Privacy Policy

1. Introduction

FlowMail is an email organization tool that connects to your Gmail account (read-only) so you can sort messages into boards using rules, and optionally get AI-assisted suggestions. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have.

2. Information We Collect

2.1 Information from Google Sign-In

When you sign in with Google, we request only the following scopes:

  • Your basic profile information (name, email address, profile picture)
  • Read-only access to Gmail (gmail.readonly) — we can view your labels, messages, and threads, but we cannot send email, delete or modify messages, or change labels on your behalf

2.2 Email Data Stored in Boards

When you add an email to a board, we store a limited copy of its metadata (subject, sender, recipients, snippet, labels, date, and thread ID) so the board can display it without re-fetching from Gmail every time. Sensitive fields (subject, sender, recipients, snippet) are encrypted at rest. Emails you have not added to a board are fetched live from Gmail and are not stored in our database.

2.3 AI Feature Data

If you enable AI features, message content may be sent to Google Gemini to generate rule suggestions, board suggestions, or thread summaries. Generated summaries are cached (keyed to your account and the message) so we don't reprocess the same content repeatedly. If you choose to bring your own Gemini API key (BYOK), that key is encrypted before it is stored and is used only to make AI requests on your behalf.

2.4 Waitlist Sign-Ups

If you join our waitlist, we collect your email address to send you product updates and your invite when available.

3. How We Use Your Information

We use the collected information to:

  • Authenticate you and maintain your session
  • Organize your emails into boards according to your rules
  • Generate optional AI suggestions (rules, boards, thread summaries) and track AI usage against daily limits or your own API key
  • Sync new Gmail messages into your boards when you request a sync
  • Maintain and improve the security and reliability of the service

4. Data Storage and Security

Your Gmail OAuth tokens, any BYOK AI API key, and the sensitive fields of emails saved to boards are encrypted at rest using per-user encryption keys, which are themselves protected by a master key that is never stored in our database. Data is hosted on Supabase (PostgreSQL), with our backend running on Google Cloud Run and our frontend on Vercel.

5. Third-Party Services

We rely on the following third-party services:

  • Google — for sign-in and read-only Gmail access. See Google's Privacy Policy
  • Google Gemini — powers optional AI suggestions and summaries; message content is sent to Gemini only when you use an AI feature
  • Supabase — database and authentication infrastructure
  • Vercel — frontend hosting and product analytics (Vercel Analytics)

6. Your Rights

You have the right to:

  • Access the information we hold about you
  • Turn AI features off at any time from AI settings
  • Delete your account, which permanently removes your boards, board emails, rules, to-dos, AI settings, encryption keys, and stored OAuth tokens
  • Unsubscribe from waitlist or product emails

7. Contact Us

If you have any questions about this Privacy Policy, please contact us at:support@flowmail.in

8. Updates to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "last updated" date.

Last updated: 8/17/2026