Legal
Privacy policy
Effective September 2, 2026
Redakt is built to let you work with email without turning your inbox into a data product. This policy explains what Redakt accesses, why it needs that access, what it stores, and how you can remove it.
1. Who this policy covers
This policy applies to the Redakt website, hosted service, and email client. Redakt is an open-source mail product that lets you connect Gmail or use a mailbox on a domain you control. Questions about this policy can be sent to hey@stylessh.dev.
2. Information Redakt collects
- Account information. Your name, email address, profile image, sign-in method, password hash when you use a password, account preferences, and account creation and update times.
- Session and security information. Session tokens, session expiry, IP address, user agent, and operational logs needed to secure and troubleshoot the service.
- Google account and Gmail information. Your Google account identifier, email address, name, profile image, OAuth grant, Gmail mailbox identity, message and thread metadata, message content, attachments, drafts, labels, and mailbox changes you ask Redakt to make.
- Gmail connection metadata. A Gmail history cursor, subscription expiry, last-sync time, connection health, and error state so Redakt can keep the inbox current.
- Hosted-mail information. If you use a custom domain, Redakt stores the domain, mailbox address, encrypted mailbox credential, DNS setup and verification state, and the mail held by the connected mail server.
- Optional AI settings. If you turn on an AI feature, Redakt stores your selected provider and model, an encrypted provider API key, the features you enabled, and the time and version of your data-processing agreement.
3. How Redakt uses information
- Create and secure your account, authenticate requests, and remember your preferences.
- Display, search, organize, draft, send, and otherwise process email when you choose those actions.
- Classify recent inbox conversations in Focus or assist with writing when you separately turn on those AI features.
- Keep connected mailboxes synchronized and notify the interface when Gmail changes.
- Provide custom-domain mailboxes and help you configure required DNS records.
- Prevent abuse, diagnose failures, maintain reliability, and comply with legal obligations.
- Respond to support requests and communicate material service or policy changes.
4. How Redakt handles Google user data
Google sign-in and Gmail access are separate. Google sign-in requests basic identity information. Redakt requests Gmail access only when you choose to connect Gmail. That access lets Redakt show and search your mailbox, read messages and attachments, create and send drafts, change read and starred state, apply mailbox labels, and move threads between inbox, archive, spam, and trash.
Redakt stores your Google account identity, encrypted access and refresh tokens, granted permissions, and the connection metadata described above. Gmail remains the source of truth. Gmail message bodies and attachments are fetched when needed to serve your request and are not persisted in Redakt's application database. Redakt processes the fetched data to return the requested mailbox view to your authenticated browser.
Redakt does not sell Google user data, use it for advertising, determine creditworthiness, or use it to train general-purpose AI or machine-learning models. People do not read your Gmail data unless you give explicit permission for support, access is necessary to investigate a security or abuse issue, or access is required by law.
AI features are optional and off by default. If you add your own provider API key and agree to AI processing, Focus may send the subject, participants, dates, and bounded message text from up to 20 recent inbox conversations so the provider can classify them. Smart Compose may send the current draft, subject, recipients, and recent messages from the conversation so the provider can complete, draft, or revise text. Redakt does not use this content to train models or let an AI feature send mail or apply mailbox actions automatically. The selected provider processes the data under your provider account and its terms.
Redakt's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
5. When information is shared
Redakt does not sell personal information. Information is shared only as needed to provide the service, protect it, comply with law, or complete a transaction you request.
- With Google when Redakt makes Gmail API or account requests on your behalf.
- With infrastructure providers that host the application, database, mail server, networking, or security services, subject to their role in operating Redakt.
- With OpenAI, Anthropic, or Google Gemini only when you enable an AI feature and request or trigger its assistance; the request uses your provider API key and is limited to the classification or writing assistance you enabled.
- When you direct Redakt to send mail or otherwise share content with a recipient.
- When required by applicable law or necessary to protect users, Redakt, or the public from fraud, abuse, or security threats.
- As part of a merger, acquisition, or sale of assets only after any consent required by the Google user-data rules or applicable law is obtained.
6. Retention, disconnection, and deletion
Account information and connection metadata are kept while your account or connected mailbox remains active, and longer only when needed for security, legal obligations, or resolving disputes. Gmail message bodies and attachments are not retained in Redakt's application database. Focus classifications and unaccepted inline writing suggestions are returned to your browser and are not persisted as separate AI records. Text you accept may be saved as part of a normal email draft. Your encrypted AI API key, enabled-feature settings, and consent record remain until you remove them or delete your account. Operational logs are kept only as long as reasonably necessary for security and reliability.
- Disconnect Gmail: Open Settings, choose Email accounts, then remove the Gmail account. Redakt stops the Gmail watch, asks Google to revoke the grant, clears local token material, and deletes the connection metadata. Mail remains in Gmail.
- Revoke at Google: You can also remove Redakt from your Google Account connections.
- Delete Redakt: Open Settings, choose Account, then delete the account. This removes the Redakt account and its local settings, sessions, connected-account records, custom domains, and hosted-mail data. Remove Redakt from Google Account connections if you also want to confirm the Google grant is revoked.
7. Security
Redakt uses HTTPS in transit, encrypted OAuth tokens, mailbox credentials, and AI provider API keys at rest, access controls, and other reasonable safeguards. No online service can guarantee absolute security, so you should use a strong password, protect your Google and AI provider accounts, and report suspected unauthorized access promptly.
8. Cookies and local storage
Redakt uses necessary cookies for authentication, security, and saved preferences. It may use browser storage to remember interface state such as open mailbox tabs. Redakt does not use third-party advertising cookies. Google may use its own cookies when you choose Google sign-in or Gmail authorization, subject to Google's policies.
Remote images can be used by senders to learn that a message was opened and to receive technical information such as your IP address and browser details. Redakt loads remote images by default. You can turn off Load remote images under Settings, then Appearance & reading.
9. Your choices and rights
You can update your name and preferences, disconnect Gmail, revoke Google access, or delete your Redakt account from Settings. Depending on where you live, you may also have rights to access, correct, delete, restrict, or receive a copy of personal information. Contact Redakt to make a request. Identity verification may be required before a request is completed.
10. International processing and children
Redakt and its service providers may process information in countries other than the one where you live. Redakt is not directed to children under 13, and children under the minimum age required in their country may not use the service without authorization from a parent or guardian.
11. Changes and contact
This policy may change as Redakt changes or legal requirements evolve. Material changes will be announced in the service or through another reasonable channel before they take effect when required. Questions or privacy requests can be sent to hey@stylessh.dev.