Privacy policy
Privacy policy
Last updated: August 20, 2026
Letterdoll (the “Service”) handles only the minimum information needed for clearly stated purposes. This policy explains how the Service collects, uses, stores, and shares information.
1. Information we collect
Google sign-in information
Google Identity Services provides a unique Google Account identifier (sub), email address, verified-email status, and display name. For the first Gmail connection, we ask for consent after sign-in; you can add another Gmail account from Settings. We do not request permissions for an account unless you allow them.
Email data you choose
We process the connected address, message body, headers, participants, dates, labels, and attachment metadata for classification and summaries only when you connect and start syncing Gmail or explicitly import an MBOX. Gmail permissions allow reading and state changes. We change state only for messages you select, to mark them read, remove them from the inbox, or immediately undo the action in the Gmail that received them. We do not send, delete, automatically archive, or edit arbitrary labels, and we do not store attachment contents. External images in HTML bodies are not loaded by default; if you choose to show them, connection information such as your IP address may reach the image host.
Technical information
For security and incident investigation, Cloudflare may record minimal technical logs such as request time, response status, and error type. We do not intentionally log message bodies, attachment contents, or authentication tokens.
2. How we use information
- Verify that you are an authorized user
- Classify, summarize, group, and evaluate email accuracy
- Mark, archive, or undo actions for messages you explicitly select
- Prevent abuse, respond to incidents, and improve quality
- Respond to your questions
We do not sell collected information for advertising or use it to profile you for third-party advertising.
3. Google user data
Information from Google is used for identity verification, sessions, and Gmail sync and organization that you explicitly start. The unique identifier and email address of the Google Account used to sign in identify you and confirm the account you authorized. Additional Gmail addresses identify and label inboxes. We do not persist Google ID tokens or short-lived access tokens. Refresh tokens needed for ongoing connections are encrypted separately for each Gmail account.
Our use and transfer of information from the Google Workspace API follows the Google Workspace API User Data and Developer Policy and its Limited Use requirements.
4. Storage and retention
Sign-in state is stored in your browser as an encrypted HttpOnly cookie for up to 12 hours and is removed when you sign out. Active data from the Cloudflare version—including synced messages, connected addresses, encrypted per-account refresh tokens, classifications, and LLM cache—is stored in Cloudflare D1 until the account is deleted.
Disconnecting Gmail does not delete imported data. “Delete account and all data” removes account data from active D1, though it may remain in Cloudflare D1 Time Travel or recovery history for up to 30 days. Data imported locally is stored outside the repository in local data storage.
5. External services and sharing
The Service uses the following services as needed to provide it:
- Google Identity Services / Gmail API: identity verification, reading mail you authorize, and marking or archiving messages you explicitly select
- Cloudflare Workers / D1 / Queues: web delivery, authentication, email storage, sync, and security logs
- OpenAI API: LLM classification you authorize and Gmail messages that rules and known templates cannot classify
Letterdoll does not use Google user data to create, train, or improve general-purpose AI models and does not enable sharing for that purpose. OpenAI’s API data controls are described in its data management documentation. Google user data is transferred to Cloudflare and OpenAI only as needed for the features above. We do not disclose personal information to other third parties unless required by law, needed for safety, or explicitly authorized by you.
6. Security
We verify ID-token signatures, issuers, audiences, and expiry on the server, and use OAuth state for CSRF protection, encrypted cookies, HTTPS, and authorized-email checks. Gmail client secrets and refresh tokens never reach the browser; each refresh token is encrypted with a dedicated AES-GCM key. Secrets are not stored in source code; they are managed as Cloudflare Secrets.
7. Your choices and deletion
You can sign out at any time and disconnect Gmail accounts individually from Settings. We attempt to revoke the Google token for the selected account and delete only its stored refresh token. Other Gmail connections are unaffected, and imported messages are not automatically deleted.
To delete all active D1 data, after signing in go to Settings → Delete account and all data. Data may remain in Cloudflare D1 Time Travel or recovery history for up to 30 days. You can delete local data with the deletion command provided to you.
8. Changes to this policy
If our practices change, we will update this page and its date. We will give reasonable advance notice of material changes.