Privacy Policy

Last updated: July 12, 2026

Calibrate LLC (“we,” “our,” or “us”) operates Cleanmail, an AI-powered email digest service available on iOS. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Cleanmail, you agree to the practices described here.

This policy is hosted at https://cleanmailapp.com/privacy and is referenced from our OAuth consent screen and in-app Settings.


1. Information We Collect

We collect only the information necessary to provide the Cleanmail service.

Information you provide directly:

Information collected from Google APIs (with your authorization):

Information collected automatically:


2. Google API Services and Limited Use

Cleanmail uses the following Google API scopes:

Google API Services Limited Use disclosure: Cleanmail’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:


3. How We Use Your Information

We use your information solely to provide Cleanmail:

We do not sell, rent, or share your personal information with third parties for marketing purposes.


4. Third-Party Sub-Processors

Cleanmail relies on the following third parties to provide its service. Each receives only the data necessary for its function:

ServicePurposeData shared
Supabase (Supabase Inc., hosted in US East — Ohio)Database and serverless functionsYour profile, digest content, events, subscription state
Anthropic (Anthropic PBC)AI digest generation via Claude APIEmail subject + body for emails you have authorized, sent at request time and not stored at Anthropic per their API terms
Google (Google LLC)Sign-in, Gmail access, Calendar syncOAuth tokens; Gmail messages from selected senders; the individual message you open via “View Email”; Calendar event metadata
Stripe (Stripe, Inc.)Subscription billingEmail address, subscription status, payment status (we never see card numbers)
Resend (Resend, Inc.)Transactional email delivery (partner invitations)The recipient email address you enter when inviting a partner, and the inviter’s display name
Apple Push Notification serviceDelivery of push notificationsAnonymous device token
Trigger.devScheduled job execution for digest deliveryUser ID and digest ID at scheduled times — no email content

We do not transfer Gmail data to any sub-processor other than Anthropic (for digest generation) and Supabase (for storage of the AI-generated summary, not the raw email). The full body of an email you open via “View Email” is retrieved from Google and rendered on your device; it is not stored on our servers (see Section 5).


5. Data Storage and Location

All data is stored in the Supabase region US East (Ohio). Raw email content is not stored at rest — emails are fetched from Gmail at digest-generation time, sent to Anthropic’s API for summarization, and discarded after the AI-generated summary is written to our database. Likewise, when you open an email via “View Email,” its full body is fetched from Gmail and rendered on your device for that viewing session only; it is not written to our database.

The following are stored persistently:


6. Shared Digests (Partner Accounts)

Cleanmail lets two people — for example, two parents — share one digest as co-equal participants. The account that creates the digest is the primary account; a second person who joins is a partner account. Both see and manage the same shared digest. This is different from linking an additional Gmail inbox to your own account (a “linked inbox”), which pools your own mailboxes and does not involve a second person; this section concerns partner accounts only.

Each person connects their own Google account, and neither can read the other’s mailbox. Sender discovery — the search that finds senders to add to a digest — only ever searches the mailbox of the person performing the search. As a result:

Each participant’s Gmail credentials remain private to them. A partner’s mailbox feeds the shared digest using that partner’s own live authorization; we do not copy one participant’s Google access to the other.

Leaving or being removed from a shared digest. A primary account can remove a partner, and a partner can leave on their own, at any time. When a partner leaves or is removed:

To permanently delete your own personal data, see Section 7 (Account Deletion).


7. Data Retention and Account Deletion

Digest history is retained for the period you select in Settings (default 30 days; configurable up to 60 days). Older history is automatically deleted.

You may permanently delete your account and all associated data at any time from within the app: Settings → Delete Account. Account deletion is immediate and removes:

If you are part of a shared digest:

After deletion, no recovery is possible. If you have trouble deleting your account in the app, contact [email protected] and we will delete it manually within 30 days.


8. Your Rights

Depending on your jurisdiction, you may have the right to:

Residents of California (CCPA) and the European Union (GDPR) have additional rights under applicable law. To exercise any of these rights, contact [email protected].


9. Security

We use industry-standard security measures including TLS-encrypted data transmission, encrypted storage via Supabase, and access controls on our serverless functions. OAuth tokens are stored encrypted at rest and never exposed to client devices.

No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you by email within 72 hours and report the incident as required by applicable law.


10. Children’s Privacy

Cleanmail is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided personal information to us, contact [email protected] and we will delete it.


We may disclose personal information when required to do so by law, such as in response to a subpoena, court order, or other legal process. We will notify you of any such request unless prohibited by law.


12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email and by updating the date at the top of this policy. Continued use of Cleanmail after changes take effect constitutes acceptance of the updated policy.


13. Contact

Questions about this Privacy Policy:

Calibrate LLC [email protected]

For privacy-specific inquiries, please include “Privacy” in the subject line.