Privacy policy
For the Google OAuth application claude-gmail. Last updated 13 September 2026.
Who runs this application
This application is operated privately by Shemeer P (folktaler.com), reachable at shemeer@aikyamhq.com. It is a self-hosted installation of the open-source project Inbox Zero, running on hardware the operator owns and controls.
Who it is for
It is a personal tool. The only mailboxes connected to it are ones the operator connects themselves. It is not offered to the public, there is no sign-up, and no third party is invited to use it.
What Google data it accesses
gmail.modify— reads messages and applies labels, archives and drafts replies in the connected mailbox.gmail.settings.basic— reads and updates basic Gmail settings such as filters and labels.userinfo.email,userinfo.profile,openid— the account's email address and basic profile, used to identify which mailbox is which.
What it does with that data
Message content is used to sort, label and summarise mail, and to prepare draft replies, in the connected mailbox only. It is not used for advertising, not sold, not rented, and not used to build any profile of anyone for any purpose beyond running these features.
Where the data is stored
Messages and metadata are stored in a PostgreSQL database on a private machine on the operator's own network. The database is not exposed to the public internet. The web interface is reachable only over an authenticated connection and is not open to sign-up.
Who else sees the data
To sort mail and write drafts, message content is sent to Anthropic for processing by its Claude models, and is handled there under Anthropic's privacy policy. No other processor receives message content, and nothing is passed to any advertising or analytics service.
If you email one of the connected mailboxes, the content of that email is handled as described above — the same as it would be by any mail client with an assistant feature.
Keeping it, and deleting it
Data is kept only while a mailbox stays connected. Disconnecting an account, or revoking access at myaccount.google.com/permissions, stops all further access immediately. To have stored data erased, write to shemeer@aikyamhq.com and it will be deleted from the database and from backups on their normal rotation.
Security
OAuth tokens are held encrypted in the application's database. Access to the host machine is restricted to the operator. Traffic to the web interface is served over HTTPS.
Limited Use
This application's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
If this policy changes, the date at the top of this page changes with it.