Skip to content
POSTBIRD
ProductWorkflowWritingTrustSecuritySupport
Chrome Web Store coming soon

Trust center

Security

Security is a required trust route for Postbird because the product works inside Gmail and includes local helpers, identity auth, and managed Postbird Cloud surfaces.

Last updated: July 17, 2026

Local-first boundary

The current product is extension-first and local-first by default. Signed-out users use visible-thread DOM data only. Optional Gmail read-only access is scoped to the current thread and requested separately after Postbird sign-in. Gmail reads stay in the extension. Postbird does not offer backend Gmail content storage, whole-mailbox sync, or server-initiated mailbox access; Paid encrypted refresh custody is used only to mint a short-lived extension token. Managed Postbird Cloud Thread Intelligence processes scoped context only after sign-in, entitlement, and explicit managed consent.

Extension permissions

Chrome extension permissions stay tied to shipped Gmail features. Gmail read-only authorization uses a separate Web OAuth client and a narrow authorization-code broker; the existing Supabase identity client remains separate and unchanged.

Gmail authorization integrity

The broker binds each OAuth start to the signed-in Postbird user, chosen Gmail connection, requested action, extension callback, and expected permission generation. The extension receives an authenticated one-time connection proof; exact replay is rejected. Access tokens, codes, private keys, full callbacks, and Gmail content are excluded from backend persistence and logs. Paid refresh credentials are encrypted before storage, bound to the exact proof/connection authority, and never logged or returned to the extension.

Cloud and provider boundaries

Managed Postbird Cloud Thread Intelligence is an account-based private-beta path for Summary, Facts, Evidence, Draft Reply, and repair. Its scoped current-thread input may come from the visible Gmail page or the user's separately approved Gmail read-only API connection. Managed Compose/HUD is a separate account-based private-beta path for user-triggered selected-text or owned-draft writing actions. Both managed paths require backend auth, entitlement, quota, consent, provider routing, safety checks, and content-free operational metadata. The current managed output-cache slice is limited to encrypted validated parent `thread_summary` and `thread_facts` output for 24 hours and support metadata by default; accepted repaired Summary/Facts output may replace those same parent cache rows only after backend proof, parent validation, and extension final acceptance. Repair actions are not independently cached. Persistent hosted-output caching for managed Compose/HUD `compose_transform`, replies, broader Gmail API use or mailbox sync, support/admin content access, broader hosted cache surfaces, and additional subprocessors remain deferred and require review and disclosure before launch.

Security contact readiness

Responsible reports should be sent to support@postbird.app.

POSTBIRD

Your privacy-first Gmail sidekick.

PrivacyTermsSupportDelete DataLimited UseSecurity
Chrome Web Store coming soon