Privacy
What Gmail data Selyf reads, what it stores, what it sends to an AI provider and when, how long it keeps anything, and how to delete it.
This page describes actual system behavior. It is documentation, not a substitute for legal advice — see the note at the bottom for what that means.
What Gmail data is read
With your read-only Gmail connection, Selyf reads inbox message metadata: subject line, sender, a short snippet, timestamps, and unread status. It does not fetch the full message body or attachments for storage.
What's stored in Selyf's own database
The metadata above, plus AI analysis results (priority, reply status, reason, suggested action, confidence) for threads you've analyzed, and account/session records needed to keep you signed in. Your OAuth refresh token is stored encrypted (AES-256-GCM), never in plain text.
What's sent to the AI provider
When you ask for an analysis or a draft on a specific thread, that thread's message content is sent to the configured AI provider (Anthropic or Gemini) to generate the result. This only happens for a thread you explicitly open and act on — not in bulk, and not on a schedule.
An analyzed message's result is cached, so the same message is never re-sent to the AI provider a second time.
How draft requests are handled
Generating a draft sends the thread's content and your requested tone to the same AI provider, and returns editable text that exists only in your browser tab. Nothing is written to Gmail, saved as a Gmail draft, or sent anywhere — the only action available is copying the text to your clipboard yourself.
Retention
Data retention follows the service's configured retention policy.
You don't need to wait for it — deleting your account removes everything immediately (see below).
Audit logs
Security-relevant events (connecting an account, disconnecting, a failed OAuth attempt, account deletion) are recorded in an internal audit log used for security investigation, not analytics or profiling. If you delete your account, this log is anonymized — your identifying information is removed from it, not left attached.
Disconnect and delete
You can disconnect your Google account or permanently delete your Selyf account — including your Google connection, synced metadata, and AI analysis results — at any time from the Security page in your dashboard. Both actions take effect immediately.
Third parties
Two categories of third party ever see any of your data: Google (as the source of your Gmail data, under Google's own terms for the OAuth scope you granted), and the configured AI provider — Anthropic or Gemini — for the specific thread content you choose to analyze or draft a reply for. Selyf does not sell, share, or otherwise provide your data to anyone else.
This page is a factual description of how the product currently works, kept accurate as the product changes. It isn't legal advice, and it isn't a substitute for a reviewed privacy policy appropriate to your jurisdiction — see Terms for the current status of that.