We do not share it with third parties for advertising. We do not use the contents of your email to train, fine-tune, or improve any AI model, ours or anyone else's.
03
How long we keep things
Metadata is retained while your account is connected so the assistant can understand patterns over time. The moment you disconnect Gmail (Settings → Connections), we revoke our access and immediately delete everything we derived from your mailbox: metadata, the drafts and notes we prepared, engagement aggregates, and activity logs. Your watch definitions stay so they still work if you reconnect.
One exception, by design: any Gmail labels or filters you asked the assistant to set up (e.g. via the Remember for this sender opt-in) live in your Gmail account, not ours. We leave those alone on disconnect so we don't silently undo organization you wanted. Remove or edit them any time from Gmail's own Settings → Filters page, or from Settings → Senders here while connected.
Deleting your account removes everything on our side in one pass, watch definitions included, with nothing left behind.
04
How we protect it
- TransitAll traffic over HTTPS / TLS 1.2+.
- At restPostgreSQL (Neon), encrypted at the storage layer. On top of that, the sensitive fields get a second layer of application-level encryption, so a database dump on its own reveals nothing readable.
- Field encryptionOAuth tokens and AI-prepared content (drafts, draft revisions, the assistant's reasoning notes) are encrypted with AES-256-GCM. The data keys are themselves wrapped by Google Cloud KMS (envelope encryption), so we never hold an unwrapped master key.
- TokensGoogle OAuth tokens are encrypted at rest and never written to logs. We never store your Gmail password. Google handles the credential exchange end to end.
- AIContent sent to Anthropic's Claude API is retained by Anthropic for up to 30 days for trust and safety, then deleted, and is never used to train or improve any model, per Anthropic's commercial terms.
05
Third parties we work with
| Provider | What they do | What they see |
|---|---|---|
| Anthropic | Prepares drafts, summaries, classifications | Email content; kept up to 30 days for safety, then deleted; no training |
| OAuth identity, Gmail API, Cloud KMS | The mailbox access you grant; KMS sees only wrapped keys, never your content | |
| Neon | Database hosting | Encrypted storage; sensitive fields encrypted again |
| Vercel | Application hosting | Request traffic; no direct database content access |
Infrastructure providers used for rate limiting and operations see request identifiers only, never email content. No third party receives your data for advertising.
06
Your rights
From Settings → Connections you can disconnect Gmail or delete your account at any time. Disconnecting revokes our access and immediately deletes everything we derived from your mailbox. Deleting your account removes the rest.
You can request a portable copy of the data we hold about you, or ask us a question, by emailing hello@yoursec.ai. We respond within two business days.
07
Changes to this policy
If we change anything material (what we access, who we share with, how long we retain), we will email everyone with an active account at least 30 days before the change takes effect. You can leave at any time, and your data leaves with you.