Skip to content
POSTBIRD
ProductWorkflowWritingTrustSecuritySupport
Chrome Web Store coming soon

Trust center

Privacy Policy

Postbird is a Gmail Chrome extension that helps with triage, follow-up reminders, thread context, and clear writing tools. This policy covers the extension-first MVP, identity-only account sign-in, optional Gmail read-only access for the current thread, free Local helpers, managed Postbird Cloud Thread Intelligence, and managed Compose/HUD assistance for eligible account-based users.

Last updated: July 17, 2026

Who we are

Postbird's launch contact for privacy, deletion, support, and security requests is support@postbird.app.

What Postbird Processes

  • Local preferences, local helper state, language, telemetry, onboarding state, and legacy cleanup state where present.
  • VIP senders, manually marked must-reply thread identifiers, follow-up labels and times, user-authored local reminder notes, limited reminder or thread metadata, Chrome alarm metadata, opt-in anonymous metadata-only telemetry counters/events, and local consent records.
  • If you sign in, identity-only account metadata such as email address, display name, avatar, account membership, and account audit metadata.
  • If you explicitly connect Gmail, Postbird uses the Gmail read-only scope to fetch messages for the current open thread when you ask for Context. Google returns the selected Gmail address and mailbox profile metadata. Postbird stores the connected address as application-encrypted identity metadata, plus a separate comparison HMAC, opaque reference, status, permission generation, and timestamps. Active members of the same Postbird account can see connected full addresses in trusted Settings. Free has no backend refresh custody. For Paid, the Google refresh credential is separately application-encrypted in a private backend table and used only to mint a short-lived extension access token. Postbird does not store Gmail message content, OAuth codes, or Gmail access tokens on its backend.
  • If eligible signed-in users explicitly enable managed Postbird Cloud Thread Intelligence, scoped visible thread context for Summary, Facts, Evidence, Draft Reply, and repair may be processed by Postbird Cloud. This can include sender emails, message excerpts or snippets, dates, links, asks, commitments, decisions, compact attachment metadata, selected current-thread inline image content for image-heavy Thread Intelligence, reply-generation context, bounded reply-repair context, and content-free request/accounting metadata.
  • If eligible signed-in users separately enable managed Compose/HUD consent, Postbird Cloud may process only the selected compose text or owned draft text needed for a user-triggered HUD or Compose rewrite action, subject text only when allowed for new-compose subject/body actions, and content-free request/accounting metadata.

Current local behavior

Postbird runs free Local Gmail helpers in the browser. Signed-out users use visible-thread DOM data only and are not offered Gmail API connection controls. A signed-in user may separately choose Gmail read-only access for the current thread. Free keeps one matching session-only access token and attempts exact-account silent renewal. Paid may remember up to five active Gmail identities, while the browser keeps at most one active access token; the backend mints a fresh token from private encrypted refresh custody. Paid switching is bounded to ten distinct identities in rolling 30 days and three newly seen identities in rolling 24 hours. Trusted Settings shows the account-wide connected roster and safe counts, never identity history. Reading remains creator-owned. Disconnect erases the readable encrypted address and Paid credential custody; membership or entitlement loss has matching cleanup. The backend never reads Gmail content. Managed Postbird Cloud remains separately consented and keeps its existing scoped processing and output-cache disclosures.

Managed Postbird Cloud

  • Local helpers remain available without sign-in, provider network access, or account quota.
  • Managed Postbird Cloud Thread Intelligence is account-based. In the current private-beta scope it can process visible thread context for Summary, Facts, Evidence, Draft Reply, compact Summary repair, Facts repair, and reply repair after sign-in, entitlement, and explicit managed consent.
  • The managed Compose/HUD rewrite actions are account-based and require sign-in, entitlement, explicit managed Compose/HUD consent, quota, and backend safety gates before processing selected compose text or owned draft text for the user-requested rewrite.

No whole-inbox scan

Postbird does not sync, index, or scan the whole mailbox. Gmail API reads are limited to messages in the current open thread and occur only after the user connects Gmail and asks for a Context action.

No sale, ads, or generalized training

Postbird does not sell personal data, run ads, or use Gmail content to train generalized AI models. Optional managed provider calls are limited to user-requested managed Thread Intelligence on visible thread context and managed Compose/HUD writing actions on selected compose text or owned draft text; follow-up reminder storage remains local in the current MVP.

Permissions

Postbird requests Chrome extension permissions for local and session storage, identity-only sign-in, active-tab/script recovery in Gmail, local alarms and notifications, Gmail UI surfaces, the Postbird backend at www.postbird.app, Google OAuth and Gmail API endpoints, and the Postbird Supabase auth project at mgqvvernvwicfaseuhoy.supabase.co. Gmail read-only access is requested separately through an explicit disclosure and Google consent flow; signing in to Postbird does not grant Gmail access.

Retention

  • Managed Postbird Cloud Thread Intelligence request payloads are processed to answer the requested Summary, Facts, Evidence, Draft Reply, or repair action. Managed Compose/HUD request payloads are processed only for the user-triggered selected-text or owned-draft rewrite action. The current managed output-cache slice is a short-lived backend validated output cache for managed `thread_summary` and `thread_facts` parent output only, protected server-side and retained for 24 hours; accepted repaired Summary/Facts output may be promoted into that same parent cache row after backend proof and extension final acceptance. Postbird also stores content-free operational metadata such as usage, quota, audit, provider/model family, request status, and consent records.
  • Local results can be processed in memory, and Thread Intelligence analyses or reply results may be cached in the browser profile or Chrome session storage to avoid repeated requests.
  • A connected Gmail short-lived access token stays in browser session storage only. Free uses online authorization and has no backend refresh custody. Paid uses offline consent; its refresh credential is application-encrypted in a private backend table and used only to mint a short-lived extension token. The connected address uses a separate encryption envelope and comparison HMAC. Disconnect, membership loss, Paid-entitlement loss, and account deletion erase credential custody. Postbird does not retain Gmail message content, OAuth codes, or Gmail access tokens.
  • Paid rolling identity history is pseudonymous and bounded: a daily cleanup deletes identity episodes after a 34-day last-use cutoff, so healthy scheduled cleanup removes them before they reach 35 days old. Account deletion removes live rolling-history rows immediately; backup/PITR copies age out under the configured retention window.
  • Local preferences, VIP senders, triage state, follow-ups, onboarding state, identity session material, opt-in anonymous local telemetry counters/events, consent records, and local/session cache records remain in the browser profile until the user deletes Postbird data, signs out where applicable, uninstalls the extension, or clears extension storage.
  • Account identity metadata and managed-cloud consent/accounting metadata are retained until account deletion or managed-cloud deletion is requested and completed, subject to required support, security, fraud-prevention, or legal retention. Backend validated output cache purge covers consent revoke, managed Cloud disable for the relevant consent lane, account deletion, retention expiry, admin/legal deletion requests, and authenticated unlink or sign-out where a valid session still exists.
  • Future hosted telemetry, if launched, must be separately disclosed and retained only for a limited support and reliability window.

Controls and deletion

  • Users can keep managed Postbird Cloud consent off, turn it off later, sign out of Postbird account identity, export settings without auth session material or email snippets, reset onboarding, and use Delete local Postbird data in Postbird Settings. Exports can include user-authored local reminder notes because they are part of the local reminder data.
  • Users can connect or reconnect the Gmail account open in the current tab from Sidekick after signing in. Paid users add another Gmail account from Settings, and Settings is the only surface that disconnects an identified saved account. Disconnect Gmail attempts provider revocation, clears the local access token and related caches, clears the readable encrypted address, and erases Paid refresh custody. The keyed non-display HMAC, disconnected status, bounded lifecycle timestamps, and rolling history remain only for their disclosed policy/retention windows. Account deletion cascades connection, credential, and rolling-history rows; backup/PITR copies age out under the configured retention window.
  • Eligible signed-in users can also keep managed Postbird Cloud consent off or revoke it later. Revoking managed Thread Intelligence or managed Compose/HUD consent blocks new sends for that managed surface, but it does not remove prior account/usage metadata already needed for audit, quota, security, or support.
  • Delete local Postbird data clears current local extension data, local auth session material, and matching Postbird follow-up alarms. Supabase identity/account metadata and managed-cloud deletion are requested separately through support.
  • Privacy, access, correction, export, and deletion requests can be sent to support@postbird.app. Postbird acknowledges deletion and privacy requests within 15 business days where identity and request scope can be verified.

Third parties and security

Postbird uses Google OAuth and the Gmail API for explicit Gmail read-only authorization and current-thread reads, Supabase/Postgres for Postbird identity/account plus encrypted Gmail connection and Paid credential records, and Postbird-managed AI providers only after explicit managed consent. The broker delivers only a short-lived access token encrypted to the initiating extension. Paid refresh custody uses a separate application-encryption key outside the database and is never returned to the extension. Gmail content reads remain in the extension. Local Postbird auth material is encrypted in browser storage, Gmail access tokens use session-only storage, and network requests use HTTPS.

Account and cloud data

Postbird may collect account identity metadata when you sign in, such as your email address, display name, avatar, account membership, and account audit metadata. When Gmail is connected, Postbird retains an application-encrypted Google-proven address, a separate comparison HMAC, bounded lifecycle metadata, and Paid-only encrypted refresh custody. These enforce Free same-account, Paid five-active, rolling ten-in-30-days, and three-new-in-24-hours policies and support Connect, Reconnect, or Disconnect state. Backend Gmail sync and Gmail content/access-token storage are not offered. Managed Postbird Cloud remains limited to the separately consented flows and cache contract described above.

Subprocessors and cross-border processing

Current service providers include Google for OAuth and Gmail API access, Supabase for identity/account and application-encrypted Gmail connection identity/lifecycle records, Vercel for the narrow Gmail OAuth broker and Postbird backend, and Postbird-managed AI providers for explicitly consented managed Thread Intelligence and Compose/HUD requests. Processing follows the relevant provider terms. Postbird must update this policy before adding billing, additional subprocessors, broader Gmail access, or broader hosted output-cache surfaces.

Children

Postbird is not directed to children.

POSTBIRD

Your privacy-first Gmail sidekick.

PrivacyTermsSupportDelete DataLimited UseSecurity
Chrome Web Store coming soon