Privacy Policy
Effective July 27, 2026
This policy covers Bmail (usebmail.com) and Kevin for Gmail, operated by Bmail. It explains what data we collect, why we collect it, how long we keep it, and how you can delete it.
Google API Limited Use disclosure
Kevin’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we affirm that:
- We use Google user data only to provide and improve the user-facing features you explicitly request from Kevin.
- We do not transfer or sell Google user data to third parties for advertising, marketing, credit assessment, or any other unrelated purpose.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models. Our AI providers are contractually bound to zero data retention and to not train on the content we send them.
- We do not allow humans to read your Google user data, except: (a) with your explicit prior consent for a specific issue you report to us; (b) where necessary for security purposes such as investigating abuse; or (c) to comply with applicable law.
Google permissions we request, and why
Kevin acts as a delegated assistant inside your existing Gmail account, so it needs the same access a human assistant with mailbox delegation would have. Each permission maps to a feature you can trigger:
| Scope | Why Kevin needs it |
|---|---|
| openid / email / profile | Identify your Google account and display your name and email address in the Kevin dashboard. |
| https://www.googleapis.com/auth/gmail.modify | Read the threads you CC Kevin on or send to Kevin, apply labels, and create drafts so Kevin can understand the request and prepare a reply in your mailbox. |
| https://www.googleapis.com/auth/gmail.compose | Compose and update drafts on your behalf when you ask Kevin to write or revise a reply. |
| https://www.googleapis.com/auth/gmail.send | Send the reply, introduction, or follow-up you explicitly delegated to Kevin, from your own address. |
| https://www.googleapis.com/auth/calendar | Check your availability across your calendars so Kevin proposes times you are actually free. |
| https://www.googleapis.com/auth/calendar.events | Create, update, and cancel the meetings Kevin schedules for you, and send invitations to attendees. |
| https://www.googleapis.com/auth/drive | Locate and attach files you reference in a request (“send them the term sheet template”) and save documents Kevin generates back to your Drive. |
| https://www.googleapis.com/auth/documents | Read and draft Google Docs when you ask Kevin to summarize, revise, or generate a document. |
| https://www.googleapis.com/auth/spreadsheets | Read and update Google Sheets when you ask Kevin to pull figures into an email or log an outcome to a tracker. |
| https://www.googleapis.com/auth/presentations | Read and draft Google Slides when you ask Kevin to prepare or summarize a deck. |
| https://www.googleapis.com/auth/tasks | Create and complete Google Tasks for the follow-ups Kevin commits to on your behalf. |
| https://www.googleapis.com/auth/drive.activity | See recent activity on a referenced file so Kevin can report the current status of a shared document. |
| https://www.googleapis.com/auth/meetings.space.created | Create a Google Meet link for the meetings Kevin schedules. |
| https://www.googleapis.com/auth/meetings.space.readonly | Read the Meet space Kevin created so the correct join link is included in the invitation. |
Kevin only acts on a thread when you explicitly involve it — by CC’ing kevin@usebmail.com, emailing Kevin directly, or issuing a request in the Kevin dashboard. Kevin does not autonomously read, summarize, or act on mail you have not delegated to it.
What we store
- Account data: your name, the email address you signed up with, your connected Google account address, and your account settings.
- OAuth credentials: a Google refresh token, stored envelope-encrypted (AES-256-GCM) and bound to your user ID. It is never logged and never leaves our servers.
- Task records: the message ID, thread ID, timestamp, task type, status, and token usage for each task Kevin runs, so you can audit Kevin’s activity and we can bill and debug.
- Transient message content: the content of a thread you delegate is fetched at run time, held in memory for the duration of the task, and sent to our AI provider to produce the result. We do not build a persistent copy or index of your mailbox.
Sub-processors
- Google LLC — Gmail, Calendar, Drive, and Meet APIs (your own account).
- Supabase — encrypted application database and authentication.
- Cloudflare — application hosting and edge compute.
- Mailgun — inbound and outbound message transport for kevin@usebmail.com.
- OpenAI and Anthropic — large language model inference, under zero-retention, no-training terms.
- Stripe — payment processing (paid plans only; card data never touches our servers).
Security
- All data is encrypted in transit with TLS 1.2+ and at rest by our infrastructure providers.
- Google refresh tokens are additionally envelope-encrypted at the application layer with per-user AEAD binding.
- Access to production systems is limited to named administrators using multi-factor authentication.
- Secrets are held in a managed secret store, never in source control.
- Suspected breaches affecting Google user data are reported to affected users without undue delay.
Retention and deletion
- Task metadata is retained for 12 months, then deleted.
- Message content is not retained after a task completes.
- Disconnecting Google in the Kevin dashboard immediately revokes and deletes your stored refresh token and stops all processing.
- Deleting your account removes all associated records within 30 days. To delete your account, email support@usebmail.com from your registered address.
- You can revoke Kevin’s access at any time from your Google Account permissions page.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. Contact privacy@usebmail.com and we will respond within 30 days. We do not sell personal information.
Children
Bmail and Kevin are not directed to anyone under 16, and we do not knowingly collect their data.
Changes
We will post material changes to this page and update the effective date. Continued use after a change constitutes acceptance.
Contact
Bmail — privacy@usebmail.com
Security reports: security@usebmail.com