Mailsort
TermsPrivacy
Draft, not legal advice. These pages describe accurately what Mailsort does with your data, but they have not been reviewed by a lawyer. Have them reviewed before relying on them commercially.

Privacy

Last updated 11 September 2026

The short version

Mailsort reads who sent your mail, what the subject line says, and when it arrived. It uses that to file the message into a folder you approved. It does not store the contents of your messages, it cannot send or delete mail, and it never touches anything older than the catch-up window shown on your plan.

What we store

  • Your name, email address and profile picture, from whichever account you signed in with.
  • For each message we file: the sender's address and domain, the subject line, the date it arrived, which folder it went to, and one sentence explaining why.
  • The folders and rules you approve, and any corrections you make.
  • An audit log of consequential actions — mailboxes connected, plans changed, data deleted.
  • Billing records, if you pay us. Card details go to Stripe and never reach our servers.

What we never store

  • The body of any message.
  • Attachments, of any kind.
  • Anything from a message older than your plan's catch-up window.

This is enforced by how the software is built, not only by policy. The permissions we request return message headers and labels; the code that talks to your mail provider has no path that fetches a body, and the database has no column that could hold one.

What briefly leaves our systems

To decide where a message belongs, we send the sender, the subject and the short preview line your mail provider already generates to Anthropic, which runs the classification model. That preview is used for the decision and discarded. It is never written to our database and never appears in a log.

Anthropic does not train models on data sent through its API. We do not use your mail for advertising, profiling, or any purpose other than organising your inbox.

Google user data

Mailsort's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Gmail data is used only to provide and improve the mail-organising features you can see, is never transferred to others except as needed to provide those features or as required by law, is never used for advertising, and is never read by a human except with your explicit permission, to resolve a support issue you raised, or where required by law.

Who else processes your data

We use these companies to run the service. Each sees only what it needs.

Supabase
Database, authentication and encrypted token storage
Anthropic
Classifies each message from sender, subject and preview
Vercel
Runs the application
Inngest
Schedules the background jobs that sort mail
Stripe
Payments. Card details never reach our servers
Google / Microsoft
Your mailbox, under the permission you granted

Access to your mailbox

We hold an access token issued by your mail provider, encrypted at rest and readable only by our servers. It permits labelling and moving messages. It does not permit sending, replying, or permanent deletion. You can revoke it at any time from your Google or Microsoft account settings, or by disconnecting the mailbox in Mailsort, which destroys our copy.

Keeping and deleting

We keep your data until you delete it. “Delete everything” in Data and privacy removes every mailbox, folder record, decision, rule and your login, and destroys the stored access tokens. It happens immediately and cannot be undone. Folders we created stay in your mailbox; you can delete those yourself.

Backups may retain deleted data for up to 30 days before being overwritten. Audit records required for tax or accounting are kept as long as the law requires.

Where we are, and which law applies

Mailsort is operated from New Jersey, United States, and your data is stored on servers in the United States. If you use the service from outside the US, you are sending your data to the US to be processed here.

Your rights

Wherever you live, you can see everything we hold about you in the app and delete all of it from Data and privacy. For anything else — a copy in a portable format, a correction, or an objection to how we process something — write to support@getmailsort.com and we will respond within 30 days. We will not charge you for this or treat you differently for asking.

If you are covered by the New Jersey Data Privacy Act, the California Consumer Privacy Act, the UK or EU GDPR, or a similar law, those rights include access, correction, deletion, portability and the right to appeal a refusal. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it for automated decisions that produce legal effects about you.

Children

Mailsort is not intended for anyone under 16. We do not knowingly collect data from children.

Changes

If we change this in a way that materially affects you, we will tell you by email before it takes effect.

Contact

Mailsort is run over email. Write to support@getmailsort.com with anything at all — a privacy request, a complaint, or a question about what we hold. That address reaches a person, and we answer within 30 days at the outside, usually far sooner.

If you are in the UK or EU and think we have got something wrong, you also have the right to complain to your local data protection authority.

Questions: support@getmailsort.com