Privacy Policy
Last updated: September 27, 2026
Initial (“Initial,” “we,” “us”) is an email assistant that connects to your mailbox, keeps it organized in the background, and lets you work with it through your inbox, topics, chat, and a daily briefing. This policy describes what data we collect, how we use it, and the choices you have. It is written to be read, not skimmed — the short version is: we keep an encrypted working copy of your mailbox so the product is fast and useful; we never sell your data or use it to train AI models; and you can delete the copy by disconnecting your inbox or deleting your account.
Information we collect
Account information
When you sign up we collect your name and email address through our authentication provider (Clerk). We also store settings you choose in the product, such as your cleaning instructions and briefing schedule.
Gmail data
When you connect a Gmail account, you authorize Initial through Google’s OAuth consent flow. OAuth tokens are held and refreshed by our authorization service (Nango); we store a reference to the connection and the connected email address, not your password or refresh token.
To show you your inbox and keep it organized, we maintain an encrypted working copy of the mailbox data the product needs:
- Thread index: for each email thread — subject, participants, dates, message identifiers, attachment names, and its state in your mailbox (folder, labels, read/unread, starred, category). This is what makes your inbox render instantly and stay in sync with Gmail.
- Message bodies: the HTML or text body of each mirrored message. Storing this copy makes messages load quickly and avoids repeatedly fetching the same content from Gmail. Attachment files and inline image bytes can be cached temporarily in private object storage after you view them.
- Derived content: short excerpts, AI-generated summaries, topic groupings and their update history, extracted dates and action items, and embeddings — numerical representations of message text that power search and grouping and are not designed to reconstruct the original text.
- Highlights: details pulled from your mail about things like flights, deliveries, bills, reservations, and appointments — times, places, confirmation codes, and the email’s own links — and how they change over time, including details from calendar invites attached to your mail.
- Activity records: for each processed message — the sender, subject, the label applied (if any), whether it was archived or kept, a one-line reason, and message identifiers. This powers the activity log you see in the product.
- Chats and briefings: your conversations with the assistant and your daily briefings are stored so you can revisit them. Because these are conversations about your mail, they can contain excerpts of email content that you or the assistant referenced — the same content you see in the transcript.
Live flight status
When a highlight is a flight, we send its flight number, date, and airports to AeroDataBox so the highlight can show live times, gates, terminals, and the baggage carousel. Nothing else from the email is sent, and the request does not identify you. We check each flight a few times before departure and around landing.
Shared topics
When you share a topic, anyone with its link can read the topic’s updates and see its highlights. Shared highlights leave out confirmation codes, seats, account and order numbers, sign-in codes, and the email’s links. Turning sharing off disables the link.
Usage information
We collect operational AI usage metrics (model, token counts, cost, and latency) using PostHog. Prompts, email content, and model responses are excluded from this telemetry. These metrics are associated with an internal account identifier and retained for up to 30 days.
How we use AI, and what AI providers see
Classifying and summarizing mail requires sending message content to large-language-model providers. All model calls are routed through the Vercel AI Gateway with zero data retention enabled: providers process the content to produce a response and do not retain it afterward, and it is never used to train models. We additionally restrict which infrastructure hosts may serve each model.
Google API Services — Limited Use disclosure
Initial’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Gmail data to provide user-facing features you can see: showing and organizing your inbox and topics, highlights such as flight and delivery status, cleaning your mailbox, answering your questions in chat, and producing your briefing.
- We do not transfer Gmail data to third parties except to provide or improve these user-facing features (the service providers listed below), as required by law, or in a merger or acquisition with prior notice to you.
- We do not use Gmail data for advertising, and we do not sell it.
- We do not retain or use Gmail data to develop, improve, or train generalized (non-personalized) AI or machine-learning models.
- Humans do not read your Gmail data, except with your explicit permission (for example, a support request), where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized.
Service providers
We rely on a small set of infrastructure providers to run Initial. Each processes data only to provide their service to us:
- Clerk — sign-in and account management
- Nango — OAuth authorization and token management for Gmail
- Neon — our database (the stored data described above)
- Cloudflare R2 — temporary private attachment and image caching
- Railway — application hosting
- Vercel AI Gateway and its model providers — AI processing, with zero data retention
- PostHog — operational AI usage metrics, with content excluded
- Exa — web search, when you ask the assistant to search the web
- AeroDataBox — live flight status. Receives a flight’s number, date, and airports; never message content or who you are
- Logo.dev — sender logos in your inbox. Your browser requests a logo using the sender’s domain (for example
github.com), so Logo.dev receives that domain and your IP address — never message content or addresses
Data retention and deletion
- Disconnecting an inbox deletes the data associated with it — its connection record, stored message bodies, thread index, cached attachments and images, derived content (including topic groupings built from that inbox), activity records, and chats and briefings scoped to it.
- Deleting your account deletes all data associated with you and revokes every connected inbox. You can delete your account from Settings or request deletion at the address below.
- OAuth access is revocable at any time from your Google Account permissions page, independent of anything you do in Initial.
Security
Data in transit is encrypted with TLS, and data at rest is encrypted by our database provider. Access to production systems is limited to those who operate the service. Stored message bodies receive the same protections and deletion controls as the rest of your mailbox mirror.
What we don’t do
- We don’t sell your data, ever.
- We don’t show you ads or use your data for advertising.
- We don’t train AI models on your data.
- We don’t retain inactive attachment and inline image caches indefinitely.
Children
Initial is not directed to children under 13, and we do not knowingly collect data from them.
Changes to this policy
If we change this policy, we will update the date at the top and, for material changes — especially any change to how we handle Gmail data — notify you in the product or by email before the change takes effect.
Contact
Questions or deletion requests: support@useinitial.com
Previous versions
- Version 1.0, in effect from July 21, 2026